Compliance & Audit Automation
Certification work was reactive - evidence scattered, policies out of date, security questionnaires rebuilt from scratch each time. We built one repository, automated policy monitoring and AI-assisted questionnaire drafting.
The problem
Maintaining ISO 9001 and ISO 27001 certifications meant a reactive cycle. Every audit triggered weeks of pulling documents together, updating policies that had gone stale and answering security questionnaires by hand - 160+ hours of senior time per cycle, with the team permanently behind.
What we built
- One document repository - policies, procedures and evidence in a single organised system, with version control and review dates. 50-100 documents, properly maintained.
- Automated policy monitoring - a weekly check flags policies approaching their review date.
- Security questionnaire drafting - incoming questionnaires are read and matched against the document library, producing a first-draft response for a person to check before anything is sent.
Stack: Claude · Document management · Automated monitoring · Questionnaire processing
The result
Audit preparation is no longer a rush when an audit is announced - it runs continuously in the background. Questionnaire turnaround went from days to hours.