Compliance & Audit Automation
ISO and TISAX certifications were generating 160+ hours of reactive work per audit cycle. We built a centralised repository, automated policy monitoring, and AI-assisted questionnaire drafting.
The problem
Managing ISO 9001, ISO 27001, and TISAX certifications meant a reactive cycle: every audit triggered weeks of pulling documents together, updating outdated policies, and manually responding to security questionnaires. The process consumed 160+ hours of senior time per cycle and left the team in a constant state of catch-up.
What we built
- A centralised document repository - all policies, procedures, and evidence consolidated into one organised system. 50-100 compliance documents in one place, properly maintained. Single source of truth.
- Automated policy monitoring - tracks KPI thresholds and flags when policies need updating.
- Security questionnaire automation - incoming questionnaires are read and matched against the document library, producing a structured first-draft response.
Stack: Claude · Document management · Automated monitoring · Questionnaire processing
The result
Audit preparation shifted from a reactive fire drill to an ongoing, low-overhead process. The 160+ hours per cycle dropped significantly. Questionnaire response time went from days to hours.