Not the fortieth GRC tool you have to fill yourself

Most platforms hand you an empty framework and a great many input fields. Assistant27 arrives with the content already in it — ninety risks to choose from, control texts with the points an auditor looks for, work themes that organise your ISMS the way your people talk about it — and it reads your documentation with AI that shows the quote behind every verdict.

The Statement of Applicability in Assistant27, with a control opened and implementation status
Frameworks ISO/IEC 27001:2022CyFun® 2025
Regulations NIS2GDPR

Sector-specific obligations (DORA, Part-IS, …) are tracked through your own risk tags — identified separately, demonstrable separately.

What sets Assistant27 apart

Four things you notice on day one — and again on the day of the audit.

The content is already there

Ninety recognisable risks to choose from, 93 controls with their purpose, a practical approach and the audit points, plus the clauses of chapters 4 to 10. You start by choosing and adjusting, not by typing.

Your structure, not the standard's

Work themes bring controls, risks and documents together the way your people talk about them: access, suppliers, continuity. One click puts the entire task board into Microsoft Planner.

Inside Microsoft 365, not beside it

Documents stay in SharePoint, tasks in Planner, sign-in through Entra ID. Secure Score, MFA coverage and vulnerabilities flow from your own tenant into the file. No second administration.

Built by an implementer

Assistant27 comes out of the daily practice of a consultant who implements ISO 27001 and CyFun® at client sites. Every feature exists because the work asked for it — not because a chapter needed a screen.

The risk library in Assistant27: ninety scenarios, with an opened scenario on the right showing threat, vulnerability and suggested controls

This is what "already filled" looks like

The risk library as an example: ninety written-out scenarios. Open one and you see exactly what you get — the threat, the vulnerability scenario and the controls that belong to it. Adding it to your register is one button; adjusting it to your situation comes after.

The same goes for the controls and the clauses: every text is written from the question "what does an auditor want to see here", not copied out of the standard.

What you do in Assistant27

From control to report, in the order the work actually happens.

Every control, one overview

ISO 27001 Annex A or CyFun®: per control the status, the justification and the evidence. With the SoA export the auditor expects — in English or Dutch.

  • Every control carries its purpose, a practical approach and the points an auditor looks at.
  • Evidence links to SharePoint: the document itself stays where it belongs.
The Statement of Applicability with a control opened
The work themes in Assistant27: eight themes with their controls

Work themes: work the way you think

Not 93 controls in a row, but eight themes your people recognise. Each theme bundles the controls, risks and documents that belong to it.

  • One click puts the full task board into Microsoft Planner, labelled and linked to the controls.
  • Name, colour and working group configurable per customer.

Steering on numbers that mean something

KPIs with a target, a trend and context — not as a loose chart, but tied to the controls and risks they are about.

  • Measurement rounds with reminders: no KPI quietly going stale.
  • One click to Excel for anyone who wants to run their own numbers.
The KPI screen in Assistant27 with trend lines and targets
A risk in Assistant27: context, current risk with its controls, and the expected residual risk with an acceptance decision

Risks you can explain

Two assessments side by side: today's risk, and what remains after treatment. Every score is tied to the controls that determine it — not a loose list living next to the ISMS.

  • If the risk sits above your threshold, the screen asks for a formal acceptance decision with a name and a date.
  • Two 5×5 matrices in the register show the whole picture: where you are now and where you end up.
  • Sector-specific tags (DORA, Part-IS, …) with their own follow-up.

Reporting without retyping

The management review gets the progress report — controls, clauses, risks, non-conformities and KPIs in one document. One click, English or Dutch.

  • Every check produces a dated report that can leave the building, to the auditor or the customer.
  • Print or save as PDF, straight from the screen.
The progress report in Assistant27 with the state of SoA, clauses, risks and KPIs
Microsoft signals in Assistant27: Secure Score, MFA coverage and vulnerabilities from your own tenant

Your Microsoft environment joins the conversation

Secure Score, MFA coverage, vulnerabilities and incidents flow straight from your own tenant into the file — as living numbers, not a quarterly copy.

  • Any signal becomes a KPI with a target in one click.
  • Incidents can be reported through the Microsoft Teams workflow your people already know.

Screening: the app checks along

One screen that holds your file up to the light and tells you what does not add up or is still missing — an asset without an owner, a risk without a treatment, a KPI that has had no measurement for months.

  • No AI, no waiting, no cost: this is plain arithmetic on your own file.
  • Fix something and the line disappears by itself. The list can be printed as a worklist.
Screening in Assistant27: 44 points of attention across four places in the file

The cherry on top: AI that saves hours and stays demonstrable

Everything above works entirely without AI. Switch it on and you win time on the most tedious work: finding where in two hundred pages of policy the answer sits. The AI does that in minutes — and it puts the quote, with document and page, next to every verdict, so you verify in seconds instead of searching yourself. Off by default, on your own key, with a monthly cap the server enforces and a cost estimate before anything leaves.

Your entire documentation set in one pass

Your policies and procedures are held against the requirements of the standard, control by control. You get a list per document of what is still missing, in imperative sentences — printable for whoever writes it.

  • Two steps, with the brake on: fetching documents is free, and you see the cost and confirm before anything goes to the AI service.
  • Whatever the AI did not reach, it says so itself. An unfinished assessment never disguises itself as a completed one.
AI screening in Assistant27: fetching documents and assessing against the standard, with the cost visible up front
The contract review in Assistant27 after an AI round: fourteen proposals with verdicts and a quote with location

From supplier contract to demonstrable decision

Fourteen security and privacy clauses against the signed contract, with the passage itself. Beside this, a real review: fourteen proposals, three gaps found, quote with location.

  • A second AI reading tries to refute the first — and says so when a justification does not hold up.
  • Gaps you cannot close are recorded as a conscious decision, with a compensating measure: exactly what an auditor wants to see.
  • Signing off puts your name under the review; until then, everything is a draft.

Request an example report

Built with security as a precondition

Your ISMS file gathers your weak spots in one place. Security was therefore not a closing chapter here but the first design question — and it is tested daily, not promised once.

One database per customer

Your data lives in its own database in the EU, not in a shared table with a customer number attached.

Sign in with your own Entra ID

No extra passwords. Your MFA and access rules apply here too.

Tamper-proof audit log

Changing or deleting entries is made technically impossible — for us as well.

Every change tested

Access control is tested automatically on every change, and a smoke test runs each night. Dated test reports are available on request.

Time for a demo?

A demo takes an hour and runs on your own standards. Tell us what you can — the more context, the sharper the conversation.

Your details go straight to info@alsecurit.be. This page stores nothing, uses no cookies and sends nothing to third parties. More in our privacy statement.