Most platforms hand you an empty framework and a great many input fields. Assistant27 arrives with the content already in it — ninety risks to choose from, control texts with the points an auditor looks for, work themes that organise your ISMS the way your people talk about it — and it reads your documentation with AI that shows the quote behind every verdict.
Sector-specific obligations (DORA, Part-IS, …) are tracked through your own risk tags — identified separately, demonstrable separately.
Four things you notice on day one — and again on the day of the audit.
Ninety recognisable risks to choose from, 93 controls with their purpose, a practical approach and the audit points, plus the clauses of chapters 4 to 10. You start by choosing and adjusting, not by typing.
Work themes bring controls, risks and documents together the way your people talk about them: access, suppliers, continuity. One click puts the entire task board into Microsoft Planner.
Documents stay in SharePoint, tasks in Planner, sign-in through Entra ID. Secure Score, MFA coverage and vulnerabilities flow from your own tenant into the file. No second administration.
Assistant27 comes out of the daily practice of a consultant who implements ISO 27001 and CyFun® at client sites. Every feature exists because the work asked for it — not because a chapter needed a screen.
The risk library as an example: ninety written-out scenarios. Open one and you see exactly what you get — the threat, the vulnerability scenario and the controls that belong to it. Adding it to your register is one button; adjusting it to your situation comes after.
The same goes for the controls and the clauses: every text is written from the question "what does an auditor want to see here", not copied out of the standard.
From control to report, in the order the work actually happens.
ISO 27001 Annex A or CyFun®: per control the status, the justification and the evidence. With the SoA export the auditor expects — in English or Dutch.
Not 93 controls in a row, but eight themes your people recognise. Each theme bundles the controls, risks and documents that belong to it.
KPIs with a target, a trend and context — not as a loose chart, but tied to the controls and risks they are about.
Two assessments side by side: today's risk, and what remains after treatment. Every score is tied to the controls that determine it — not a loose list living next to the ISMS.
The management review gets the progress report — controls, clauses, risks, non-conformities and KPIs in one document. One click, English or Dutch.
Secure Score, MFA coverage, vulnerabilities and incidents flow straight from your own tenant into the file — as living numbers, not a quarterly copy.
One screen that holds your file up to the light and tells you what does not add up or is still missing — an asset without an owner, a risk without a treatment, a KPI that has had no measurement for months.
Everything above works entirely without AI. Switch it on and you win time on the most tedious work: finding where in two hundred pages of policy the answer sits. The AI does that in minutes — and it puts the quote, with document and page, next to every verdict, so you verify in seconds instead of searching yourself. Off by default, on your own key, with a monthly cap the server enforces and a cost estimate before anything leaves.
Your policies and procedures are held against the requirements of the standard, control by control. You get a list per document of what is still missing, in imperative sentences — printable for whoever writes it.
Fourteen security and privacy clauses against the signed contract, with the passage itself. Beside this, a real review: fourteen proposals, three gaps found, quote with location.
Your ISMS file gathers your weak spots in one place. Security was therefore not a closing chapter here but the first design question — and it is tested daily, not promised once.
Your data lives in its own database in the EU, not in a shared table with a customer number attached.
No extra passwords. Your MFA and access rules apply here too.
Changing or deleting entries is made technically impossible — for us as well.
Access control is tested automatically on every change, and a smoke test runs each night. Dated test reports are available on request.
A demo takes an hour and runs on your own standards. Tell us what you can — the more context, the sharper the conversation.