One compliance platform.
Five frameworks. Every artifact your auditor asks for.

Complyanz runs ISO 27001, ISO 27701, ISO 42001, SOC 2 and HIPAA in a single workspace — risk registers, controls, evidence and the audit-ready document set — so one team can carry certifications, attestations and regulatory programs at the same time.

No credit card required ISO 27001:2022 aligned Your data is never used to train models
Integrated management system

Add a standard. Don't start a second program.

Most tools sell one framework per subscription, so a second certification means a second set of policies, a second risk register and the same work done twice. In Complyanz the ISO standards compose: ISO 27001 is the foundation, and privacy and AI extend it into one integrated management system with a single, consistent document set.

36documents — ISO 27001 on its own (ISMS)
38documents — 27001 + 27701, privacy integrated (IMS1)
40documents — 27001 + 42001, AI integrated (IMS2)
42documents — 27001 + 27701 + 42001, fully integrated (IMS3)

Adding privacy to an existing ISMS moves you from 36 documents to 38 — not to 36 plus a separate privacy library. The overlapping clauses stay in one place, which is exactly what an integrated management system is supposed to deliver.

How it works

The same path your assessor expects

Each framework carries its own roadmap in the product. The shape is consistent, so a team that has run one program can run the next.

Step 1

Scope

Define the organization, the boundary and the standards in play. Locations, entities and interested parties are captured once and reused across every program.

Step 2

Assets and risk

Register the assets in scope with their confidentiality, integrity and availability values, then build the risk register from a library of 266 pre-written ISO scenarios.

Step 3

Controls and applicability

Work through the controls for each active standard, record justifications and produce the Statement of Applicability, Controls Applicability Matrix or Safeguard Applicability the assessor wants.

Step 4

Evidence and audit

Attach evidence to controls, run internal audits and management reviews, log incidents and corrective actions, and walk into the audit with the trail already assembled.

The platform

Nine modules, one system of record

Everything a compliance program generates — risks, controls, documents, evidence, incidents, people and suppliers — lives in one place and stays linked.

Risk register and treatment plans

Build the register from 266 pre-written ISO scenarios or your own. Map each risk to the controls that treat it, set owners and track residual risk to closure.

Statement of Applicability

The document an ISO auditor asks for first. Walk all 93 Annex A controls, record inclusion or exclusion with justification, and export the SoA. SOC 2 and HIPAA get their equivalent applicability views.

Document library

90 ISO documents, tagged by management-system variant, plus dedicated SOC 2 and HIPAA sets. Pre-filled with your organization's details and exported as formatted Word and PDF files.

Evidence vault

Attach evidence directly to the control or criterion it proves, with the audit period it covers. When the assessor asks, the answer is one click away instead of one email thread.

Incidents and corrective actions

Log security and privacy incidents, classify severity, and drive corrective actions to closure. Breach records and notification readiness are built in for HIPAA.

Suppliers and business associates

Track third parties, the data they touch and the assurance you hold over them — including business associate agreements for organizations handling protected health information.

Training and awareness

Assign awareness training, record completion and keep the evidence every framework asks for when it wants proof that your people know the policies.

AI systems and impact assessments

Inventory the AI systems you build or buy, classify their impact across affected domains, and produce the assessments ISO 42001 expects.

Management review and internal audit

Run the governance cycle the standards mandate — internal audits, management reviews, metrics and continual improvement — with the minutes and records generated as you go.

Why teams switch

Spreadsheets and consultants, or one system of record

Most compliance programs start in a shared drive. They work until the first audit, the first standard added, or the first person who owned the spreadsheet leaves.

How the two approaches compare across the work a program actually generates.
 Spreadsheets and consultantsComplyanz
Getting started A blank workbook, or a consultant's template pack that has to be adapted to your organization before it means anything. Controls, risk scenarios and documents are pre-loaded for every standard you enable, already tied to your organization's details.
Writing the documents Authored by hand or bought as a static pack, then edited in a shared drive where version history is whoever remembered to rename the file. Generated from a maintained library, filled with your data, versioned in the platform and exported as Word or PDF.
Evidence at audit time Screenshots gathered in the fortnight before the audit, chased over email, stored wherever the person who collected them put them. Attached to the control it proves as part of normal work, with the period it covers recorded alongside it.
Adding a second framework A second workbook and a second document set, with overlapping requirements maintained twice and drifting apart. Enable the standard. ISO extensions integrate into one management system; SOC 2 and HIPAA reuse the assets, risks and evidence you already hold.
Keeping it alive between audits Nothing happens until the surveillance audit is scheduled, and then the scramble repeats. Internal audits, management reviews, corrective actions and training run on a schedule, with the records produced as a by-product.
Where the knowledge lives With the consultant, or with one person and their spreadsheet. In the platform, with roles per family so the right people see the right program.
AI assistance

AI that drafts the work, not the decisions

Complyanz uses AI where it removes typing and leaves judgement with your team: drafting risk scenarios for the assets you register, filling policy content from your organization's details, suggesting control justifications, and scoring how ready a program looks.

Deterministic where it matters

Document selection, template filling and exports are deterministic. If AI is unavailable, those flows keep working exactly as before — the artifacts you hand an auditor never depend on a model being up.

Your data is not training data

Content sent to the configured model provider is used to answer your request and nothing else. It is not used to train models. Full detail is in the privacy policy.

Questions

Frequently asked

Does Complyanz certify us?

No, and no software can. Certification is issued by an accredited certification body, and a SOC 2 report is issued by a CPA firm. Complyanz gets you audit-ready and gives you the artifacts and evidence trail those assessors ask for.

How long does it take to get certified?

It depends on your scope, how much of the groundwork already exists and your assessor's availability — so anyone quoting a fixed number is guessing. What Complyanz changes is the preparation: the controls, risk library and documents are already there, so the time goes into decisions rather than authoring.

Can we run ISO 27001 and SOC 2 at the same time?

Yes. They are separate programs with separate applicability views, but they share the same assets, risks, evidence and people, so the underlying work is done once.

What is an integrated management system?

When you certify to several ISO standards, their requirements overlap heavily. An integrated management system maintains one set of policies and procedures covering all of them instead of parallel copies. Complyanz ships pre-built document sets for each combination: ISO 27001 alone, plus privacy, plus AI, or all three.

Are the documents actually accepted by auditors?

They are authored against the clause structure of each standard, tagged to the standards and management-system variant they apply to, and exported as formatted Word and PDF files. Your auditor still assesses whether the content reflects what your organization genuinely does — no document pack can substitute for that.

Can one person work across several organizations?

Yes. One identity can belong to many organizations and switch between them, which is how consultancies and groups with multiple legal entities use the platform. Roles are held per organization, and per framework family within it.

What happens to our data?

Your data belongs to you, is scoped to your organization, and can be exported. Content sent to the AI provider is not used to train models. The privacy policy has the detail.

Do we still need a consultant?

Many teams do not, and those that do use one for less time. Complyanz covers the structure and the artifacts; a consultant is most valuable on scope decisions and readiness review, which is a much smaller engagement than authoring a management system from scratch.

Is there a free tier?

You can create an organization and start building without a credit card. Get in touch if you want a walkthrough before committing time to it.

Start with one framework. Add the rest when you are ready.

Create an organization, pick the standards you are working towards, and the controls, risks and documents are waiting for you.