Trust

Governance · the documents behind the register

Policies

The written record that ISO/IEC 27001:2022 and ISO/IEC 42001:2023 ask for, published as pages rather than filed as documents nobody can check. Each one is its own route, names the clauses it is the record for, and can be linked to section by section. The conformance register links back to these, and the same content is available as data.

These describe the service as it actually runs, including where it falls short. A policy asserting a control that does not exist would make every other row on the register suspect.

20 documents