Document packs
Every framework kit lives on this page. Use the navigation to jump straight to the pack you need.
ISO 27001:2022
Information Security Management System (ISMS)
The international standard for managing information security risks. The 2022 revision introduces 93 controls across four themes — Organisational, People, Physical, and Technological. Relevant for any SME handling customer data, operating in regulated industries, or tendering for enterprise and government contracts.
Document packs · 3 available
Six foundational policy documents required by ISO 27001 Clause 5–6: Information Security Policy, Acceptable Use Policy, Access Control Policy, Incident Response Policy, Asset Management Policy, and Business Continuity Policy. Each document is pre-structured with your company placeholder fields, purpose, scope, responsibilities, and review schedule.
What's included
- Information Security Policy
- Acceptable Use Policy
- Access Control Policy
- Incident Response Policy
- Asset Management Policy
- Business Continuity Policy
A complete, pre-populated spreadsheet covering all 93 controls from ISO 27001:2022 Annex A, organised by theme. Includes applicability column, implementation status tracking, control owner, evidence reference, and notes. Structured for direct use as your Statement of Applicability working document.
What's included
- All 93 Annex A controls (2022 revision)
- 4 themes: Organisational, People, Physical, Technological
- Applicability & justification columns
- Implementation status tracking
- Control owner and evidence fields
A structured Excel risk register aligned to ISO 27001 Clause 6.1 (risk assessment) and 6.2 (risk treatment). Includes pre-populated example risks across common SME threat categories — cloud, third-party, physical access, phishing — with likelihood/impact matrix and treatment plan columns.
What's included
- Risk identification and categorisation
- Likelihood × Impact matrix (5×5)
- Inherent and residual risk scores
- Treatment options (accept / mitigate / transfer / avoid)
- 30+ pre-populated SME-relevant risk examples
ISO 42001:2023
Artificial Intelligence Management System (AIMS)
The first international standard for responsible AI governance. Covers AI risk assessment, lifecycle controls, and ethical deployment obligations. Essential for SMEs building or deploying AI-powered products and services, particularly under emerging AI policy frameworks.
Document packs · 3 available
Five policy documents establishing your AI governance framework under ISO 42001:2023: AI Governance Policy, AI Use Policy, AI Risk Management Policy, Data Governance for AI Policy, and Human Oversight Policy. Aligned to Clause 5 (Leadership) and Clause 6 (Planning) requirements.
What's included
- AI Governance Policy
- AI Use and Acceptable Use Policy
- AI Risk Management Policy
- Data Governance for AI Policy
- Human Oversight and Accountability Policy
A structured Excel workbook implementing ISO 42001 Annexure A requirements. Guides you through identifying AI systems in scope, assessing societal and individual impacts, mapping to controls, and producing an auditable impact assessment record. Includes a worked example for a generic SME AI use case.
What's included
- AI system inventory sheet
- Impact category assessment (Annexure A)
- Control mapping worksheet
- Risk treatment and residual risk summary
- Worked example: customer-facing AI assistant
A practical Excel workbook based on ISO 42001 Annexure B guidance. Covers implementation tasks for all major AIMS clauses — from AI context and stakeholder mapping to lifecycle controls and continual improvement. Use as your implementation project tracker alongside the core policy bundle.
What's included
- Clause-by-clause implementation tasks
- Annexure B guidance cross-reference
- Stakeholder and interested parties register
- AI lifecycle controls checklist
- Internal audit readiness checklist
NIST AI RMF
AI Risk Management Framework (NIST AI 100-1)
The US National Institute of Standards and Technology's voluntary framework for managing AI risk across the full system lifecycle. Organised around four core functions — GOVERN, MAP, MEASURE, MANAGE — it is widely adopted internationally and increasingly referenced in enterprise and government AI procurement requirements. Complements ISO 42001 and is suitable for SMEs supplying AI-enabled products or services to larger organisations.
Document packs · 2 available
Four policy documents aligned to the NIST AI RMF GOVERN function: AI Governance and Accountability Policy, AI Risk Tolerance and Appetite Policy, AI Incident Response Policy, and Third-Party AI Supplier Policy. Pre-structured with placeholder fields, roles, and review schedules. Suitable for SMEs needing to demonstrate AI risk governance to enterprise or government clients referencing NIST AI 100-1.
What's included
- AI Governance and Accountability Policy
- AI Risk Tolerance and Appetite Policy
- AI Incident Response Policy
- Third-Party AI Supplier Policy
- GOVERN function alignment notes throughout
A structured Excel workbook implementing the NIST AI RMF MAP, MEASURE, and MANAGE functions. Includes an AI system inventory, risk context worksheet, measurement criteria aligned to MEASURE subcategories, and a risk treatment tracker. Cross-referenced to NIST AI RMF 1.0 subcategory IDs throughout. Includes a worked example for a customer-facing AI recommendation system.
What's included
- AI system inventory and context sheet (MAP)
- Risk identification and likelihood/impact scoring (MEASURE)
- NIST subcategory ID cross-reference column
- Risk treatment and residual risk tracker (MANAGE)
- Worked example: AI recommendation engine
Questions?
If you have questions about which kit is right for your business, or need a custom document set for a specific framework or industry, contact us at hello@certisme.co.za.