ISO 27001 without building a compliance team

The AI writes the first draft.
A person signs it.

You need ISO 27001, not a compliance department. Describe your business in plain English and ClearIMS drafts your scope, risk register, risk treatments, Statement of Applicability, policies and tasks, then hands you the pen. Nothing is approved until a named person approves it.

Not sure where you stand? Take the 2-minute readiness check →

30-day free trial · No VAT charged · Cancel monthly plans with 30 days’ notice

EXAMPLE LTD (FICTIONAL) · ISMS-POL-01DRAFT 0.1 · generated by ClearIMS

Information Security Policy

1. Purpose. Example Ltd designs and hosts booking software for independent dental practices in the UK. This policy sets out how we protect the confidentiality, integrity and availability of the information we hold on behalf of our customers and their patients.

2. Scope. The ISMS covers the booking platform, the supporting cloud infrastructure, and the London office Manchester office and all remote workers. Suppliers processing patient data are in scope under A.5.19 to A.5.23.

3. Commitments. Top management commits to meeting applicable legal, regulatory and contractual requirements

DRAFTED BYClearIMS (AI draft, not an approval)
APPROVED BY (TOP MANAGEMENT)R. Okafor, Managing Director
BUILT FOR
ISO 27001:2022Available now
Cyber EssentialsAvailable now
Business continuityIncluded
ISO 22301 · 14001 · 45001Planned, no dates promised

One system, four jobs.
Draft, approve, run, show your auditor.

All screens show Example Ltd, a fictional organisation

From a description to a complete starting ISMS

You tell ClearIMS what your organisation does, where it works and who works in it. It drafts the core records of a starting system, each one clearly marked as a draft waiting for a named approver.

  • iScope
  • iiRisk register and risk treatments
  • iiiStatement of Applicability, all 93 Annex A controls
  • ivPolicies and tasks
Apply for a founding place
EXAMPLE LTD (FICTIONAL) · STATEMENT OF APPLICABILITY · DRAFT93 controls · 0 approved by AI
CONTROLDRAFTED JUSTIFICATIONAPPLICABLEAPPROVAL
A.5.1Policies for information security are required; Example Ltd holds patient data on behalf of practices.YesApproved · J. Patel
A.7.4Physical security monitoring. Applicable to the London office. No fixed office; staff work remotely.Yes NoDraft · awaiting J. Patel
A.8.13Information backup. Booking data is backed up nightly by the cloud provider; restore tests are quarterly.YesApproved · J. Patel
A.8.24Use of cryptography. Data is encrypted in transit and at rest; key management is delegated to the cloud provider.YesDraft · awaiting J. Patel
Every approval records who approved, which version, and when.

Who it’s for

Solutions by role
01 · THE BUSINESS

Needs ISO 27001, not a compliance team

A customer, a tender or the board is asking for it. ClearIMS does the drafting and the admin, so you don’t have to hire people to deliver it.

02 · THE PERSON WHO RUNS IT

ISO 27001 on top of the day job

Usually an IT manager, operations lead or director. They get a full first draft to react to, not a blank template, and a system that runs on tasks, owners and due dates.

03 · THE ADVISER

Helping a client’s small team

If you support a small organisation through ISO 27001, you can work in their system alongside them, while every approval is still made by a named person in their business.

02 · APPROVE

The AI never approves anything. A named person does.

Every approval records who approved, which version, and when. The information security policy and each management review sign-off need a top-management approver.

RECORD · EXAMPLE LTD (FICTIONAL)STATUS
Risk R-014 · Laptop theftDrafted
SoA · A.8.1 User endpoint devicesApproved · J. Patel · v1.2
Information Security Policy v1.0Approved · R. Okafor (MD)
Management review · Q3Awaiting top management
EXAMPLE LTD (FICTIONAL) · THIS MONTHOwners set by people
Evidence · quarterly restore test (A.8.13)S. AhmedDue
Internal audit · Annex A.5L. BrennanScheduled
Nonconformity NC-04 · leaver accessS. AhmedOpen
Management review · Q3M. Doyle (MD)To sign
03 · RUN

Then the redlines keep coming

An ISMS is a running system, not a folder. Evidence, tasks, internal audits, management reviews and nonconformities are owned, dated and recorded, so a small team can keep the system honest between audits.

04 · SHOW YOUR AUDITOR

Your auditor sees the approved records, and only those

The auditor portal gives your external auditor read-only access to your approved records: policies, the Statement of Applicability, risks, audits and reviews. Drafts stay private until your people approve them.

We make the software. Your certification is yours, awarded by your certification body.

AUDITOR PORTAL · EXAMPLE LTD (FICTIONAL)Read-only · approved records
CLAUSERECORDAPPROVED BY
5.2Information Security Policy v1.0R. Okafor (MD)
6.1.3Statement of Applicability v1.2J. Patel
9.2Internal audit report · Annex A.5L. Brennan
9.3Management review minutes · Q2M. Doyle (MD)

Pricing

Two plans, one product. Every plan starts with a 30-day free trial. No VAT is charged.

Billing period
10 PLACES · FOUNDING CUSTOMER10 PLACES · FOUNDING

Founding

For the first ten organisations. Price locked for 24 months.

£150per month, billed monthly

Annual: £1,500 a year paid upfront. No VAT charged.

Apply for a founding place
  • Everything in Standard
  • 30-day free trial first
  • £150 a month locked for 24 months, half the standard price
  • In return: a short monthly feedback call, and a case study once your certification body has awarded your certification

Standard

For every organisation after the founding places are filled.

£300per month, billed monthly

Monthly plans cancel with 30 days' notice. No VAT charged.

Book a 20-minute call
  • AI-drafted starting ISMS: scope, risk register, treatments, SoA, policies, tasks
  • Named-person approvals on every record; top-management sign-off where required
  • Evidence, tasks, internal audits, management reviews, nonconformities
  • Auditor portal, Cyber Essentials and business continuity included

Honest answers to the usual questions

Do you certify us?

No. We make the software; your certification is awarded by your certification body. ClearIMS helps you build, run and evidence the system they’ll assess.

Does the AI approve anything?

Never. The AI drafts. A named person in your organisation approves every record, and the information security policy and management review sign-off need a top-management approver.

Will my auditor accept AI-drafted documents?

Your auditor assesses your system: whether it fits your organisation, whether your people approved it, and whether you run it. AI drafting is where you start, not what they assess. ClearIMS records who approved each record and when.

What happens after the 30-day trial?

You choose a plan or you stop. If you’ve applied for and been offered a founding place, it starts when the trial ends at £150 a month, or £1,500 a year upfront.

Can I cancel?

Monthly plans cancel with 30 days’ notice. Annual plans run for the year you’ve paid for.

Which standards are covered?

ISO 27001 and Cyber Essentials today, with business continuity included. ISO 22301, 14001 and 45001 are planned. We don’t publish dates we can’t keep.

TRUST AND SECURITY

Only what’s true

No badges we haven’t earned. Just how the software works.

Read more on the security page

Designed with tenant isolation and UK data handling in mind

Ask us how it works and we’ll give you a straight answer.

A named person approves every record

The AI drafts and never approves. Every approval records who approved, which version, and when.

Your auditor gets scoped, read-only access

The auditor portal shows your external auditor your approved records, and nothing else.

FOUNDING CUSTOMER PROGRAMME · 10 PLACES

Ten organisations get the software at half price. We get to learn from them.

Start with the 30-day free trial. If ClearIMS earns its place, a founding seat locks £150 a month for 24 months, or £1,500 a year upfront. No VAT charged.

Apply for a founding placeBook a 20-minute callWe make the software. Your certification is yours, awarded by your certification body.
FOUNDING CUSTOMER PROGRAMME · 10 PLACES

Apply for a founding place, or book a 20-minute call

Tell us a little about your organisation and we’ll reply by email. The founding programme is subject to acceptance and a separate agreement.

Prefer email? Write to [email protected].

What would you like to do?
name
email
company
role
driver
Optionaltarget