Skip to main content

Working files, not slides.

The risk registers, mappings, checklists and policies we hand out in our own cohorts. Designed to lift, adapt and ship. Drop your email and the file lands in your inbox.

Built for paste-and-adapt, not for a slideshow.

Working files

XLSX, DOCX, ZIP kits. Pre-filled with the fields the auditor or the regulator actually asks for.

Audit-tested

Templates are based on practitioner workflows and reviewed for training use. Each download states its revision status and intended scope.

Free

No paywall. Submit your email to receive the file. Newsletter subscription is separate and is added only when you opt in.

DORA

XLSX

DORA × ISO 27001:2022 Mapping

Every DORA control mapped to ISO 27001:2022 Annex A across the 8 operational domains, 95 sub-requirements deep. Drop your ISMS evidence into the Coverage column and the live dashboard tells you exactly which DORA articles you can already prove.

Free with emailGet the template

ISO 27001

XLSX

Information Security Risk Register V3

An ISO 27001:2022 compliant risk register, 32 columns per entry, with inherent and residual scoring on a 5×5 heat map, treatment strategy tracking, and full ISO 27001 Annex A control mapping. Real-time dashboard summarises your landscape by category, treatment, and control effectiveness.

Free with emailGet the template

NIS 2

KIT

NIS 2 Compliance Kit

Go from 'we think we're in scope' to 'we have evidence' without re-reading 70 pages of directive text. A scope decision tree, a 43-point readiness checklist aligned with Art. 21(2), and the four Art. 23 notification letters covering the 24h, 72h, intermediate and 1-month cycle.

Free with emailGet the template

ISO 22301

DOCX

Business Continuity & Disaster Recovery Policy

A battle-ready BC/DR policy aligned with ISO 22301 and mapped to ISO 27001 Annex A, NIS 2, and DORA. Written for organisations that want a policy auditors and operations can both work from, not the 12-page PDF that dies between audits.

Free with emailGet the template

ISO 22301

XLSX

Business Impact Assessment (BIA)

A pragmatic Business Impact Analysis you can finish in a working week, with three lenses on impact (People, Systems, Locations) and impact-over-time scoring at 0-1d, 2-4d, 5-10d, and >10d. Aligned with ISO 22301 and mapped to NIS 2 and DORA continuity expectations.

Free with emailGet the template

GDPR

KIT

GDPR DPIA Template

A 9-criterion EDPB WP248 threshold assessment with automatic verdict that tells you whether a DPIA is mandatory, recommended, or not required for any processing in your ROPA. The companion Word template walks you through the full Art. 35 methodology with the EDPB three-axis risk model baked in.

Free with emailGet the template

GDPR

XLSX

GDPR ROPA Template

An audit-ready Records of Processing Activities register with the full 17-column Art. 30 schema, six worked SaaS / e-commerce / HR examples, and companion sheets for TOMs, sub-processors and an action plan. Auto-calculating dashboard for total processings, special-category data, international transfers, and open remediation items.

Free with emailGet the template

AI Act

XLSX

AI Act Risk Classifier

A use-case intake that runs your AI system through Art. 5 (Prohibited), Art. 6 / Annex III (High-risk), and Art. 50 (Transparency) tests, and returns the tier with the specific articles that apply. Includes 14 pre-classified worked examples and a cross-walk to your ISO 42001 controls.

Free with emailGet the template

ISO 42001

XLSX

ISO/IEC 42001:2023 Statement of Applicability

The full 39-control Statement of Applicability for an ISO/IEC 42001:2023 AI management system, with applicability decisions, implementation status, evidence tracker, and a Compliance Dashboard that auto-calculates implementation rates per Annex A group. Includes a KPI Examples sheet with concrete metrics for every control.

Free with emailGet the template

Need a kit right now?

Talk to us. Some of these already live in our cohorts.

Several of the kits above ship with our in-house training programmes. Book a discovery call and tell us what you are scoping. We will send you the relevant pre-release working file.