Paste the sheet you run your controls from. Get back what proves each one.
Every control mapped to the evidence an auditor accepts, the system that evidence already lives in, and which of your periodic reviews can become a live record instead of a quarterly scramble. First run needs no account.
A.5.1 Policies for information security Annual policy review, board sign-off Priya A.5.15 Access control Access review spreadsheet every 6 months Sam A.5.18 Access rights Leaver checklist emailed to IT Sam A.5.23 Cloud services Vendor list in SharePoint, reviewed yearly Jordan A.6.3 Awareness training Training tracker xlsx, certificates in a folder HR A.8.2 Privileged access Admin list checked quarterly Sam A.8.8 Technical vulnerabilities Scan report attached to the monthly ticket Ops A.8.15 Logging Quarterly log review meeting Ops A.8.16 Monitoring Alerts reviewed weekly, screenshots saved Ops Backups Backup restore test twice a year Ops 9.2 Internal audit programme Annual audit by consultant Priya 9.3 Management review Minutes in the ISMS folder Priya
Paste, or start from the standard
Rows from Excel, Google Sheets, a GRC export, a Word table. Clause numbers are matched exactly; rows without one are matched on their wording, and anything doubtful is marked so you check it rather than trust it.
See what proves each control
For every control: the artefacts an auditor accepts, each tagged as a live system record, a periodic review output, or a governing document. Plus the common gap auditors find on that exact control.
Convert the reviews that can be records
A first move per control: which system already holds the evidence and what to pull from it on a schedule. The controls that are genuinely people and documents are told so, because automating those is where continuous compliance projects go to die.
Why a sheet and not another platform
The funded compliance platforms want your whole programme migrated and integrated before they show you anything. Your controls already live in a spreadsheet, and the spreadsheet is fine. What it lacks is the column that says what evidence each row needs and where that evidence already exists. That is the column this builds, in under a minute, from the rows you already have.