ISO audit
Preparing staff training for an ISO audit
Turn your ISO 27001 or ISO 9001 policies into short courses, and show the auditor a completion record per person.
The situation
You're certified to ISO 27001, and the surveillance audit is in March. Clause 7.3 requires that everyone working under your organisation's control is aware of the information security policy, their contribution to the management system, and what happens if they don't follow it. Your evidence today is a policy acknowledgement signed at onboarding and attendance at last year's awareness session. Since then, three policies have been revised and 40 people have joined.
How it works in Ervy
01
Upload the policies in scope
The policies and procedures of your management system.
02
Ervy builds a course per policy
With quizzes that check understanding, not just that someone opened the file.
03
Send it to everyone in scope
Via Microsoft Teams or email, and see who hasn't started yet.
04
Export the record
Completion per person and per policy, ready for the auditor.
Documents you'd upload
Information security policy
Acceptable use policy
Access control policy
Information classification procedure
Incident management procedure
Supplier security policy
What the lessons look like
The result
Awareness evidence ready before the auditor asks
Quiz results show understanding, not only a signature
When a policy is revised, update the course and re-send it
Related
Related solution
Compliance
Scheduled compliance lessons with every completion logged.
Related use case
PTAC
88% completion in 30 days across 105 employees.
See what Ervy builds from your documents
Upload one document and get a full course in under 10 minutes.



