Bring any framework. Vissibl maps your controls once and keeps them audit-ready, always.
BLOG

What is ISO 27001 compliance software for Australian businesses?

23 September 2026 · Sean Hurley
Vissibl controls / ISMS product UI

The certification body books the surveillance visit months ahead. The date sits in the calendar and it doesn't move because SharePoint's a mess, or because last year's minor non-conformances are still sitting open with nobody's name against them.

That's the week most Australian teams find out what their ISO 27001 programme actually is. Not the certificate framed near reception. The living information security management system the auditor samples when they walk in.

ISO 27001 is the international standard for an information security management system, or ISMS. In Australia the certificate usually runs on a three year cycle, with a JAS-ANZ accredited certification body coming back every year for surveillance. This article's for teams who already hold 27001, or who need it for a customer, a tender or a board, and who have to decide what the software behind that certificate should actually do.

It's the programme behind the certificate, not a site check-in app or an inspection tool.

What is ISO 27001 compliance software for Australian businesses?

ISO 27001 compliance software is the system that keeps your ISMS running between certification and surveillance audits. It holds the scope, the risk assessment, the Statement of Applicability, the controls, the evidence, the owners and the actions in one place, so you can show the system's been operating all year rather than for the fortnight before the visit.

In the Australian market that usually means working with:

  1. ISO 27001 as the standard, including the Annex A controls.
  2. JAS-ANZ as the accreditation body that accredits certification bodies across Australia and New Zealand.
  3. A certification body that runs the Stage 1 and Stage 2 audits and the annual surveillance visits.
  4. Your own internal audit and management review cycle, which the certification body will sample.

Good software doesn't invent a new ISMS for you two weeks out. It maps the documents and records you already have against the clauses, shows what's missing, and keeps that picture current when something changes.

What does an auditor actually sample?

They book the visit weeks ahead, you get notice, and then they sample.

They're not after a rebuilt folder from last Tuesday. They want evidence the ISMS has been running. Typical samples include:

  1. Scope of the ISMS: what's in, what's out, and why.
  2. Risk assessment and treatment plan that match how the business actually works.
  3. Statement of Applicability: which Annex A controls apply, which don't, and the justification for each.
  4. Access reviews, change records and incident records that match the policy cadence you published.
  5. Internal audit programme and findings, including anything still open.
  6. Management review minutes with decisions in them, not attendance lists only.
  7. Named owners on controls and corrective actions.
  8. Evidence that matches the clause, rather than a slide that narrates the clause.

If the policy says quarterly access reviews and the last one is eight months old, that's the finding. The software's job is to make that gap visible before the certification body does.

Why point-in-time readiness fails

Evidence usually lives across SharePoint, email and a consultant's leftover spreadsheet. Owners are implied rather than named. Last year's minor non-conformances are still open. Policies got updated once for Stage 2 and then drifted quietly for eleven months.

So the fortnight before surveillance turns into a scramble to prove the system existed all year. People rewrite registers. Someone digs through inboxes looking for the missing management review. The shared drive gets a new folder called "Audit pack 2026".

That scramble is the product problem. A tool that gets you ready once is solving the wrong fortnight, because the certification body is testing whether the ISMS ran for twelve months, not whether you can assemble a pack in ten days.

Buyer questions in tenders and enterprise security questionnaires make the same point. They ask who owns the control, when it was last reviewed, and where the evidence lives. A rebuilt folder doesn't answer any of that for long.

What should ISO 27001 compliance software do?

If you're comparing ISO 27001 software for Australia, judge it against the programme rather than a feature checklist written for generic GRC.

It should:

  1. Map the documents you already have to ISO 27001 clauses and Annex A controls.
  2. Rank the gaps by audit risk, not alphabetically and not by whoever shouted loudest in the last meeting.
  3. Put a named owner on every control and every action.
  4. Keep the vault current when a document changes, so the readiness answer moves with the evidence.
  5. Hold internal audit, non-conformances and management review in the same programme as the controls.
  6. Stay current every day, not only the week before the certification body arrives.
  7. Pull vendor risk into the same picture when suppliers touch your systems or your data: certificates, insurance, questionnaires and residual risk, rather than a separate filing cabinet.

If the tool can't answer "would we pass a surveillance audit today" from the live programme, it isn't doing the job the certificate requires.

How Australian certification actually runs

For teams new to the cycle, the shape's usually this:

  1. Gap analysis against ISO 27001 and Annex A.
  2. ISMS build: scope, policy set, risk assessment, Statement of Applicability, controls and evidence.
  3. Internal audit and management review before the certification body arrives.
  4. Stage 1, the document and readiness review, and Stage 2, the implementation audit, with a JAS-ANZ accredited certification body.
  5. Certificate issued, typically valid for three years.
  6. Surveillance audits each year, then a recertification audit at the end of the cycle.

Software that only helps for Stage 2 and then goes quiet between surveillance visits leaves you with the same scramble next year. Continuous programmes match how certification actually works here.

What buyers and tenders usually ask

Enterprise customers and government-adjacent tenders rarely ask whether you've "got ISO". They ask for evidence the ISMS still works. The common asks:

  1. Current certificate scope and expiry, plus the certification body's name.
  2. Statement of Applicability, and how any exclusions are justified.
  3. Last internal audit date and any open non-conformances.
  4. Access review cadence against the last completed review.
  5. Incident and supplier risk evidence for systems that touch their data.
  6. Named owners for the controls protecting the services in the deal.

If your ISO 27001 compliance software can't pull those answers from a live programme, someone will assemble them by hand under deadline. That's the same scramble surveillance already punishes.

How Vissibl runs the programme

Vissibl is an AI-native compliance platform for operational businesses in Australia and the GCC, and it adapts to whatever framework you run. For 27001 that means the whole ISMS sitting in one place.

You bring the documents. Vissi Audit reads what you already have, maps it clause by clause against ISO 27001 and Annex A, and returns a gap list ranked by audit risk. Every control carries a named owner and a status. The readiness score updates when your documents change, so the answer to "would we pass today" sits on the dashboard instead of in someone's head.

Internal audit, non-conformances, management review and vendor risk all run in the same platform. Unlimited users and unlimited sites, so the person who actually owns the control can log in and own it.

From $12,000 AUD per framework per year. Implementation included. No setup fee. No per-seat charges.

Vissibl isn't SafetyCulture or HammerTech and isn't trying to be. Those live on the tools and on site. This is the programme the certification body and your enterprise customers ask for.

See what the auditor would find before the auditor does

Bring your current ISMS pack. In the first session we run a live Vissi Audit against your documents, and you see what a surveillance auditor would sample before you commit to anything.

Book a demo when you want that gap reading on your own evidence rather than on a generic checklist.