ISO 27001 Compliance

The ISO 27001 tool to run your ISMS risk management

Run your risk assessment with EBIOS RM and track your treatment plan, evidence included, on a platform built in France.

What ISO 27001 is and why to get certified

ISO/IEC 27001 is the leading international standard for information security management. It requires an ISMS grounded in risk assessment, the treatment of those risks and the selection of security controls drawn from Annex A. ISO 27001 certification, issued by an accredited body, shows your customers and partners that your organization manages security in a structured and audited way.

How Vailor equips your ISMS

Vailor equips the core of your ISMS: risk assessment, run in EBIOS RM or as a flash assessment, with fields prefilled by AI from your documents and validated by your experts. Only the business owner named on the assessment accepts each residual risk, one by one. Risks feed a register linked to the treatment plan, where each measure carries its effort, cost and priority; its evidence is reviewed, the AI proposes a cited verdict and a person decides. On the compliance side, the ISO 27001 framework is planned in the Vailor Control Framework: each Annex A control will become a control maintained once, linked to its evidence, its actions and the other frameworks that ask for it, such as NIS2 or DORA. You approach certification and surveillance audits with an up-to-date risk assessment and treatment plan.

Why a traceable ISO 27001 platform built in France

An ISMS rests on trust and traceability. In Vailor, the AI proposes and your experts decide: when the AI relies on your documents, it quotes the passage, and Vailor checks word for word that it is there, and every decision is recorded in an audit log with no delete function you can show the auditor. Every export carries the assessment's protection marking. As SaaS, data is stored in France (AWS Paris region) and AI processing runs on AWS Bedrock in EU regions. Vailor also installs on your premises (Docker), with the AI model of your choice. You choose where your ISMS data lives.

An ISO 27001 platform to run your ISMS

The AI proposes, your experts decide

The AI prefills your risk assessment from your documents, your experts validate every field.

Tracked treatment plan

Each risk is linked to its measures in the action plan, with effort, cost and a priority from P1 to P4.

EBIOS RM risk analysis

Run your ISMS risk assessment in EBIOS RM or as a flash assessment.

Data stored in France

As SaaS, data stored in France (AWS Paris region), or installed on your premises, with an audit log with no delete function.

The benefits of the Vailor ISO 27001 tool

Risk assessment in EBIOS RM or as a flash assessment
A risk register linked to the treatment plan
ISO 27001 framework planned in the Vailor Control Framework
A risk assessment that also feeds your NIS2 or DORA work
PDF, Word and PowerPoint exports for your management reviews
Data stored in France as SaaS, or installed on your premises

Frequently asked questions about ISO 27001

What is the difference between ISO 27001 and ISO 27002?

ISO/IEC 27001 is the requirements standard: it sets out what an ISMS must contain, and it is the one you are certified against. ISO/IEC 27002 is a guidance document that explains, control by control, how to implement what Annex A of ISO 27001 lists. No body issues an ISO 27002 certificate. In practice the audit is conducted against ISO 27001, while your team works from ISO 27002 as the implementation handbook.

How many controls are in Annex A of ISO 27001?

The ISO/IEC 27001:2022 edition reorganised Annex A into 93 controls grouped under four themes: organisational, people, physical and technological. The 2013 edition listed 114 controls across 14 clauses. None of them applies automatically: you select the controls your risk assessment justifies and record the reasoning for every exclusion in the statement of applicability, usually the first document an auditor opens.

Is ISO 27001 certification mandatory, and for whom?

No. ISO 27001 is a voluntary standard and no general law requires certification. What makes it necessary is usually commercial: contract clauses, tenders and customer security questionnaires. The organisations that need it first are therefore those selling to large accounts, regulated firms or the public sector. It also gives you a documented base when answering NIS2 or DORA, though a certificate is not in itself evidence of compliance with them: their own obligations still have to be demonstrated separately.

How does an ISO 27001 certification audit work?

The initial audit is carried out by an accredited certification body and comes in two stages. Stage 1 is largely documentary: it checks that the ISMS exists and that the statement of applicability holds together. Stage 2 examines whether the selected controls actually work. The certificate then runs on a three-year cycle, with surveillance audits in between and a recertification audit at the end, so the ISMS has to stay current all year rather than wake up before each visit.

Which risk assessment method does ISO 27001 require?

None in particular. The standard asks for a defined, documented and repeatable risk assessment process with explicit acceptance criteria, but leaves the choice of method open. ISO/IEC 27005 offers guidelines, and the EBIOS Risk Manager method, published by the French national cybersecurity agency ANSSI, is widely practised in France. What the auditor tests is not the method itself, but whether you apply it consistently from one year to the next.

Is a spreadsheet enough to run an ISO 27001 ISMS?

Enough to start, rarely enough to sustain. A current ISMS means keeping risks, selected controls, the treatment plan and the supporting evidence connected at all times. Once those links are spread across separate workbooks, the statement of applicability drifts out of step and the evidence gathered for the initial audit quietly ages without anyone noticing. A dedicated tool also keeps a dated trail of who decided what, which a shared file cannot produce on demand.

What does AI actually do inside an ISO 27001 tool?

In Vailor, it works on the risk assessment: the AI reads your documents (architecture, policies, contracts) and prefills the analysis fields from excerpts, which cuts the matching and copying work. The compliance side does not rely on generative AI: your controls, evidence and actions stay in your teams' hands. The judgement stays human: you decide the exclusions and defend them in front of the auditor. It should not be confused with ISO/IEC 42001, published in 2023, which covers the management of AI systems themselves.

Build your ISO 27001 ISMS with Vailor

Book 30 minutes with us: we listen to your context and tell you concretely how Vailor fits into your ISMS.

Book a demo