Agentic compliance for ISO 27001

ISO 27001, from scope to certificate. Run by agents.

ISO/IEC 27001 asks for an information security management system: a defined scope, risk assessment and treatment, a Statement of Applicability and proof that it works. Teddy's agents build each part from your real systems, and a compliance engineer takes you through the certification audit.

93 controlsEach one checked against your systems
CertificatePlanned from scope to audit
Every weekA full check of where you stand
What ISO 27001 asks for

Six building blocks.
Each one has a home in Teddy.

ISO/IEC 27001:2022 is a management system standard. Clauses 4 to 10 set the requirements for the ISMS. Annex A lists 93 reference controls that you compare your risk treatment against. Here is what each part asks for and where it lives in Teddy.

Clause 4Context and scope

Determine internal and external issues, interested parties and their requirements, and the boundaries of the ISMS.

In TeddyCompany model and scope, drafted by the Certification Agent
Clause 5Leadership

Top management demonstrates commitment, establishes the information security policy and assigns roles, responsibilities and authorities.

In TeddyPolicy and roles, approved by management and logged
Clause 6Risks and objectives

Assess information security risks, select a treatment for each and set information security objectives, measurable where practicable.

In TeddyRisk register linked to assets, vendors and controls
Clause 6.1.3Statement of Applicability

List the necessary controls, justify every inclusion and exclusion against Annex A and state whether each control is implemented.

In TeddyBuilt from your systems, updated with every gap audit
Annex A93 controls in four themes

Organizational, people, physical and technological controls. Those you declare applicable must be implemented, and their operation shown with evidence.

In TeddyEvidence Agent collects proof from connected tools
Clauses 9 and 10Evaluation and improvement

Monitoring and measurement, internal audits and management reviews at planned intervals, corrective action and continual improvement.

In TeddyGap Audit Agent runs weekly, findings become tasks
Initial auditStage 1Documentation and readiness
Initial auditStage 2Implementation and effectiveness
At least yearlySurveillance auditsDuring the three-year cycle
Before expiryRecertification auditRenews the certificate for three years
The problem

A standard, not a checklist.
And a deal that waits for it.

Customers ask for the certificate, but ISO 27001 has its own logic. Most teams lose months working out what the clauses mean for their company before they fix anything.

01The standard in plain language

The Certification Agent turns each requirement into a task with an owner and a due date.

02Which controls apply to you

Teddy suggests which controls you need and why. You make the final call.

03Proof for the auditor

The Evidence Agent collects records from your systems, with date and source.

04Spreadsheets, template packs and consultant hours. Still no SoA.

The SoA lives in an Excel file on version twelve, the policies come from a template pack, and the consultant bills by the hour. You ask ChatGPT for a scope statement, but it knows nothing about your systems. Teddy reads your real setup and builds the SoA, risks and policies from it.

How it works

From the first session to a certificate you can keep

Teddy's agents do the work clause by clause. You make the decisions, and a compliance engineer is there when the auditor arrives.

01 Certification Agent

Scope and plan in the first session

Teddy asks about your company, locations and systems and drafts the ISMS scope and a plan to the certificate. You adjust it, then approve.

ISMS scope · Acme Inc.Draft
LocationsBerlin, Lisbon
Systems in scope12
Interested parties7
TargetStage 1 in Q1
02 Gap Audit Agent

Risks and SoA from your real systems

Teddy assesses every Annex A control against what you actually run, builds the risk register and drafts the Statement of Applicability with a justification for each inclusion and exclusion.

Statement of ApplicabilityAnnex A
A.5 Organizational controls31 of 37
A.8 Technological controls26 of 34
Excluded, with justification6
Teddy: Each exclusion has a justification the auditor can follow. Two need your confirmation.
03 Policy Agent

Policies that match how you work

No template pack. The Policy Agent drafts each policy from your setup, so what is written matches what your team does.

PoliciesLinked to Annex A
Information security policyApproved
Access control policyDraft
Backup and restore policyDraft
Teddy: Your backups run daily in AWS. I wrote the policy to match what you actually do.
04 Evidence Agent

Evidence collected all year

The Evidence Agent pulls proof from connected tools on a schedule. When the auditor samples records, they are already there.

EvidenceLast 90 days
AWS backup jobsCurrent
Entra ID MFA reportCurrent
A.8.13 Restore testMissing
05 Gap Audit Agent

Map once, comply many

Controls you already run for SOC 2, TISAX® or NIS2 count for ISO 27001 too. Teddy maps every framework onto one control set and shows only what is new.

Shared controlsOne control set
Shared with SOC 258
Shared with TISAX®71
New for ISO 27001 only9
Teddy: The Statement of Applicability and the management review are new for you. Most of your SOC 2 evidence counts.
Never stuck

Ask what a clause means for you. Get the work done, not just an answer.

Ask in plain language what a clause means for you. Teddy answers from your live ISMS and does the work. For the certification audit, our compliance engineers are at your side.

1

Ask TeddyWhat does Clause 6 mean for us? Which controls can we exclude, and why? Teddy knows the standard and your setup.

2

Agents do the workScope, risks, SoA, policies and evidence arrive ready for your approval, each with its source.

3

Our team backs you upCompliance engineers help you choose a certification body and join you through Stage 1 and Stage 2.

TeddyAcme Inc. · ISO 27001
Are we ready for Stage 2?
Not yet. Stage 1 is closed and the SoA is approved. Two requirements still have no record:
  • Internal audit (Clause 9.2)Not started
  • Management review (Clause 9.3)Not scheduled
  • Statement of ApplicabilityApproved
Shall I plan the internal audit with your compliance engineer?
Plan internal auditAsk our team
CEYour compliance engineer joins Stage 1 and Stage 2 with you.
FAQ

Questions about ISO 27001

Does Teddy certify us?

No. An accredited certification body audits your ISMS and issues the certificate. Teddy builds and runs your ISMS and measures your evidence. We help you find a certification body, and a compliance engineer goes through the audit with you.

What is the difference between Stage 1 and Stage 2?

Stage 1 reviews your documented information, such as scope, policy, risk assessment and the Statement of Applicability, and checks whether you are ready for Stage 2. Stage 2 evaluates whether the ISMS, including the applicable controls, is implemented and effective.

We already have SOC 2. How much can we reuse?

A lot. Teddy maps both frameworks onto one control set, so evidence collected once counts for both. The gap audit shows what ISO 27001 adds, such as the Statement of Applicability, internal audit and management review.

What happens after certification?

The certificate is valid for three years. Surveillance audits take place at least once a year, and a recertification audit before expiry renews it. Teddy keeps running gap audits and collecting evidence, so each audit is routine, not a project.

Your ISO 27001, built from how you actually work.

Start with a gap audit against Annex A on your own systems.

Reviewed by Sven Moritz, former CISO · October 2026

What to expect

How long ISO 27001 takes, and how Teddy cuts it to weeks

Typical6 to 12 months

From kickoff to certificate. Most of the time goes into documentation and closing gaps.

With TeddyWithin weeks

Ready for Stage 1. Scope and plan in the first session, SoA and risk register from your real systems, evidence collected from day one.

  • What stays fixed: internal audit (9.2) and management review (9.3) before Stage 2, and the dates of the certification body. Book early, auditors are often booked weeks ahead.
  • Audit effort: the certification body calculates audit days from headcount and scope under ISO/IEC 27006-1. A tight scope means fewer days.
SMSven MoritzCo-founder of Teddy, former CISOLast reviewed: October 2026
From the audit room

What goes wrong in ISO 27001 audits

  1. The risk register is written once and never touched again.

    Auditors check whether it changed when the business did: a new cloud provider, a new office, a new product. Risk assessment and treatment are among the clauses with the most nonconformities.

  2. Internal audit and management review are left to the last two weeks.

    Both are required before Stage 2. Auditors want real findings and real decisions, not a signed template.

  3. The policy says one thing, the team does another.

    Auditors ask an engineer how access is granted and compare it with the written procedure. Not following your own procedures is a classic nonconformity, and template policies make it more likely.