Compliance · VISFO

Build your own ISO 27001 and SOC 2 risk registers — without the spreadsheet sprawl.

ISOSOC turns the risk register from a file someone forgot to update into a living, explained, exportable record. Each user gets their own private workspace, set up by your administrator.

Two frameworks, one method

Build ISO 27001 registers mapped to Annex A (2022) and SOC 2 registers mapped to the Trust Services Criteria — using the same guided scoring model.

Private by default

Registers are visible only to the person who created them, enforced in the database. Administrators grant access; they never read your content.

Explained as you go

Every field carries a tooltip, and the methodology and glossary sections explain inherent versus residual risk, treatment options and appetite in plain English.

Audit-ready exports

Export to Excel with instructions, scoring scales, the register itself and a change log — or to CSV for your GRC tool.

Consistent scoring, every time

Likelihood x impact, scored 1-5 and banded automatically — so two people assessing the same risk land in the same place.

Low · 1-4Medium · 5-9High · 10-14Critical · 15-25

ISO/IEC 27001

Aligned to the risk assessment and treatment requirements in ISO/IEC 27001 clauses 6.1.2, 6.1.3, 8.2 and 8.3, with Annex A (2022) controls.

SOC 2 (AICPA Trust Services Criteria)

Aligned to the AICPA Trust Services Criteria, evidencing the risk identification and mitigation activity expected under SOC 2 Type I/II — primarily CC3.x and CC9.x.