Compliance · VISFO
Build your own ISO 27001 and SOC 2 risk registers — without the spreadsheet sprawl.
Two frameworks, one method
Build ISO 27001 registers mapped to Annex A (2022) and SOC 2 registers mapped to the Trust Services Criteria — using the same guided scoring model.
Private by default
Registers are visible only to the person who created them, enforced in the database. Administrators grant access; they never read your content.
Explained as you go
Every field carries a tooltip, and the methodology and glossary sections explain inherent versus residual risk, treatment options and appetite in plain English.
Audit-ready exports
Export to Excel with instructions, scoring scales, the register itself and a change log — or to CSV for your GRC tool.
Consistent scoring, every time
Likelihood x impact, scored 1-5 and banded automatically — so two people assessing the same risk land in the same place.
ISO/IEC 27001
Aligned to the risk assessment and treatment requirements in ISO/IEC 27001 clauses 6.1.2, 6.1.3, 8.2 and 8.3, with Annex A (2022) controls.
SOC 2 (AICPA Trust Services Criteria)
Aligned to the AICPA Trust Services Criteria, evidencing the risk identification and mitigation activity expected under SOC 2 Type I/II — primarily CC3.x and CC9.x.