Skip to main content
Free working documents

Compliance Templates and Checklists

Download five public compliance worksheets for SOC 2 readiness, ISO 27001 gaps, HIPAA risk assessment, audit evidence, and security policies.

Get a readiness snapshot

Download a starting point for your review

These public resources are Markdown documents that you can save and adapt in a text editor or document tool. No account is required to download them. They provide a structure for planning; completing a template does not establish compliance or produce an audit opinion.

ResourceUse it toDownload
SOC 2 readiness scorecardOrganize control questions before a readiness discussionDownload scorecard
ISO 27001 gap assessment checklistCompare your management system and controls with the scope being consideredDownload checklist
HIPAA risk assessment templateRecord systems, risks, ownership and follow-up questionsDownload template
Audit evidence checklistAssign sources and reviewers to evidence needsDownload checklist
Security policy templatesDraft policies for review against actual operationsDownload policy pack

Adapt before approving

Replace example assumptions with your own systems, responsibilities, and review cadence. Remove sections only after establishing that they do not apply, and retain the reasoning. A policy that commits to a process your team cannot operate creates an additional gap.

Have the accountable owner review the draft and confirm how it will be implemented. Where interpretation depends on a law, contract, or assessment requirement, involve the appropriate counsel or assessor. Keep credentials and sensitive records out of broadly shared working copies.

Connect the document to evidence

For each commitment, identify how a reviewer will know it happened. An access-review policy needs an account population, reviewer, decision record, and follow-up process. A recovery plan needs a way to exercise the relevant recovery steps and document the result.

Retain a version, owner, approval date, and next review trigger. When your systems change, revisit both the document and the operating process. A signed template should be the beginning of an accountable workflow, not its final evidence.

Use the readiness tool for an initial self-assessment, explore policy gap analysis, or discuss implementation help.