Compliance Templates and Checklists
Download five public compliance worksheets for SOC 2 readiness, ISO 27001 gaps, HIPAA risk assessment, audit evidence, and security policies.
Get a readiness snapshotDownload a starting point for your review
These public resources are Markdown documents that you can save and adapt in a text editor or document tool. No account is required to download them. They provide a structure for planning; completing a template does not establish compliance or produce an audit opinion.
| Resource | Use it to | Download |
|---|---|---|
| SOC 2 readiness scorecard | Organize control questions before a readiness discussion | Download scorecard |
| ISO 27001 gap assessment checklist | Compare your management system and controls with the scope being considered | Download checklist |
| HIPAA risk assessment template | Record systems, risks, ownership and follow-up questions | Download template |
| Audit evidence checklist | Assign sources and reviewers to evidence needs | Download checklist |
| Security policy templates | Draft policies for review against actual operations | Download policy pack |
Adapt before approving
Replace example assumptions with your own systems, responsibilities, and review cadence. Remove sections only after establishing that they do not apply, and retain the reasoning. A policy that commits to a process your team cannot operate creates an additional gap.
Have the accountable owner review the draft and confirm how it will be implemented. Where interpretation depends on a law, contract, or assessment requirement, involve the appropriate counsel or assessor. Keep credentials and sensitive records out of broadly shared working copies.
Connect the document to evidence
For each commitment, identify how a reviewer will know it happened. An access-review policy needs an account population, reviewer, decision record, and follow-up process. A recovery plan needs a way to exercise the relevant recovery steps and document the result.
Retain a version, owner, approval date, and next review trigger. When your systems change, revisit both the document and the operating process. A signed template should be the beginning of an accountable workflow, not its final evidence.
Use the readiness tool for an initial self-assessment, explore policy gap analysis, or discuss implementation help.