Skip to content
compliancebase

Templates

Auditors do not just want controls in place — they want the documented policy that says the control is supposed to exist, dated and version-controlled. These templates are starting drafts for that documentation layer: access control policies, incident response plans, and the other written artifacts that show up on evidence request lists across SOC 2 and ISO 27001 engagements.

Every template is a starting point, not a finished policy. Auditors check that a policy matches what you actually do, not that it uses particular boilerplate — a template copied verbatim without editing the placeholders to reflect your real process is a common audit finding, not a shortcut past one. Read the corresponding control page for what the policy needs to cover before you adapt the template.

Each template is published as readable HTML on its own page, which is the canonical version for reference and search. Download the .docx copy when you need to edit placeholders and get a document ready for internal sign-off.