Abstract
As a GRC and RegTech SaaS provider trusted by organisations to manage their own risk, compliance and information security obligations, calQrisk held itself to the same standard it expects of its customers. Pursuing ISO 27001 certification for its Information Security Management System (ISMS), the company made a deliberate decision. Rather than run the certification project on spreadsheets, shared drives and email trails (the very approach calQrisk exists to replace) it would build and operate its entire ISMS on the calQrisk platform itself.
The result was a live, auditable system of record covering risk and control registers aligned to ISO 27001 Annex A, IT and data asset registers, minuted ISMS management meetings with tracked actions and a structured incident management process with customised forms and automated alerts. What started as an internal compliance exercise became one of the clearest demonstrations of the platform's own capability.
Challenges
As a software vendor holding sensitive risk and compliance data on behalf of organisations, calQrisk faced growing expectations to formally demonstrate the strength of its information security practices. Increasingly, questionnaires from clients asked not just what calQrisk's platform could do for them but how the company secured its own environment.
Achieving ISO 27001 certification meant building a full Information Security Management System from the ground up:
- Identifying and classifying information assets, physical and logical
- Running risk and control assessments aligned with Annex A
- Establishing a legal and contractual requirements registers
- Setting up document control for policies and procedures
- Conducting IT Compliance and Internal Audits
- Delivering and recording information / cyber awareness training
- Managing Role Based Access Control (RBAC)
- Managing Third Parties and knowing the dependencies
- Instituting a regular cadence of ISMS management review meetings
- Standing up a formal incident management process
- And more
Like any growing SaaS company, there was limited internal resource to dedicate to running this as a parallel manual exercise. Spreadsheets and shared documents would have made it difficult to keep registers current, to prove that meetings and actions were actually happening and being closed out, and to produce a coherent evidence trail at audit time.
The Solution
calQrisk's answer was to configure and run its ISMS entirely within its own platform. The modules used include:
Risk, Controls & Tasks – A dedicated risk and control register was built and mapped directly to ISO 27001 Annex A control objectives rather than adapted from a generic template. Risks are assessed consistently against an established impact and likelihood matrix, controls are linked to the risks they mitigate and the register updates in real time as new risks are identified or controls are tested. Gaps in controls (absent or not effective) were identified and tasks were created and assigned to individuals for completion.
Registers (Asset Management) – calQrisk maintains its IT asset register and data asset registers on the platform covering the hardware, software, systems and data holdings that fall within ISMS scope. A Legal and Contractual Requirements Register captures applicable Irish and EU legislation and a software asset register tracks the SaaS tools used across the business. Keeping these on the platform rather than in disconnected spreadsheets means ownership, review dates and links to related risks are all visible in one place. In addition to this, all training activities are recorded in the system, making it easy to demonstrate the commitment to ongoing information security awareness
Meetings – ISMS management review meetings are scheduled, recorded and minuted directly on the platform. Rather than minutes living in a document store disconnected from the ISMS, actions arising from each meeting are assigned to named owners with due dates and tracked to closure within the same system that holds the risks and controls those actions relate to. Ultimately, giving a clear, auditable line from a meeting decision to the register it affected.
Incidents – A structured incident management process was configured on the platform, including customised incident forms tailored to the categories of security incident relevant to calQrisk's environment. Automated alerts were configured to ensure the right people are notified as soon as an incident is logged. Incidents can be linked to the relevant risks and controls so that recurring issues feed back into the risk register and control effectiveness can be reassessed where needed.
Third Parties – All third parties contract details and details regarding the services provided are recorded in the system. Links to services that depend on the third parties are easily made allowing for a total picture of operations and dependencies to be created.
Audits – Using the Audit module we created checklists, scheduled audits and began conducting regular IT compliance and internal audits to check that we were following our own policies and procedures. We input the "Opportunities for Improvement", identified in Stage 1, as "Findings" and closed off these improvements before Stage 2 (of the certification audit).
Implementation
The ISMS build was carried out internally by the calQrisk team using the same configuration options available to every customer and no bespoke development was required. Registers were populated, audits were conducted, meeting and minuting workflows were set up for the ISMS management review cycle, and the incident module was configured with forms and alert rules specific to calQrisk's own risk profile. Because the team was configuring the platform it also builds and supports, the implementation doubled as a practical stress-test of the product from a genuine end-user's perspective.
Results
Running its ISMS on its own platform gave calQrisk a single, real-time source of truth for its ISO 27001 programme. Risks, controls, assets, audits, training, meetings, actions and incidents are all in one auditable system rather than scattered across spreadsheets and email. At audit time, evidence of control operation, meeting governance and incident handling was available at the touch of a button rather than assembled under time pressure.
Beyond the certification itself, the exercise gave calQrisk a first-hand, ongoing proof point to offer prospective and existing customers. The same registers, meeting workflows and incident process that underpin its own ISO 27001 certification are available to any organisation running its ISMS on calQrisk.