From Chaos to Compliance: An Unexpected Journey with ISO, SOC, and AI Tools
How a functioning ISMS became a continuously operated, evidenced, measurable, audit-ready security programme.
Original LinkedIn version(or: how I stopped worrying and learned to love compliance)
When I joined Dayshape in 2022 as IT & Cyber Security Manager, the organisation already had ISO 27001 certification and a functioning ISMS in place. But like many scale-ups, the company had grown fast, customer expectations had evolved, and the level of structure needed in governance and control operation needed to mature with it. This is a story of how we took a solid starting point — and levelled it up into something continuously operated, evidenced, measurable and audit-ready. And in the process, made compliance something that supported the business rather than slowed it down.
Into the Fire
I started working at Dayshape just weeks before our first surveillance audit for ISO 27001:2013. The previous manager had left (I imagine they’re sipping cocktails somewhere, blissfully free of audit and compliance headaches), and ownership of the Information Security Management System (ISMS) had landed with the Operations Team leader. Lovely person, but not someone who gets excited about firewall logs, patching or access control reviews.
The ISMS was complete and it was accurate, if not vague. It was comprehensive in that the blanket statements and policies covered the required controls, but it was all very “generic”. There was some history (which I have still not dug into) around the compilation of documentation and the accreditation, but at least there were documents to start with, all piled into a “ISO” folder on Google Drive.
Year One: Aftermath Part 2
My first job was to find the bodies, and what better way to do so than to run an internal audit. Imagine arriving at a party after everyone’s gone home: cups everywhere, mystery stains on the carpet, and someone’s left their shoe behind. That was our ISMS. The documents hadn’t been touched since the auditor certified the organisation’s compliance some 10 months prior.
My initial audit helped to highlight the areas where evidence was lacking, some policies were being generous and/or deliberately obtuse and information registers lacked information. By the time I’d reached these conclusions though I’d managed to rope in another recruit to support the Ops manager and myself. The poor soul was overheard mentioning their involvement in an ISO 27001 audit in a former life. Together we pulled enough of the ISMS back together to face the external auditors for the Surveillance audit.
The Surveillance audit turned up a few minor non-conformities. Nothing catastrophic, but enough to remind us that “ISO” doesn’t stand for “It’s Sort Of fine.”
But we survived. I still remember the sigh of relief, and the feedback from the auditor about “areas for improvement” (translation: please tidy this up before I come back).
Year Two: From Shoebox to SharePoint
I decided we needed structure. Enter SharePoint. Yes, I know, I’m assuming a groan rattled through your mind if not your mouth at the mention of that word. But when configured properly, SharePoint is like moving from a shoebox of receipts to an actual filing cabinet.
Here’s what we built:
- Lists: asset registers, risk logs, Opportunities For Improvements, Non-Conformities and general control tracking.
- Pages: policies and governance documents (version-controlled and access-managed).
- Document Libraries: evidence storage with clear permissions.
This aligned with industry best practice: centralised, searchable, secure. It also meant we could stop playing “Where’s Wally?” every time an auditor asked for a copy of the Business Continuity Plan.
And with a couple of years of compliance and audits came need to demonstrate an effort to maintain ongoing training and awareness throughout the organisation. I was like a man possessed. I used Sooty and sock puppets, I read a bedtime story about updating policies wearing a dressing gown, I took the opening of Spongebob Squarepants and re-recorded my own lyrics to the song (Oh, who wants to hear more about our Policies? I-S-M-S!) and sure enough, no one could say that they hadn’t gone through awareness training!
By the time the second surveillance audit rolled around, we were in much better shape. The only non-conformity? Apparently, I couldn’t audit my own work and call it “independent.” Who knew?
Preparing for Renewal: Time to Get Serious
As the renewal of our ISO 27001 certificate approached, and the Senior Leadership Team were pushing for SOC 2 Type 2, I realised we needed more than duct tape and good intentions. We needed a compliance platform.
So, like any good IT Manager, I went shopping. We evaluated a handful of platforms for the functionality, guidance and support, usability and auditor compatibility.
After a round of demos, debates, and more coffee than I’d like to admit, we went with Vanta.
Why Vanta Won
Vanta wasn’t just shiny, it solved real problems:
- Control Clarity: Vanta highlighted the controls, test and documents required to demonstrate compatibility and compliance with the chosen standard(s)
- Automated Evidence Collection: Instead of begging colleagues for screenshots at 4pm on a Friday, Vanta connected directly into Microsoft 365, Intune, Azure and HR systems. Evidence? Collected. Automatically.
- Continuous Monitoring: No more mad scrambles before audit week. Controls were checked daily. I slept better.
- Task Management: Dashboards, reminders, assignments, integration with Jira. Finally, compliance tasks were visible and (mostly) done. It was considerably easier to delegate tasks using Jira linked back into the relevant controls and remediations.
- Scalability: Whether ISO 27001, SOC 2, or something new down the line, one platform could handle it.
For a one-person Security and Compliance team (hi, that’s me), this was game-changing. Suddenly, I had time to actually improve processes rather than chase down laptop encryption screenshots.
The Big Leap: ISO 27001:2022 and SOC 2 Type II
With Vanta in place, we weren’t just ready to update to ISO 27001:2022. We chased after SOC 2 Type II as well.
If you’re new to ISO27001 and SOC 2, here’s the quick version:
- SOC 2 Type I: You say you’re secure.
- ISO27001: You align your systems with an internationally approved and recognised set of controls. An auditor compares the standard with evidence of your controls annually.
- SOC 2 Type II: You prove you’re secure, continuously, over six months or more. (Imagine an auditor moving into your office and watching everything you do. Uncomfortable, but effective.)
This was where Vanta’s continuous monitoring really paid off. Instead of trying to prove six months of discipline with one month of panic, we had a daily log of compliance evidence.
The Human Side of Compliance
Of course, tools only solve half the problem. The human side is harder.
We had migrated from Google Workspace to Microsoft 365 just 9 months earlier. Imagine spending months trying to convince staff who love Google Docs that SharePoint is better and proving it with a dedicated SharePoint site for the ISMS, that you then proceeded to tear apart to pull into an external tool… I’ve had easier conversations with toddlers about bedtime.
And then there was AI. We experimented with using AI to re-draft policies and structure documentation. On good days, it was brilliant, it wrote faster than I ever could. On bad days, it made up fake legal references or started quoting Star Wars. (“The trade federation shall invoke the droideka response to any Incidents reported…” nice try, AI)
But even these experiments proved useful. AI became a writing partner, helping to polish processes and cut down on busywork. I could quickly compare versions and different policies for conflicts. It also meant I could keep a sense of humour when buried under ISO clauses.
Lessons Learned (and a Few Laughs Along the Way)
- Don’t rely on “final_FINAL_v3.docx.” If your policies don’t have version control, your auditor will spot it before you do.
- Independence matters. Apparently auditing yourself doesn’t count. Who knew?
- Compliance platforms are worth their weight in coffee. Vanta turned my role from “compliance janitor” to “compliance strategist.”
- ISO ≠ IT-only. The ISMS touches every department. While HR, Finance, and Operations may be more obviously called upon, the Product and Development teams are responsible for a considerable number of risks, as are the Marketing, Commercial and Customer Experience teams. The sooner you involve them, the fewer surprises await you later.
- Humour helps. Whether it’s staff groaning about SharePoint or AI quoting sci-fi, a little levity makes compliance less painful. You might not want to customise the Spondebob opening song, or read a bedtime story to your colleagues, but it’s certainly kept Information Security on the radar…!
Conclusion: From Compliance Burden to Business Trust
What started as a necessary maintenance cycle became a strategic transformation. We didn’t “fix a broken ISMS”, we evolved it. The business had matured, expectations had changed, and security maturity needed to grow with it. The biggest shift wasn’t tools or templates, it was moving from episodic evidence to continuous assurance.
Compliance isn’t about box-ticking. Done well, it becomes one of the clearest signals of trust to customers, audit partners and colleagues.
If you or your organisation is on that same journey my advice is simple:
Start small. Start structured. Let automation help you scale.
And remember: good security isn’t about passing audits — it’s about being ready every day.