Back to Writing

From Chaos to Compliance: An Unexpected Journey with ISO, SOC, and AI Tools

How a functioning ISMS became a continuously operated, evidenced, measurable, audit-ready security programme.

Original LinkedIn version

(or: how I stopped worrying and learned to love compliance)

When I joined Dayshape in 2022 as IT & Cyber Security Manager, the organisation already had ISO 27001 certification and a functioning ISMS in place. But like many scale-ups, the company had grown fast, customer expectations had evolved, and the level of structure needed in governance and control operation needed to mature with it. This is a story of how we took a solid starting point — and levelled it up into something continuously operated, evidenced, measurable and audit-ready. And in the process, made compliance something that supported the business rather than slowed it down.

Into the Fire

I started working at Dayshape just weeks before our first surveillance audit for ISO 27001:2013. The previous manager had left (I imagine they’re sipping cocktails somewhere, blissfully free of audit and compliance headaches), and ownership of the Information Security Management System (ISMS) had landed with the Operations Team leader. Lovely person, but not someone who gets excited about firewall logs, patching or access control reviews.

The ISMS was complete and it was accurate, if not vague. It was comprehensive in that the blanket statements and policies covered the required controls, but it was all very “generic”. There was some history (which I have still not dug into) around the compilation of documentation and the accreditation, but at least there were documents to start with, all piled into a “ISO” folder on Google Drive.

Year One: Aftermath Part 2

My first job was to find the bodies, and what better way to do so than to run an internal audit. Imagine arriving at a party after everyone’s gone home: cups everywhere, mystery stains on the carpet, and someone’s left their shoe behind. That was our ISMS. The documents hadn’t been touched since the auditor certified the organisation’s compliance some 10 months prior.

My initial audit helped to highlight the areas where evidence was lacking, some policies were being generous and/or deliberately obtuse and information registers lacked information. By the time I’d reached these conclusions though I’d managed to rope in another recruit to support the Ops manager and myself. The poor soul was overheard mentioning their involvement in an ISO 27001 audit in a former life. Together we pulled enough of the ISMS back together to face the external auditors for the Surveillance audit.

The Surveillance audit turned up a few minor non-conformities. Nothing catastrophic, but enough to remind us that “ISO” doesn’t stand for “It’s Sort Of fine.”

But we survived. I still remember the sigh of relief, and the feedback from the auditor about “areas for improvement” (translation: please tidy this up before I come back).

Year Two: From Shoebox to SharePoint

I decided we needed structure. Enter SharePoint. Yes, I know, I’m assuming a groan rattled through your mind if not your mouth at the mention of that word. But when configured properly, SharePoint is like moving from a shoebox of receipts to an actual filing cabinet.

Here’s what we built:

This aligned with industry best practice: centralised, searchable, secure. It also meant we could stop playing “Where’s Wally?” every time an auditor asked for a copy of the Business Continuity Plan.

And with a couple of years of compliance and audits came need to demonstrate an effort to maintain ongoing training and awareness throughout the organisation. I was like a man possessed. I used Sooty and sock puppets, I read a bedtime story about updating policies wearing a dressing gown, I took the opening of Spongebob Squarepants and re-recorded my own lyrics to the song (Oh, who wants to hear more about our Policies? I-S-M-S!) and sure enough, no one could say that they hadn’t gone through awareness training!

By the time the second surveillance audit rolled around, we were in much better shape. The only non-conformity? Apparently, I couldn’t audit my own work and call it “independent.” Who knew?

Preparing for Renewal: Time to Get Serious

As the renewal of our ISO 27001 certificate approached, and the Senior Leadership Team were pushing for SOC 2 Type 2, I realised we needed more than duct tape and good intentions. We needed a compliance platform.

So, like any good IT Manager, I went shopping. We evaluated a handful of platforms for the functionality, guidance and support, usability and auditor compatibility.

After a round of demos, debates, and more coffee than I’d like to admit, we went with Vanta.

Why Vanta Won

Vanta wasn’t just shiny, it solved real problems:

For a one-person Security and Compliance team (hi, that’s me), this was game-changing. Suddenly, I had time to actually improve processes rather than chase down laptop encryption screenshots.

The Big Leap: ISO 27001:2022 and SOC 2 Type II

With Vanta in place, we weren’t just ready to update to ISO 27001:2022. We chased after SOC 2 Type II as well.

If you’re new to ISO27001 and SOC 2, here’s the quick version:

This was where Vanta’s continuous monitoring really paid off. Instead of trying to prove six months of discipline with one month of panic, we had a daily log of compliance evidence.

The Human Side of Compliance

Of course, tools only solve half the problem. The human side is harder.

We had migrated from Google Workspace to Microsoft 365 just 9 months earlier. Imagine spending months trying to convince staff who love Google Docs that SharePoint is better and proving it with a dedicated SharePoint site for the ISMS, that you then proceeded to tear apart to pull into an external tool… I’ve had easier conversations with toddlers about bedtime.

And then there was AI. We experimented with using AI to re-draft policies and structure documentation. On good days, it was brilliant, it wrote faster than I ever could. On bad days, it made up fake legal references or started quoting Star Wars. (“The trade federation shall invoke the droideka response to any Incidents reported…” nice try, AI)

But even these experiments proved useful. AI became a writing partner, helping to polish processes and cut down on busywork. I could quickly compare versions and different policies for conflicts. It also meant I could keep a sense of humour when buried under ISO clauses.

Lessons Learned (and a Few Laughs Along the Way)

Conclusion: From Compliance Burden to Business Trust

What started as a necessary maintenance cycle became a strategic transformation. We didn’t “fix a broken ISMS”, we evolved it. The business had matured, expectations had changed, and security maturity needed to grow with it. The biggest shift wasn’t tools or templates, it was moving from episodic evidence to continuous assurance.

Compliance isn’t about box-ticking. Done well, it becomes one of the clearest signals of trust to customers, audit partners and colleagues.

If you or your organisation is on that same journey my advice is simple:

Start small. Start structured. Let automation help you scale.

And remember: good security isn’t about passing audits — it’s about being ready every day.