The ISO 27001 Audit page provides a comprehensive, interactive view of your organization's compliance posture against the ISO/IEC 27001:2022 framework. This centralized interface allows you to systematically review requirements across Clauses 4 through 10, monitor real-time progress
Go to app.maplegrc.com.
Log in with your account credentials.
Select ISO 27001 Audit from the left navigation sidebar.
Enter your foundational data " Context, Users, Assets, Roles & Responsibilities, Policies, Guidelines, Vendors, Risk Scenarios, Cyber Risk Strategy, and Supply Chain Governance" in their respective MapleGRC sections
Your evidence will appear here and be mapped to the appropriate clause in the standard.
If you update anything elsewhere (e.g., a new policy version), re-run the analyzer and attach the latest artifact to the relevant clause.
A progress chart showing counts for Implemented, Partially Implemented, Not Implemented, and more.
A comprehensive, clause-by-clause table designed to streamline your compliance tracking. The table organizes your audit requirements into the following columns:
ID & Requirements: Displays the specific ISO 27001:2022 clause requirement identifier alongside the official standard text.
Implementation Guide: Provides a pop-up with guidelines for implementing and auditing the clause.
Implementation Status: (e.g., Implemented, Partially Implemented, Not Started) to help you update and track your current progress.
Evidence: Includes a dedicated button to attach and manage supporting documentation directly to the requirement.
Note: Contains a text box for capturing specific observations, automated analysis results, notes, and other relevant information.
Click Run analyzer.
MapleGRC retrieves the latest data and evidence from related pages " Context, Users, Assets, Roles & Responsibilities, Policies, Guidelines, Vendors, Risk Scenarios, Cyber Risk Strategy, and Supply Chain Governance" and maps it to the relevant clauses.
When the analysis finishes, MapleGRC will prompt you to refresh the page.
Press Ctrl+R (Cmd+R on Mac) or click your browser’s Reload icon ⟳ to refresh the page.
2. Click Auto fill all to apply all suggested statuses based on the last analysis.
3. Review the changes and adjust any rows as needed before saving.
Click Export Report.
This downloads a report of the clause table (clause ID & Requirment , evidence guideline, status, notes).
Click Download Evidence Package.
Downloads all files you’ve attached as evidence for the clauses in this audit (mapped to the relevant clauses).
Use this to provide auditors or assessors with a complete evidence bundle.
Review what the Analyzer proposed and complete any gaps.
Review & amend Notes (if needed)
Open the Notes cell and edit the generated note, if needed. Then save it by click on disk icon
Change Status (if needed)
Use the Status dropdown to set the correct state:
Implemented • Partially Implemented • Not Implemented • Observation • Opportunity for improvement • Not Specified
Add Evidence, attach more files (if needed)
Click the Evidence button (shows the current count, e.g., (1) Evidence).
Attach a new file or select an existing item from Evidence Manager.
You will be given the option to either upload an attachment from your existing company profile files or add a new file.
If you choose to upload from existing files, a list of all previously generated or uploaded files in your company profile will be displayed.
Select the desired file from the list
Click Add new File to upload a file from your computer.
From the Tag dropdown, choose one of: Policy, Procedure, Record, Checklist, or Other (specify).
Then, Click Upload Files
Shows your current status
The progress chart and clause statuses (Implemented / Partially Implemented / Not Implemented, etc.) tell you exactly where you stand and what’s left.
Analyzer to pull the latest updates and Auto fill all to apply proposed statuses in relevant clause.
Creates auditor-ready outputs
One click to Export Report and Download Evidence Package; everything an assessor needs, mapped to the right clauses.