About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Day: September 2, 2026

The ISO 27001 maturity assessment explained

ISO 27001 Maturity Assessment: A Clear Guide to 6 Levels

Governance Docs02nd September 2026

An ISO 27001 maturity assessment scores how well a control works, not whether it exists. The 6 levels,…
Read More
The NQA-1 corrective action program

Corrective Action Program: A Clear NQA-1 Guide for 2026

Governance Docs02nd September 2026

A corrective action program turns on one classification decision. What conditions adverse to quality require, what significant ones…
Read More
Special characteristics in IATF 16949

Special Characteristics: A Clear IATF 16949 Guide to All 6 Documents

Governance Docs02nd September 2026

Special characteristics are one designation flowing through 6 documents. Where each must appear, what it obliges, and the…
Read More
DORA subcontracting and the 2025 RTS

DORA Subcontracting: A Clear Guide to the 2025 RTS

Governance Docs02nd September 2026

DORA subcontracting under Regulation (EU) 2025/532: what the RTS requires, why the chain is now the unit of…
Read More
The HIPAA breach risk assessment explained

Breach Risk Assessment: A Clear Guide to the 4 HIPAA Factors

Governance Docs02nd September 2026

A HIPAA breach risk assessment starts with 3 exclusions, then the 4 factors in 45 CFR 164.402 -…
Read More
External providers under ISO 9001 clause 8.4

External Providers: A Clear Guide to ISO 9001 Clause 8.4

Governance Docs02nd September 2026

External providers under ISO 9001 clause 8.4: the 3 sub-clauses, how to band control by effect on conformity,…
Read More
NCA ECC implementation step by step

NCA ECC Implementation: A Clear Guide in 6 Steps

Governance Docs02nd September 2026

NCA ECC implementation in 6 steps: scope, gap assessment, governance, remediation, internal review and assessment - plus the…
Read More
ISO 13485 purchasing and supplier controls

ISO 13485 Purchasing: A Clear Guide to Clause 7.4

Governance Docs02nd September 2026

ISO 13485 purchasing in 3 parts: supplier evaluation, purchasing information and verification - plus the change-notification agreement most…
Read More
The AI system impact assessment explained

AI System Impact Assessment: A Clear Guide to ISO 42005

Governance Docs02nd September 2026

An AI system impact assessment looks outward, not inward. What ISO/IEC 42005:2025 asks for in 7 steps, how…
Read More
Threat intelligence and ISO 27001 control 5.7

Threat Intelligence: A Clear Guide to ISO 27001 Control 5.7

Governance Docs02nd September 2026

Threat intelligence under ISO 27001 control 5.7: the 3 levels, the 5 artefacts that make it auditable, and…
Read More
The plan of action and milestones explained

Plan of Action and Milestones: A Clear POA&M Guide for 2026

Governance Docs02nd September 2026

A plan of action and milestones in 9 fields, where the POA&M is still required in 2026, where…
Read More
The cloud shared responsibility matrix

Shared Responsibility Matrix: A Clear Guide for ISO 27017

Governance Docs02nd September 2026

A shared responsibility matrix decides who patches, configures and restores. What goes in it across IaaS, PaaS and…
Read More
    ←
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • …
  • 8
  • →

Recent Posts

The gifts and hospitality policy explained
Gifts and Hospitality: A Clear ISO 37001 Guide for 2026

September 2, 2026

ISO 27018 cloud privacy explained
ISO 27018: A Clear Guide to the 2025 Cloud Privacy Rules

September 2, 2026

The ISO 21001 internal audit checklist
ISO 21001 Internal Audit: A Clear Checklist for 2026

September 2, 2026

Authorised Economic Operator status explained
Authorised Economic Operator: A Clear Guide to the 4 Tests

September 2, 2026

CSA STAR Level 2 explained
STAR Level 2: A Clear Guide to Certification vs Attestation

September 2, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA