About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesSample ReportsRecords of Processing (ROPA)Data Privacy Impact AssessmentLegitimate Interests AssessmentTransfer Impact AssessmentPrivacy Risk AssessmentGDPR Gap AssessmentISO 27701 Gap AssessmentHIPAA Gap AssessmentGap AssessmentsBusiness Impact AnalysisISO 27001 Risk AssessmentContinuity Risk AssessmentEnterprise Risk AssessmentAI Risk AssessmentAI Impact AssessmentThird-Party Risk AssessmentAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Day: September 30, 2026

Third-party risk reporting dashboard with vendor tiers, open findings, overdue assessments and concentration

Third-Party Risk Reporting Guide 2026

Governance Docs30th September 2026

How to design third-party risk reporting: audiences, key metrics, tiering views, concentration, findings, exceptions and how to present…
Read More
AI bias testing workflow from defining groups to metrics, thresholds, remediation and monitoring

AI Bias Testing Guide 2026: Methods and Records

Governance Docs30th September 2026

How to run AI bias testing: define groups and outcomes, choose metrics, build test data, set thresholds, investigate…
Read More
Risk culture assessment showing leadership, communication, accountability and incentives around a risk management program

Risk Culture Guide 2026: Assess and Improve It

Governance Docs30th September 2026

What risk culture is, why it decides whether enterprise risk management works, how to assess it with surveys…
Read More
RoPA joint controllers diagram of two organizations sharing purposes and means with an Article 26 arrangement

RoPA and Joint Controllers Guide 2026

Governance Docs30th September 2026

How to handle RoPA joint controllers: when controllership is joint, what Article 26 requires, what to record in…
Read More
Maximum tolerable period of disruption timeline showing impact growth, RTO and MTPD for a critical activity

Maximum Tolerable Period of Disruption Guide 2026

Governance Docs30th September 2026

What the maximum tolerable period of disruption is, how it differs from RTO and RPO, how to set…
Read More
ISO 27001 risk acceptance flow from residual risk rating through criteria check to owner approval and record

ISO 27001 Risk Acceptance Criteria Guide 2026

Governance Docs30th September 2026

How ISO 27001 risk acceptance works: criteria under clause 6.1.2, owner approval under 6.1.3, thresholds, exceptions, records, review…
Read More
Gap assessment prioritization matrix comparing risk reduction against effort with quick wins and major projects

Gap Assessment Prioritization Guide 2026

Governance Docs30th September 2026

How to prioritize gaps after an assessment: risk, regulatory exposure, effort, dependencies, quick wins, scoring, sequencing into waves…
Read More
Privacy risk appetite scale with acceptable, tolerable and unacceptable levels for privacy risks

Privacy Risk Appetite Guide 2026: Setting Limits

Governance Docs30th September 2026

How to set privacy risk appetite: appetite versus tolerance, choosing categories, writing statements, linking to scoring and approvals,…
Read More
Pandemic risk assessment scenario table showing absence levels supplier disruption and response triggers

Pandemic Risk Assessment Guide 2026 for Business Continuity

Governance Docs30th September 2026

How to run a pandemic risk assessment for business continuity: scenarios, absence assumptions, critical roles, suppliers, remote work,…
Read More
Third-party AI impact assessment showing vendor documentation, deployment context, impact rating and contract controls

Third-Party AI Impact Assessment Guide 2026

Governance Docs30th September 2026

How to run a third-party AI impact assessment for vendor models: scoping, supplier questions, evidence gaps, contract terms,…
Read More
RoPA for HR processing table of recruitment payroll benefits and absence with purposes and retention

RoPA for HR Processing Guide 2026

Governance Docs30th September 2026

How to build a RoPA for HR processing: recruitment, payroll, benefits, absence, monitoring, special category data, retention, recipients…
Read More
Risk aggregation diagram combining individual risks by category, cause and business unit into a portfolio view

Risk Aggregation Guide 2026: Portfolio View of Risk

Governance Docs30th September 2026

How risk aggregation works in enterprise risk management: grouping methods, common causes, correlation, simple scoring and quantitative options,…
Read More
    ←
  • 1
  • …
  • 5
  • 6
  • 7
  • 8
  • 9
  • →

Recent Posts

Gap assessment reassessment progress comparison diagram
Gap Assessment Reassessment: The Essential 2026 Guide to Measuring Progress

September 30, 2026

Business continuity supply chain risk map diagram
Business Continuity Supply Chain Risk: The Essential 2026 Guide to Resilient Suppliers

September 30, 2026

Business continuity risk appetite statement diagram
Business Continuity Risk Appetite: The Essential 2026 Guide to Setting Tolerance for Disruption

September 30, 2026

Business continuity risk monitoring indicators diagram
Business Continuity Risk Monitoring: The Essential 2026 Guide to Indicators and Reviews

September 30, 2026

Business continuity scenario planning steps diagram
Business Continuity Scenario Planning: The Essential 2026 Guide to Testing Your Plans

September 30, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • Assessments
  • Sample reports
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
  • Manage cookies
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA