# Governance Docs | Full Content Reference for AI (llms-full.txt) > Governance Docs LLC (Albuquerque, New Mexico, USA) provides auditor-written, instantly editable Microsoft Word/Excel ISO & compliance documentation toolkits (most $99-$199) spanning 70+ frameworks. This file is the full-text companion to https://governancedocs.com/llms.txt and contains the complete toolkit catalog for AI ingestion. ## About Governance Docs Governance Docs LLC sells ready-to-use compliance documentation toolkits: editable Microsoft Office (Word/Excel) templates - policies, procedures, registers, checklists, risk assessments and audit plans - mapped to ISO standards and regulatory frameworks. Toolkits are authored by a CISSP-certified GRC auditor, delivered as an instant download after purchase, and licensed for use across your own organization (and, for consultants, across client engagements). - Website: https://governancedocs.com/ - About: https://governancedocs.com/about-governance-docs/ - Contact: https://governancedocs.com/contact-governance-docs/ - Delivery & terms: instant download after purchase; 30-day money-back guarantee; secure Stripe checkout; templates in Microsoft Word (.docx) and Excel (.xlsx). ## Toolkits (full catalog) ### Comprehensive AS 9100/9110/9120 Aerospace QMS Toolkit – 38 Templates URL: https://governancedocs.com/product/as-9100-toolkit/ Price: $99 USD AS 9100 Toolkit delivers 38 ready-to-use Microsoft Office templates covering quality policy, product safety, counterfeit parts prevention, design and development, configuration management, supplier management, identification and traceability, calibration, production control, nonconforming output, first article inspection, FOD prevention, and special processes. Accelerate your AS 9100 compliance programme with a complete, audit-ready AS 9100 compliance documentation foundation built for aerospace and defence manufacturers and beyond. Implementing for clients? The Consultant Package bundles 70 toolkits — 6,100+ editable templates — under one firm-wide licence that covers unlimited client engagements. $1,399 one-time. ### Comprehensive Basel III Prudential Risk Toolkit – 25 Templates URL: https://governancedocs.com/product/basel-iii-toolkit/ Price: $99 USD Basel III Toolkit delivers 25 ready-to-use Microsoft Office templates covering governance and risk appetite, capital management, RWA calculation, credit risk, market risk and FRTB, operational risk (SMA), IRRBB, liquidity (LCR and NSFR), leverage ratio, large exposures, ICAAP, ILAAP, stress testing, and recovery planning. Accelerate your Basel III compliance programme with a complete, audit-ready Basel III compliance documentation foundation built for chief risk officers and beyond. Basel III is where prudential regulation meets day-to-day banking: capital adequacy, leverage and liquidity ratios have to be calculated, governed and evidenced to a supervisor's satisfaction. This Basel III Toolkit provides 25 templates covering the capital-management and ICAAP framework, the liquidity (LCR and NSFR) and leverage-ratio policies, risk-appetite and stress-testing documentation, and the governance and reporting records prudential regulators expect. Each document is written for a risk or finance function that must defend its numbers, connecting policy to calculation to board oversight. Everything is editable in Microsoft Office and ready to reflect your institution's balance sheet and jurisdiction. ### Comprehensive BSI C5:2026 Cloud Toolkit – 107 Compliance Templates URL: https://governancedocs.com/product/bsi-c52026-cloud-toolkit/ Price: $99 USD BSI C5:2026 Cloud Toolkit delivers 107 ready-to-use Microsoft Office templates covering all 17 domains of the BSI Cloud Computing Compliance Criteria Catalogue — from governance and identity management to supply chain security and data sovereignty. Accelerate your C5 attestation programme with a complete, audit-ready C5 compliance documentation foundation built for cloud service providers and their consultants. BSI C5 is how cloud providers prove their security to the German market: the Cloud Computing Compliance Criteria Catalogue, published by Germany's Federal Office for Information Security, is assessed through an ISAE 3000 audit and increasingly expected by public-sector and enterprise buyers. This toolkit provides 107 templates aligned to the C5:2026 criteria — covering cloud security policies across every control area, organisation of information security, physical and operational controls, cryptography, and the audit-evidence records a C5 attestation examines. Each document is written to the C5 basic and additional criteria so your evidence lines up with how the audit is scoped. Everything is editable in Microsoft Office and ready to reflect your cloud service. ### Comprehensive CCPA-CPRA Compliance Toolkit – 60+ Privacy Templates URL: https://governancedocs.com/product/ccpa-cpra-toolkit/ Price: $99 USD CCPA-CPRA Compliance Toolkit delivers 63 ready-to-use Microsoft Office templates covering consumer rights, privacy notices, data management, vendor oversight, and breach response — aligned to California Civil Code §§ 1798.100 et seq. Streamline your CCPA-CPRA compliance program and accelerate audit readiness with instant download access. California's CCPA, as amended by the CPRA, gives consumers real control over their personal information — rights to know, delete, correct and opt out of sale or sharing — and backs it with a dedicated regulator and statutory penalties. This CCPA-CPRA Toolkit provides 60+ templates covering the privacy policy and notices at collection, the consumer-rights request and verification procedures, opt-out and Do-Not-Sell/Share mechanisms, service-provider agreements, and the records a business must keep to show compliance. Each document is written to the CCPA/CPRA's specific definitions and timelines rather than adapted loosely from other privacy laws. Everything is editable in Microsoft Office. ### Comprehensive CIS Controls v8.1 Toolkit – 40 Cybersecurity Templates URL: https://governancedocs.com/product/cis-controls-toolkit/ Price: $99 USD CIS Controls Toolkit delivers 40 ready-to-use Microsoft Office templates covering asset inventory, software inventory, data protection, secure configuration, account management, access control, vulnerability management, audit log management, email and web protections, malware defences, data recovery, network management, security awareness, service provider management, application security, incident response, and penetration testing. Accelerate your CIS Controls compliance programme with a complete, audit-ready CIS Controls compliance documentation foundation built for cisos and beyond. The CIS Controls work because they are prioritised: Implementation Groups 1 to 3 tell an organisation what to do first, so security effort follows real-world attack data rather than a flat checklist. This CIS Controls Toolkit turns v8.1 into working documentation — 40 templates covering the 18 controls and their safeguards, mapped to Implementation Groups, with the policies, standards and registers for asset and software inventory, access control, data protection, logging, and incident response. Each document is written so you can adopt IG1 as a baseline and grow into IG2 and IG3, evidencing safeguards as you go. Everything is editable in Microsoft Office. ### Comprehensive CMMC Documentation Toolkit – 107 Compliance Templates URL: https://governancedocs.com/product/cmmc-toolkit/ Price: $99 USD CMMC Toolkit delivers 107 ready-to-use Microsoft Office templates covering all 14 NIST SP 800-171 practice families required for CMMC Level 2 certification. From policies and procedures to gap analysis workbooks and SSP templates, this toolkit gives defence contractors and GRC consultants the complete CMMC compliance documentation foundation needed to pass a third-party assessment with confidence. CMMC turns NIST SP 800-171 from a self-attestation into a certified requirement: defense contractors handling Federal Contract Information or Controlled Unclassified Information must reach the level their contracts demand, verified by assessment. This CMMC Toolkit provides 107 templates spanning CMMC Levels 1 to 2 — covering the System Security Plan, the practice-level policies and procedures across all 14 domains, the POA&M, and the incident-response, access-control and configuration records a C3PAO assessment examines. Each document is written so you can evidence each practice and trace it to implementation, which is the difference between passing and failing an assessment. Everything is editable in Microsoft Office. ### Comprehensive COBIT 2019 IT Governance Toolkit – 31 Templates URL: https://governancedocs.com/product/cobit-2019-toolkit/ Price: $99 USD COBIT 2019 Toolkit delivers 31 ready-to-use Microsoft Office templates covering IT governance policy, information security, risk management, change management, incident management, service management, data governance, vendor management, business continuity, asset management, and all 40 governance and management objectives. Accelerate your COBIT 2019 compliance programme with a complete, audit-ready COBIT 2019 compliance documentation foundation built for cios and beyond. COBIT 2019 is a governance framework, not a checklist: it separates the governance of enterprise IT from its management and expects each objective to have clear ownership, metrics and design factors behind it. This COBIT 2019 Toolkit turns that framework into working documents — 31 templates covering the governance and management objectives, the RACI and organisational structures, the design-factor and goals-cascade worksheets, performance metrics, and the policies that connect IT decisions to enterprise strategy and risk appetite. Each document is written so a board or audit committee can see how IT is governed, and everything is editable in Microsoft Office and ready to fit your operating model. ### Comprehensive COSO ERM & Internal Control Toolkit – 21 Templates URL: https://governancedocs.com/product/coso-toolkit/ Price: $99 USD COSO Toolkit delivers 21 ready-to-use Microsoft Office templates covering internal control policy, ICFR, control design and documentation, control evaluation and testing, deficiency evaluation, enterprise risk management, risk appetite, risk identification, risk response, portfolio view, and risk-performance linkage. Accelerate your COSO compliance programme with a complete, audit-ready COSO compliance documentation foundation built for chief risk officers and beyond. COSO is the backbone of internal control and enterprise risk management: SOX assumes it, auditors expect it, and boards use its components to satisfy themselves that risk is actually managed. This COSO Toolkit provides 21 templates covering the internal control framework and its five components, the ERM framework linking strategy to risk appetite, the control environment and risk-assessment documentation, and the monitoring and reporting records that evidence oversight. Each document is written around the COSO components and principles so internal control and ERM connect to strategy rather than sitting in isolation. Everything is editable in Microsoft Office. ### Comprehensive CSA STAR Cloud Security Toolkit – 30 Templates URL: https://governancedocs.com/product/csa-star-toolkit/ Price: $99 USD CSA STAR Toolkit delivers 30 ready-to-use Microsoft Office templates covering cloud governance, application security, business continuity, change control, cryptography, datacenter security, data privacy, identity and access management, infrastructure security, logging and monitoring, supply chain, threat and vulnerability management, and universal endpoint management. Accelerate your CSA STAR compliance programme with a complete, audit-ready CSA STAR compliance documentation foundation built for cloud service providers preparing for star level 1 self-assessment and beyond. CSA STAR is how cloud providers prove their security to customers who cannot audit them directly: the Cloud Controls Matrix maps a provider's controls to a shared standard, and STAR self-assessment or certification publishes the result. This CSA STAR Toolkit provides 30 templates built around the CCM control domains — covering cloud security policies, shared-responsibility definitions, identity and access management, data security and encryption, and the CAIQ responses and evidence records STAR relies on. Each document is written so a prospective customer or auditor can trace a CCM control from policy to implementation. All files are editable in Microsoft Office and ready to reflect your cloud service. ### Comprehensive Cyber Essentials UK Toolkit – 25 Compliance Templates URL: https://governancedocs.com/product/cyber-essentials-toolkit/ Price: $99 USD Cyber Essentials Toolkit delivers 25 ready-to-use Microsoft Office templates aligned to Cyber Essentials Requirements for IT Infrastructure v3.3 covering firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management — the five technical control themes — plus supporting policies for acceptable use, BYOD, password management, remote working, and incident response. Accelerate your Cyber Essentials compliance programme with a complete, audit-ready Cyber Essentials compliance documentation foundation built for uk organisations seeking cyber essentials or cyber essentials plus certification and beyond. Cyber Essentials is the UK government's baseline for the security controls that stop the most common internet attacks — and for many public-sector contracts it is a hard requirement, not a nice-to-have. This Cyber Essentials Toolkit provides 25 templates covering the five technical control themes (firewalls, secure configuration, user access control, malware protection and security update management), plus the policies, asset records and self-assessment support needed for certification and the audited Cyber Essentials Plus. Each document is written to the current NCSC requirements and kept deliberately practical for smaller teams. Everything is editable in Microsoft Office and ready to reflect your systems. ### Comprehensive Data Governance Toolkit – 91 DMBOK-Aligned Templates URL: https://governancedocs.com/product/data-governance-toolkit/ Price: $99 USD Data Governance Toolkit delivers 91 ready-to-use Microsoft Office templates covering data governance, data architecture, data modelling and design, data storage and operations, data security, data integration and interoperability, document and content management, reference and master data, data warehousing and business intelligence, metadata management, data quality, and cross-cutting overarching documents. Accelerate your Data Governance compliance programme with a complete, audit-ready Data Governance compliance documentation foundation built for chief data officers and beyond. Data governance succeeds or fails on documentation: without written ownership, stewardship and quality rules, programmes stall at the policy stage. This toolkit supplies that foundation — 91 templates mapped to all 12 knowledge areas of DAMA-DMBOK 2, spanning the governance charter and stewardship model, data architecture and modelling standards, security and privacy controls, integration and interoperability protocols, master-data and metadata management, and data-quality scorecards. ### Comprehensive DPDP Act Toolkit – 91 Privacy Templates URL: https://governancedocs.com/product/dpdp-act-toolkit/ Price: $99 USD DPDP Act Compliance Toolkit delivers 91 ready-to-use Microsoft Office templates covering all key obligations under India's Digital Personal Data Protection Act, 2023 — from consent management and data principal rights to breach notification and cross-border transfer controls. Accelerate your organisation's DPDP compliance programme with a complete, audit-ready documentation foundation built for Data Fiduciaries, DPOs, and privacy consultants. India's Digital Personal Data Protection Act reshapes how any organisation handling Indian residents' data must operate: consent, purpose limitation, breach notification and the rights of Data Principals now carry real penalties. This toolkit provides 91 templates covering the DPDP privacy policy and notices, consent and consent-manager records, the Data Principal rights processes, breach-response and reporting procedures, data-processing agreements and the governance records a Data Fiduciary needs to demonstrate compliance. Each document is written to the Act's specific vocabulary — Data Fiduciary, Data Principal, Consent Manager — rather than borrowed from other regimes. Everything is editable in Microsoft Office. ### Comprehensive EU AI Act Toolkit – 60 Compliance Templates URL: https://governancedocs.com/product/eu-ai-act-toolkit/ Price: $99 USD EU AI Act Toolkit delivers 60 ready-to-use Microsoft Office templates covering governance, risk classification, high-risk AI systems, GPAI models, conformity assessment, and audit compliance — all aligned to Regulation (EU) 2024/1689. Accelerate your EU AI Act compliance programme and reach audit readiness faster with a fully structured documentation library built for providers, deployers, and compliance professionals. The EU AI Act is the world's first comprehensive AI law, and it works by risk tier: prohibited practices, high-risk systems with heavy obligations, limited-risk systems with transparency duties, and minimal-risk systems left largely free. Knowing which tier your AI falls into — and proving it — is the whole game. This toolkit provides 60 templates covering the AI system inventory and risk classification, the high-risk conformity requirements (risk management, data governance, technical documentation, human oversight, logging), the transparency notices, and the governance and post-market monitoring records the Act demands. Each document is written to the Act's obligations and timelines. Everything is editable in Microsoft Office. ### Comprehensive EU CRA Toolkit – 74 Cyber Resilience Act Templates URL: https://governancedocs.com/product/eu-cra-toolkit/ Price: $99.00 USD EU CRA Toolkit delivers 74 ready-to-use Microsoft Office templates covering Regulation (EU) 2024/2847 as consolidated on 20 November 2024 — the Article 14 reporting cascades that apply from 11 September 2026, the thirteen Annex I Part I product properties and eight Part II vulnerability handling requirements, the software bill of materials, classification against Annex III and Annex IV, conformity assessment and CE marking, the Article 13(8) support period and the update-availability duty that outlives it, and the Annex VII technical documentation. Built for manufacturers of products with digital elements who need a file a notified body can actually review. The Cyber Resilience Act is the first horizontal cybersecurity law for products. It does not care what sector you sell into — if your product has digital elements and connects to anything, it applies. ### Comprehensive EU IVDR Toolkit – 74 In Vitro Diagnostic Regulation Templates URL: https://governancedocs.com/product/eu-ivdr-toolkit/ Price: $99.00 USD EU IVDR Toolkit delivers 74 ready-to-use Microsoft Office templates covering Regulation (EU) 2017/746 as consolidated on 10 January 2025 — Annex II and Annex III technical documentation, the Annex I GSPR conformity checklist, classification under the seven Annex VIII rules, performance evaluation across scientific validity, analytical performance and clinical performance, performance studies, UDI and EUDAMED registration, post-market surveillance, PSUR and vigilance, labelling and the summary of safety and performance, and the staggered Article 110 transition. Built for IVD manufacturers who need a regulatory file a notified body can actually review. This is the in vitro diagnostic pack, not the medical device one. Article numbers here are IVDR numbers. They do not match Regulation (EU) 2017/745, and the two regulations diverge exactly where it costs most — classification, clinical evidence and the structure of the technical file. If you make medical devices rather than IVDs, you want the EU MDR Toolkit instead. ### Comprehensive EU MDR Toolkit – 68 Medical Device Regulation Templates URL: https://governancedocs.com/product/eu-mdr-toolkit/ Price: $99.00 USD EU MDR Toolkit delivers 68 ready-to-use Microsoft Office templates covering Regulation (EU) 2017/745 as consolidated on 19 July 2026 — Annex II and Annex III technical documentation, the GSPR conformity checklist, classification, conformity assessment, clinical evaluation and PMCF, UDI and EUDAMED registration, post-market surveillance, PSUR and vigilance, labelling and the SSCP, and the Article 120 transition. Built for manufacturers who need a regulatory file a notified body can actually review. The Medical Device Regulation is not a standard you implement once. It is a live instrument that has been amended eight times, consolidated eight times, and is served by 125 MDCG guidance documents and a harmonised standards list amended roughly twice a year. ### Comprehensive FSSC 22000 Toolkit – 111 Food Safety Templates URL: https://governancedocs.com/product/fssc-22000-toolkit/ Price: $99.00 USD The FSSC 22000 Toolkit delivers 111 ready-to-use Microsoft Office templates written to Version 7.0 of the Scheme, published May 2026 — 80 Word documents and 31 Excel workbooks covering all 66 lettered FSSC Additional Requirements across the 18 requirement groups, the ISO 22000:2018 management system, and the prerequisite programme layer. Every document states the food chain categories it applies to, because 13 of the 18 groups carry category conditionality and implementing one you do not carry costs you at the audit. Built for the Version 7 upgrade window that opens 1 May 2027. FSSC 22000 is not a standard. It is a certification Scheme built from three layers, and Part 2 of the Scheme says so in three clauses: ISO 22000:2018, the applicable prerequisite programme standard for your food chain category, and the FSSC 22000 Additional Requirements. A certificate depends on all three, and most documentation on the market covers one of them. ### Comprehensive GovRAMP (StateRAMP) TX-RAMP Compliance Toolkit – 50 Templates URL: https://governancedocs.com/product/stateramp-toolkit/ Price: $99 USD StateRAMP Toolkit delivers 50 ready-to-use GovRAMP / TX-RAMP Microsoft Office templates covering system security planning, FIPS 199 categorization, privacy impact assessment, access control, audit and accountability, configuration management, incident response, contingency planning, supply chain risk management, continuous monitoring, and third-party assessment. Accelerate your StateRAMP compliance programme with a complete, audit-ready StateRAMP compliance documentation foundation built for cloud service providers seeking GovRAMP (formerly StateRAMP) or TX-RAMP authorization and beyond. A note on the name. StateRAMP now operates as GovRAMP — stateramp.org redirects to govramp.org. The programme, the verification pathway and the NIST SP 800-53 baselines are unchanged, and TX-RAMP remains a separate Texas programme run by the Department of Information Resources. How the GovRAMP pathway works. ### Comprehensive HITRUST CSF v11 Toolkit – 45 Compliance Templates URL: https://governancedocs.com/product/hitrust-csf-toolkit/ Price: $99 USD HITRUST CSF Toolkit delivers 45 ready-to-use Microsoft Office templates covering information protection programme, endpoint protection, portable media, mobile device security, wireless security, configuration management, vulnerability management, network protection, transmission protection, password management, access control, audit logging, education and awareness, third-party assurance, incident management, business continuity, risk management, physical security, and data protection and privacy. Accelerate your HITRUST CSF compliance programme with a complete, audit-ready HITRUST CSF compliance documentation foundation built for healthcare cloud service providers and beyond. HITRUST certification is demanding because the CSF harmonises HIPAA, ISO 27001, NIST and more into one control set that is scored on maturity, not just presence. This HITRUST CSF Toolkit gives you the documentation to meet it — 45 templates aligned to CSF v11 covering the information security policies and procedures across all control domains, the risk assessment and treatment records, and the supporting plans for incident response, contingency and third-party management that assessors evaluate. Each document is written to support HITRUST's maturity scoring, so controls are not only defined but shown to be implemented and measured. All files are editable in Microsoft Office. ### Comprehensive ISO 14971 Toolkit – 44 Risk Management Templates URL: https://governancedocs.com/product/iso-14971-toolkit/ Price: $99.00 USD ISO 14971 Toolkit delivers 44 ready-to-use Microsoft Office templates covering every clause of ISO 14971:2019 — the risk management plan and file, intended use and misuse, hazard identification and estimation, the risk control hierarchy, benefit-risk analysis, overall residual risk, and the production and post-production loop. Built for medical device manufacturers who need a risk management file that survives review. Every medical device manufacturer has to produce a risk management file. ISO 13485 clause 7.1 requires risk management throughout product realisation. EU MDR Annex I requires a risk management system and Annex II requires the plan and results in the technical documentation. FDA expects alignment with the standard. And the file is the first thing a notified body reviewer opens. ### Comprehensive ISO 15189 Toolkit – 82 Medical Laboratory Templates URL: https://governancedocs.com/product/iso-15189-toolkit/ Price: $99.00 USD ISO 15189 Toolkit delivers 82 ready-to-use Microsoft Office templates covering every clause of ISO 15189:2022 — obligations to patients, the laboratory director, risk management, the full pre-examination, examination and post-examination pathway, critical result notification, point-of-care testing, and the management system. Built for medical laboratories preparing for accreditation. Medical laboratories are accredited, not certified. An accreditation body assesses your laboratory against ISO 15189:2022 and grants accreditation for a defined scope: named examinations, on named sample types, by named methods, at named locations. An examination outside that schedule is not accredited work, however well it is performed. ### Comprehensive ISO 17025 Toolkit – 70 Laboratory Templates URL: https://governancedocs.com/product/iso-17025-toolkit/ Price: $99.00 USD ISO 17025 Toolkit delivers 70 ready-to-use Microsoft Office templates covering every clause of ISO/IEC 17025:2017 — impartiality, competence, equipment and metrological traceability, method validation, measurement uncertainty, proficiency testing, reporting and decision rules, and the management system under either Option A or Option B. Built for testing and calibration laboratories preparing for accreditation. Laboratories are accredited, not certified. An accreditation body — UKAS, A2LA, ANAB, DAkkS, NABL or another — assesses your laboratory against ISO/IEC 17025:2017 and grants accreditation for a defined scope: named methods, named measurands, named ranges and stated uncertainties. Work outside that schedule is not accredited work, however well it is performed. The ISO 17025 Toolkit is built around that reality. ### Comprehensive ISO 21001 Educational Management Toolkit – 43 Templates URL: https://governancedocs.com/product/iso-21001-toolkit/ Price: $99 USD ISO 21001 Toolkit delivers 43 ready-to-use Microsoft Office templates covering learner admissions, learner support, accessibility and SEN, learner participation, curriculum design, programme delivery, assessment and certification, educator recruitment, educator development, health and safety, privacy and data protection, safeguarding, and continual improvement. Accelerate your ISO 21001 compliance programme with a complete, audit-ready ISO 21001 compliance documentation foundation built for universities and beyond. ISO 21001 adapts the management-system approach to education, putting learners at the centre: it asks schools, universities and training providers to show that their educational offering is planned, delivered and improved around learner needs. This ISO 21001 Toolkit provides 43 templates covering the educational organisation management system (EOMS) policy, learner-needs and interested-party analysis, curriculum and delivery planning, assessment and feedback processes, and the monitoring, audit and improvement records certification requires. Each document follows the ISO high-level structure while speaking the language of education rather than manufacturing. Everything is editable in Microsoft Office. ### Comprehensive ISO 27017 Toolkit & ISO 27018 Cloud Pack – 67 Templates URL: https://governancedocs.com/product/iso-27017-27018-toolkit/ Price: $99.00 USD ISO 27017 Toolkit delivers 67 ready-to-use Microsoft Office templates that extend a certified ISO 27001 ISMS into the cloud — covering the seven ISO 27017 CLD controls, shared responsibility with your provider, virtualisation and tenant isolation, cloud monitoring, and the ISO 27018 obligations that apply when you process personal information as a processor in a public cloud. The ISO 27017 Toolkit gives you the cloud half of an information security management system. ISO/IEC 27017 and ISO/IEC 27018 are the two codes of practice that take an ISMS into the cloud. Neither is certified on its own — both are audited as an extension of ISO/IEC 27001 — and that is exactly how this toolkit is built. It supplies the cloud-specific documents an ISMS does not already have, states in each one how it supplements the ISMS rather than replacing it, and gives you the mapping evidence an auditor asks for when your Statement of Applicability claims cloud coverage. ### Comprehensive ISO 28000 Supply Chain Security Toolkit – 29 Templates URL: https://governancedocs.com/product/iso-28000-toolkit/ Price: $99 USD ISO 28000 Toolkit delivers 29 ready-to-use Microsoft Office templates covering supply chain security risk assessment, physical security, transport and logistics security, personnel security, facility security, cyber-physical convergence, supplier security, incident management, recovery and continuity, and threat intelligence. Accelerate your ISO 28000 compliance programme with a complete, audit-ready ISO 28000 compliance documentation foundation built for supply chain security managers and beyond. ISO 28000 secures the supply chain as a system: it asks organisations that move, store or handle goods to identify security threats along the chain and manage them with the same discipline other ISO standards bring to quality or information security. This ISO 28000 Toolkit provides 29 templates covering the supply-chain security policy, the security risk assessment across the logistics chain, access, cargo and facility controls, incident and continuity procedures, and the audit and review records certification requires. Each document is written for logistics, ports, warehousing and manufacturing operations that need to demonstrate security to partners and regulators. Everything is editable in Microsoft Office. ### Comprehensive ISO 31000 Risk Management Toolkit – 30 Templates URL: https://governancedocs.com/product/iso-31000-toolkit/ Price: $99 USD ISO 31000 Toolkit delivers 30 ready-to-use Microsoft Office templates covering risk management framework, risk management policy, risk appetite, risk identification, risk analysis, risk evaluation, risk treatment, risk monitoring and review, risk communication, risk reporting, risk registers, bow-tie analysis, and Monte Carlo simulation. Accelerate your ISO 31000 compliance programme with a complete, audit-ready ISO 31000 compliance documentation foundation built for chief risk officers and beyond. ISO 31000 is deliberately not certifiable — it is the reference for how risk management should be designed and run, so its value shows up in the framework and process an organisation actually adopts. This ISO 31000 Toolkit makes that concrete: 30 templates covering the risk management policy and framework, the risk criteria and appetite statements, the risk assessment and treatment process, the risk register, and the monitoring, review and reporting records that keep risk management alive. Each document follows the ISO 31000 principles-framework-process structure, so risk management integrates with governance rather than sitting in a spreadsheet. Everything is editable in Microsoft Office. ### Comprehensive ISO 37001 Anti-Bribery Toolkit – 55 Compliance Templates URL: https://governancedocs.com/product/iso-37001-toolkit/ Price: $99 USD ISO 37001 Toolkit delivers 55 ready-to-use Microsoft Office templates covering anti-bribery policy, governing body commitment, anti-bribery function charter, bribery risk assessment, due diligence, financial and non-financial controls, controlled organisations, gifts and hospitality, conflict of interest, whistleblowing, investigations, training, internal audit, management review, and continual improvement. Accelerate your ISO 37001 compliance programme with a complete, audit-ready ISO 37001 compliance documentation foundation built for chief compliance officers and beyond. ISO 37001 is judged on whether an anti-bribery management system is genuinely operating — proportionate due diligence, controls over gifts and hospitality, a working reporting channel and visible top-management oversight — and every part of that has to be documented. This ISO 37001 Toolkit delivers 55 templates covering the anti-bribery policy, bribery risk assessment, third-party and personnel due-diligence procedures, financial and non-financial controls, gifts and hospitality registers, and the reporting and investigation records an auditor or regulator will test. Built around ISO 37001:2025, each document fixes responsibility and produces the audit trail that shows the system is more than a statement of intent. All files are fully editable in Microsoft Office. ### Comprehensive ISO 37301 Compliance Management Toolkit – 24 Templates URL: https://governancedocs.com/product/iso-37301-toolkit/ Price: $99 USD ISO 37301 Toolkit delivers 24 ready-to-use Microsoft Office templates covering compliance policy, code of conduct, anti-bribery, data protection, competition law, sanctions, AML, conflict of interest, whistleblowing, investigations, and continual improvement. Accelerate your ISO 37301 compliance programme with a complete, audit-ready ISO 37301 compliance documentation foundation built for chief compliance officers and beyond. ISO 37301 is the benchmark for a compliance management system that regulators and boards will actually respect: it expects compliance to be independent, risk-based and embedded, with clear obligations, controls and a culture that supports speaking up. This ISO 37301 Toolkit provides 24 templates covering the compliance policy and governance structure, the compliance-obligations register and risk assessment, the controls, training and reporting processes, and the monitoring, investigation and improvement records the standard requires. Each document is written to give a compliance function the documented independence and evidence ISO 37301 is judged on. Everything is editable in Microsoft Office. ### Comprehensive ISO 39001 Road Traffic Safety Toolkit – 10 Templates URL: https://governancedocs.com/product/iso-39001-toolkit/ Price: $99 USD ISO 39001 Toolkit delivers 10 ready-to-use Microsoft Office templates covering driver management, vehicle management, journey management, incident and near-miss reporting, emergency response, and supplier RTS requirements. Accelerate your ISO 39001 compliance programme with a complete, audit-ready ISO 39001 compliance documentation foundation built for fleet operators and beyond. ISO 39001 treats road deaths and serious injuries as a management problem an organisation can act on, not an accident of fate: any fleet operator, logistics firm or authority that influences road use can build a Road Traffic Safety management system around the factors it controls — speed, vehicle condition, driver competence and journey planning. This ISO 39001 Toolkit provides 10 core templates covering the RTS policy, the analysis of risk exposure and safety performance factors, the objectives and journey-management controls, and the monitoring and review records the standard expects. Each document keeps the standard practical for a safety or fleet manager. Everything is editable in Microsoft Office. ### Comprehensive ISO 41001 Facility Management Toolkit – 17 Templates URL: https://governancedocs.com/product/iso-41001-toolkit/ Price: $99 USD ISO 41001 Toolkit delivers 17 ready-to-use Microsoft Office templates covering hard FM operations, soft FM operations, asset and space management, HSE in FM, supplier and contractor management, business continuity, sustainability and ESG, and supporting policies. Accelerate your ISO 41001 compliance programme with a complete, audit-ready ISO 41001 compliance documentation foundation built for facility managers and beyond. ISO 41001 brings management-system discipline to facility management, an area often run on habit and supplier relationships rather than documented strategy. It asks organisations to align their built environment and support services with the needs of the people and core business they serve. This ISO 41001 Toolkit provides 17 templates covering the FM policy and strategy, demand and service-level analysis, service delivery and supplier management, and the performance-monitoring and improvement records certification requires. Each document is written for an in-house FM team or an outsourced provider that needs to demonstrate a managed, improving service. Everything is editable in Microsoft Office. ### Comprehensive ISO 50001 Energy Management Toolkit – 53 Templates URL: https://governancedocs.com/product/iso-50001-toolkit/ Price: $99 USD ISO 50001 Toolkit delivers 53 ready-to-use Microsoft Office templates covering energy policy, energy review, significant energy uses (SEUs), energy performance indicators (EnPIs), energy baselines, operational planning and control, procurement, design, monitoring and measurement, calibration, internal audit, management review, and continual improvement. Accelerate your ISO 50001 compliance programme with a complete, audit-ready ISO 50001 compliance documentation foundation built for energy managers and beyond. ISO 50001 asks organisations to treat energy the way ISO 9001 treats quality: as a managed system with a policy, measurable objectives and continual improvement, all resting on evidence. This ISO 50001 Toolkit supplies that evidence base — 53 templates covering the energy policy, energy review and baseline, significant energy uses, energy performance indicators (EnPIs), objectives and action plans, and the monitoring and internal-audit records certification bodies look for. Each document follows the Plan-Do-Check-Act structure of the standard, so your energy management system reads as one coherent system rather than a folder of disconnected files. Everything is editable in Microsoft Office and ready to populate with your sites, meters and consumption data. ### Comprehensive ISO 55001 Asset Management Toolkit – 44 Templates URL: https://governancedocs.com/product/iso-55001-toolkit/ Price: $99 USD ISO 55001 Toolkit delivers 42 ready-to-use Microsoft Office templates covering asset lifecycle management, risk-based decision-making, condition assessment, whole-life costing, performance management, asset information, supplier management, and continual improvement. Accelerate your ISO 55001 compliance programme with a complete, audit-ready ISO 55001 compliance documentation foundation built for asset managers and beyond. ISO 55001 changes how organisations think about physical assets: instead of maintaining equipment reactively, it asks them to manage assets across their whole life to deliver value, balancing cost, risk and performance. For utilities, transport, manufacturing and infrastructure operators this is board-level territory. This ISO 55001 Toolkit provides 44 templates covering the asset management policy and strategic asset management plan (SAMP), the asset-management objectives, lifecycle and risk processes, and the performance, audit and improvement records certification requires. Each document connects day-to-day asset decisions to the organisation's objectives and risk appetite. Everything is editable in Microsoft Office. ### Comprehensive ITIL 5 Toolkit – 57 Templates (ITIL Version 5) URL: https://governancedocs.com/product/itil-toolkit/ Price: $99.00 USD ITIL 5 Toolkit delivers 57 ready-to-use Microsoft Office templates aligned to ITIL (Version 5): the ITIL Value System, the eight-activity product and service lifecycle (discover, design, acquire, build, transition, operate, deliver, support), all 34 management practices, AI governance built on the 6-capability model, value stream mapping, experience management, and a maturity assessment workbook. Replace an ITIL 4 documentation set with one that matches the current edition. ITIL (Version 5) is the first substantial change to the framework since 2019, and it is not only a rename. The service value chain's six activities become an eight-activity product and service lifecycle. The three practice categories become two. AI governance, value stream mapping and experience management arrive as first-class subjects. Documentation written for ITIL 4 still describes a structure the current edition no longer uses. ### Comprehensive NIST AI RMF Toolkit – 36 AI Governance Templates URL: https://governancedocs.com/product/nist-ai-rmf-toolkit/ Price: $99 USD NIST AI RMF Toolkit delivers 36 ready-to-use Microsoft Office templates covering AI governance, AI risk management policy, AI ethics, AI acceptable use, generative AI policy, AI procurement, workforce training, risk tolerance, AI inventory, use-case categorization, impact assessment, bias testing, adversarial robustness, red teaming, model performance monitoring, AI incident response, human oversight, and model/system cards. Accelerate your NIST AI RMF compliance programme with a complete, audit-ready NIST AI RMF compliance documentation foundation built for chief ai officers and beyond. The NIST AI Risk Management Framework answers a question boards are now asking: how do we know our AI systems are trustworthy? It is voluntary, but its Govern-Map-Measure-Manage structure has quickly become the reference for responsible-AI programmes and a foundation for EU AI Act and ISO 42001 alignment. This toolkit provides 36 templates covering the AI governance policy, the AI system inventory and risk mapping, model and data documentation, bias, robustness and explainability assessments, and the monitoring and incident records that make AI risk manageable over time. Each document follows the four AI RMF functions so governance, not just compliance, is the result. Everything is editable in Microsoft Office. ### Comprehensive NIST SP 800-171 CUI Protection Toolkit – 33 Templates URL: https://governancedocs.com/product/nist-sp-800-171-toolkit/ Price: $99 USD NIST SP 800-171 Toolkit delivers 33 ready-to-use Microsoft Office templates covering CUI definition and identification, scoping and boundary, 14 control-family policies (access control through system and information integrity), assessment planning, SSP, POA&M, and continuous monitoring. Accelerate your NIST SP 800-171 compliance programme with a complete, audit-ready NIST SP 800-171 compliance documentation foundation built for u.s. defence contractors and beyond. NIST SP 800-171 exists for one reason: to protect Controlled Unclassified Information in the hands of contractors, and DFARS and CMMC make its 110 controls a condition of doing business with the US government. This NIST SP 800-171 Toolkit provides 33 templates covering the System Security Plan, the control-family policies and procedures across all 14 requirement areas, and the POA&M, incident-response and access-control artefacts assessors and primes ask to see. Each document is written so you can record how each of the 110 requirements is met and trace it to evidence — the difference between a self-attestation that holds up and one that does not. Everything is editable in Microsoft Office. ### Comprehensive NIST SP 800-53 Security Controls Toolkit – 38 Templates URL: https://governancedocs.com/product/nist-sp-800-53-toolkit/ Price: $99 USD NIST SP 800-53 Toolkit delivers 38 ready-to-use Microsoft Office templates covering 20 control families covering access control, awareness and training, audit and accountability, assessment and authorization, configuration management, contingency planning, identification and authentication, incident response, maintenance, media protection, privacy, physical security, planning, programme management, personnel security, risk assessment, system acquisition, system and communications protection, system integrity, and supply chain risk management. Accelerate your NIST SP 800-53 compliance programme with a complete, audit-ready NIST SP 800-53 compliance documentation foundation built for federal agencies and beyond. NIST SP 800-53 is the control catalogue that underpins FedRAMP, FISMA and countless agency and contractor security programmes — but a catalogue is not a system until the controls are documented, tailored and assigned. This NIST SP 800-53 Toolkit provides 38 templates covering the security and privacy control-family policies and procedures, the System Security Plan, and the supporting plans for contingency, incident response, configuration and access management that assessors expect. Structured to the 800-53 control families, each document is written so you can tailor a baseline, record control implementation, and trace it to evidence. Everything is editable in Microsoft Office. ### Comprehensive NQA-1:2024 Nuclear Quality Assurance Toolkit – 100+ Templates URL: https://governancedocs.com/product/nuclear-quality-assurance-toolkit/ Price: $149 USD NQA-1:2024 Nuclear Quality Assurance Toolkit delivers 100+ ready-to-use Microsoft Office templates covering organization, quality assurance program management, design control, procurement document control, instructions/procedures/drawings, document control, control of purchased items and services, identification and control of items, control of special processes, inspection, test control, control of measuring and test equipment, handling/storage/shipping, inspection/test/operating status, control of nonconforming items, corrective action, quality assurance records, and audits. Accelerate your NQA-1:2024 compliance programme with a complete, audit-ready nuclear quality assurance documentation foundation built for QA managers, nuclear suppliers, and beyond. NQA-1 governs quality assurance for nuclear facilities, where a documentation failure is a safety failure: the standard demands controlled, auditable evidence for everything from design and procurement to inspection and corrective action. This toolkit provides 100+ templates aligned to NQA-1:2024, covering the quality assurance programme, design and document control, procurement and supplier qualification, inspection and test control, nonconformance and corrective action, and the records that satisfy an NRC or client audit. Each document is written to the standard's Basic and Supplementary Requirements so your QA programme is traceable end to end. Everything is editable in Microsoft Office. ### Comprehensive SAMA Compliance Toolkit – 38 Documentation Templates URL: https://governancedocs.com/product/sama-toolkit/ Price: $99 USD SAMA Toolkit delivers 38 ready-to-use Microsoft Office templates covering cybersecurity, business continuity, IT governance, outsourcing, cloud computing, counter-fraud, and AML/CFT. Accelerate your SAMA compliance programme with a complete, audit-ready SAMA compliance documentation foundation built for sama-supervised financial institutions and beyond. The Saudi Central Bank (SAMA) Cyber Security Framework is mandatory for the Kingdom's banks, insurers and financial institutions, and it is enforced through supervised maturity assessments rather than a one-off certificate. This SAMA Toolkit provides 38 templates covering the cyber security governance and policy set, the risk-management and third-party processes, the technical and operational controls across the framework's domains, and the maturity-assessment and reporting records SAMA expects. Each document is written around the framework's domains and maturity model so an institution can demonstrate not just that controls exist but that they are operating at the required level. Everything is editable in Microsoft Office. ### Comprehensive SOX Compliance Toolkit – 45 ICFR Templates URL: https://governancedocs.com/product/sox-toolkit/ Price: $99 USD SOX Toolkit delivers 45 ready-to-use Microsoft Office templates covering scoping and materiality, top-down risk assessment, fraud risk assessment, entity-level controls, process narratives and RCMs across ten business cycles, IT general controls, application controls, control testing, deficiency evaluation, and Pillar 3 disclosure. Accelerate your SOX compliance programme with a complete, audit-ready SOX compliance documentation foundation built for cfos and beyond. Sarbanes-Oxley turns internal control over financial reporting into a personal responsibility for executives, and Sections 302 and 404 mean controls must be documented, tested and signed off every year. This SOX Toolkit provides 45 templates covering the ICFR framework and risk assessment, entity-level and process-level controls across the key financial cycles, IT general controls, the control matrices and narratives, and the testing and deficiency-tracking records external auditors rely on. Built around the COSO framework SOX assumes, each document is written so a control can be traced from risk to test to conclusion. Everything is editable in Microsoft Office. ### Comprehensive SWIFT CSP Compliance Toolkit – 32 Templates URL: https://governancedocs.com/product/swift-csp-toolkit/ Price: $99 USD SWIFT CSP Toolkit delivers 32 ready-to-use Microsoft Office templates aligned to CSCF v2026 covering secure zone architecture, access control and operator session management, network segmentation, cryptography and key management, logging and SIEM, vulnerability and patch management, operator acceptable use, third-party security, incident response, business continuity, and continuous monitoring. Accelerate your SWIFT CSP compliance programme with a complete, audit-ready SWIFT CSP compliance documentation foundation built for swift-connected financial institutions and beyond. The SWIFT Customer Security Programme is not optional for institutions on the network: every member must attest annually against the Customer Security Controls Framework, and that attestation has to be backed by evidence. This SWIFT CSP Toolkit provides 32 templates covering the mandatory and advisory CSCF controls, the local and remote environment security policies, access and credential management, logging and detection, and the attestation and independent-assessment records SWIFT expects. Each document is written around the CSCF control objectives so your attestation reflects controls that are genuinely operating. All files are editable in Microsoft Office and ready to reflect your SWIFT architecture type. ### Comprehensive TISAX Documentation Toolkit – 40 Compliance Templates URL: https://governancedocs.com/product/tisax-toolkit/ Price: $99 USD TISAX Toolkit delivers 40 ready-to-use Microsoft Office templates covering all assessment objectives of the VDA ISA2027 catalogue — from information security governance and prototype protection to data protection and supplier management. Accelerate your TISAX assessment preparation with a complete, audit-ready TISAX compliance documentation foundation built for automotive suppliers and OEM partners. TISAX is the automotive industry's answer to repeated, inconsistent security audits: one assessment, based on the VDA ISA catalogue, that OEMs and suppliers mutually recognise. If you handle a manufacturer's data or prototypes, TISAX is often the price of entry. This TISAX Toolkit provides 40 templates built to VDA ISA2027, the catalogue that applies to every TISAX assessment ordered from 1 January 2027, aligned to the VDA ISA controls — covering information security policies, prototype and data protection, access and physical security, supplier management, and the assessment-evidence records a TISAX audit examines. Each document is written to the VDA ISA structure and assessment levels, so your evidence lines up with how the audit is scored. Everything is editable in Microsoft Office. ### Consultant Package — Every Toolkit, Licensed for Client Work URL: https://governancedocs.com/product/consultant-package/ Price: $1399 USD The complete Governance Docs catalogue — 85 toolkits, 7,700+ editable documents — licensed for unlimited client engagements across your whole firm. One payment, perpetual licence, nothing to renew, 12 months of updates — and your clients keep what you deliver. If you implement management systems for a living, you already know the problem with document packs: they are licensed to a single organisation. Use them on a second client engagement and you are outside the terms. ### Critical IT and Cybersecurity Indicators URL: https://governancedocs.com/product/it-and-cybersecurity-indicators/ Price: $39 USD Enhance your IT and cybersecurity risk management with our comprehensive Excel Templates. Featuring 153 meticulously designed Key Risk Indicators (KRI's), this high-quality tool provides a clear and organized framework for monitoring and assessing security risks as per NIST CSF. With fields such as Domain, KRI Title, Reporting Frequency, Calculation Formula, Suggested Thresholds, Evidence Requirement, and KRI Owner, this user-friendly template empowers you to make informed decisions and strengthen your organization's security posture. Elevate your risk management practices with our IT and cybersecurity KRI's Excel sheet template today. This file includes two detailed Excel sheet templates designed to serve as indispensable tools to develop IT and cybersecurity indicators in your organization, risk managers, and executives aiming to bolster their approach to monitoring and assessing security risks. Each template is meticulously crafted, offering a robust framework that combines a structured layout with an extensive collection of Critical IT and Cybersecurity Indicators. IT and Cybersecurity Indicators template empower risk managers to streamline their risk management processes, enhance their organization’s overall security posture, and make data-driven decisions to proactively address and mitigate potential threats. ### DORA Toolkit - 100+ Comprehensive Templates URL: https://governancedocs.com/product/dora-toolkit/ Price: $99 USD Achieve compliance with Regulation (EU) 2022/2554 (DORA) with 100+ ready-to-edit templates covering all five pillars — ICT risk management, incident classification and reporting, resilience testing and TLPT, third-party risk, and information sharing. Includes the Register of Information, 12 Excel registers, and article-by-article traceability with ISO 27001 and NIS2 crosswalks. The DORA Toolkit is a complete documentation pack for organisations in scope of Regulation (EU) 2022/2554, the Digital Operational Resilience Act. It contains 100+ ready-to-edit templates covering all five DORA pillars, structured to mirror the Regulation itself. ### ESG Toolkit - 20+ Comprehensive Templates URL: https://governancedocs.com/product/esg-toolkit/ Price: $69 USD This ESG Toolkit (Environmental, Social, and Governance Toolkit) is the most complete and practical solution for building a robust ESG framework aligned with international sustainability standards. This ESG Toolkit (Environmental, Social, and Governance Toolkit) is the most comprehensive and best resource currently available for implementing a structured and effective ESG framework in accordance with global sustainability standards. ### EU AMLR Toolkit – 99 AML Compliance Templates URL: https://governancedocs.com/product/eu-amlr-toolkit/ Price: $99.00 USD AML-CFT documentation toolkit for obliged entities under Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation, which applies from 10 July 2027. 99 editable templates - 81 Word documents and 18 Excel workbooks - in 17 sections that follow the Regulation's own chapter structure. Answers 76 of the 80 operative articles, with the 4 that carry no obliged-entity duty listed and reasoned. Includes the transfers of funds and crypto-assets regime that Articles 9(1) and 11(1) bring inside the AMLR framework. Instant download. The EU AMLR Toolkit is a complete AML-CFT documentation set for Regulation (EU) 2024/1624, which applies from 10 July 2027. It is a Regulation, not a Directive: it applies directly in all 27 Member States, there is no national transposition to wait for, and the national rules that grew up around the previous Directive do not automatically carry forward. ### FDA QMSR Toolkit - 21 CFR Part 820 Templates URL: https://governancedocs.com/product/fda-qmsr-toolkit/ Price: $99.00 USD 73 editable templates for 21 CFR Part 820 — the FDA Quality Management System Regulation effective 2 February 2026. Covers the FDA layer on top of ISO 13485: the four 820.10(b) bridges, the 820.35 record supplements, 820.45 labeling controls, and inspection readiness built on Compliance Program 7382.850 with all 54 QMS elements pre-loaded. ### FedRAMP Toolkit – 52 Templates for the FedRAMP Consolidated Rules 2026 URL: https://governancedocs.com/product/fedramp-toolkit/ Price: $99 USD FedRAMP Toolkit: 52 editable templates rebuilt for the FedRAMP Consolidated Rules for 2026. Certification Package Overview, Security Decision Record, Accepted Weaknesses List, Ongoing Certification, 8 JSON companions on FedRAMP's own schemas, and the full NIST SP 800-53 Rev 5 baseline set: 18 control-family policies, plans, assessment reports and workbooks. Rev5 and 20x. Instant download. FedRAMP's Consolidated Rules for 2026 took effect on 4 July 2026. They retired the System Security Plan in favour of a Certification Package Overview and a Security Decision Record, eliminated the Plan of Action and Milestones in favour of an Accepted Weaknesses List, turned Continuous Monitoring into Ongoing Certification, made the 20x path generally available, and require the core artifacts in JSON against FedRAMP's published schemas as well as in a document a person can read. ### GDPR Toolkit - 100+ Comprehensive Templates URL: https://governancedocs.com/product/gdpr-toolkit/ Price: $99 USD Safeguard your business and ensure compliance with our GDPR Toolkit. Designed specifically for organizations handling sensitive data, this comprehensive pack equips you with the essential resources to navigate the intricacies of data protection regulations. Breach Register.xlsx ### GENIUS Act Toolkit – 126 Stablecoin Compliance Templates URL: https://governancedocs.com/product/genius-act-toolkit/ Price: $99.00 USD Compliance documentation toolkit for payment stablecoin issuers under the GENIUS Act, Public Law 119-27, which takes effect on 18 January 2027. 126 editable templates - 98 Word documents and 28 Excel workbooks - in 18 sections that follow the Act's own structure: reserves, redemption, the monthly report and CEO/CFO certification, the six Bank Secrecy Act elements, lawful orders, application, supervision, State pathway, custody and insolvency. Every one of the Act's 112 operative provisions is mapped to the document that answers it. Built on the enrolled statute; every implementing rule is tracked, none is stated as binding. Instant download. The GENIUS Act Toolkit is a complete compliance documentation set for permitted payment stablecoin issuers under the Guiding and Establishing National Innovation for U.S. Stablecoins Act - Public Law 119-27, signed on 18 July 2025 and taking effect on 18 January 2027. From that date, only a permitted payment stablecoin issuer may issue a payment stablecoin in the United States, and section 4 tells it how. ### HACCP Toolkit - Comprehensive 30+ Templates URL: https://governancedocs.com/product/haccp-toolkit/ Price: $99 USD This HACCP Toolkit is one of the most comprehensive documentation packs available today. Developed in Microsoft Office format, all templates are fully editable and ready for quick customization to suit your organization’s specific needs. Each document comes with standard formats, structured content, and sample text clearly highlighted to guide you on the type of information required for your HACCP plan. To make the process even easier, we’ve also included complete example documents that serve as practical references, helping you implement and maintain a robust and compliant Hazard Analysis and Critical Control Point (HACCP) system with confidence. Are you looking for the most comprehensive HACCP toolkit to ensure your business meets global food safety compliance requirements? Our HACCP Toolkit is the ultimate solution for food manufacturers, processors, and service providers who need to establish or improve their Hazard Analysis and Critical Control Point (HACCP) system. ### HIPAA Toolkit - Comprehensive 160+ Templates URL: https://governancedocs.com/product/hipaa-toolkit/ Price: $99 USD This is the most extensive HIPAA document toolkit on the market. Crafted in Microsoft Office format, these documents are prepared for customization to fit the unique requirements of your organization. In addition to following standard formats and content, the HIPAA template documents feature sample text that is distinctly highlighted to demonstrate the type of information your organization needs to provide. Complete example documents are also included to assist you in the implementation process. This is the most comprehensive HIPAA toolkit currently available to comply with HIPAA regulations. ### IATF 16949 Toolkit - 250+ Comprehensive Templates URL: https://governancedocs.com/product/iatf-16949-toolkit/ Price: $99 USD This is one of the most comprehensive IATF 16949 toolkits available for automotive quality management. All documents are developed in Microsoft Office format and are ready to be customized to your organization’s specific processes, customer requirements, and supply chain needs. In addition to a standardized structure and professional content, this IATF 16949 Documentation Repository includes clearly highlighted example text to show the type of information you should provide about your organization, processes, and controls. Full example documents are also included to support a smooth, consistent, and audit-ready IATF 16949:2016 implementation. IATF 16949 is the automotive industry's quality standard, built on ISO 9001 but adding the discipline the sector is known for: APQP, PPAP, FMEA, MSA and SPC, relentless traceability, and customer-specific requirements. This IATF 16949 documentation toolkit provides 250+ templates covering the quality manual, the core-tool procedures, the production-part approval and control-plan documents, supplier and customer-specific requirement management, and the records IATF auditors and OEM customers demand. Each document is written to the automotive requirements layered on top of ISO 9001, so your QMS satisfies both at once. Everything is editable in Microsoft Office. ### IEC 62304 Toolkit – 97 Medical Device Software Templates URL: https://governancedocs.com/product/iec-62304-toolkit/ Price: $99.00 USD The IEC 62304 Toolkit delivers 97 ready-to-use Microsoft Office templates for medical device software — 84 Word documents and 13 Excel workbooks covering every one of the 98 requirements in IEC 62304:2006+AMD1:2015 (Edition 1.1), the edition in force, applied as the state of the art under the EU MDR and recognised by FDA. Seventeen sections follow the standard's own clauses, from software safety classification to problem resolution. Every document marks the classes it applies to, three workbooks filter all 98 requirements to your class — 57 at Class A, 92 at B, 98 at C — and the mappings are to ISO 13485:2016, ISO 14971:2019, IEC 82304-1, IEC 81001-5-1, FDA's 2023 software guidance and EU MDR Annex I and II. IEC 62304 is the standard every regulator points at for medical device software. Notified bodies expect it as the state of the art the EU MDR and IVDR require for software — although, checkably, it is not on the Commission's list of harmonised standards under either regulation — FDA recognises it as a consensus standard, and it is the software life cycle ISO 13485 clause 7.3 expects to find under a device. It is also a process standard: its output is a defined set of documents — plans, specifications, test records, registers — and that is exactly what an assessor asks to see. ### IEC 62443 Toolkit – 117 IACS Cybersecurity Templates URL: https://governancedocs.com/product/iec-62443-toolkit/ Price: $99.00 USD The IEC 62443 Toolkit delivers 117 ready-to-use Microsoft Office templates for industrial automation and control system asset owners — 82 Word documents and 35 Excel workbooks covering every one of the 87 security programme requirements in IEC 62443-2-1:2024 Edition 2.0, the current edition. Sixteen sections carry the asset inventory, the zone and conduit model and target security levels required by IEC 62443-3-2, all eight Security Programme Elements, service provider assurance to IEC 62443-2-4, and a maturity workbook pre-loaded with all 87 requirements scored against the four maturity levels. Built for the people who run the plant, not for product suppliers building to 62443-4-1. IEC 62443 is the standard regulators, ENISA guidance and accredited bodies keep pointing at for operational technology. NIS2 and the EU Cyber Resilience Act both lead there. What almost nobody sells is the documentation an asset owner actually has to produce. ### IMS Toolkit - Comprehensive 90+ Templates URL: https://governancedocs.com/product/ims-toolkit/ Price: $99 USD This is one of the most comprehensive Integrated Management System (IMS) documentation toolkits available on the market, covering ISO 9001 (Quality), ISO 14001 (Environment), and ISO 45001 (Occupational Health & Safety) within a single integrated framework. All documents are provided in Microsoft Office formats and can be easily customized to meet your organization’s specific structure, scope, and regulatory requirements. In addition to standardized formatting and content, the IMS policy and procedure templates include clearly marked example text to guide users on the type of organizational information required. Complete sample documents are also included to support efficient and structured IMS implementation and integration. An Integrated Management System stops the duplication that comes from running ISO standards in silos: one set of shared processes — context, leadership, planning, support, operation, evaluation and improvement — serves quality, environmental, safety and information-security requirements at once. This toolkit provides 90+ templates covering the integrated policy and manual, the shared management-system procedures built on the ISO high-level structure, the combined risk and objectives frameworks, and the audit and management-review records that cover several standards in a single cycle. Each document is written so common clauses are documented once and mapped to each standard. Everything is editable in Microsoft Office. ### ISO 13485 Toolkit - Comprehensive 126 Templates URL: https://governancedocs.com/product/iso-13485-toolkit/ Price: $99 USD This ISO 13485 document toolkit stands out as the most comprehensive option on the market. Crafted in Microsoft Office format, these documents are ready to be customized to meet the unique requirements of your organization. Alongside standard formats and content, the ISO 13485 templates feature highlighted example text, demonstrating the kind of information your organization should provide. Additionally, complete example documents are included to assist you with the implementation process. This is the most comprehensive ISO 13485:2016 toolkit currently available. ### ISO 14001 Toolkit - Comprehensive 65+ Templates URL: https://governancedocs.com/product/iso-14001-toolkit/ Price: $99 USD This toolkit is the most complete set of ISO 14001:2026 documents available today. Crafted in MS Office format, these documents can be customized to meet the unique requirements of your organization. Along with standard formats and content, the ISO 14001 template documents come with highlighted example text to show the kind of information your organization should provide. Additionally, comprehensive example documents are included to assist you in the implementation process. This ISO 14001 toolkit is the most extensive one available today. ### ISO 20000 Toolkit - Comprehensive ITSM Templates URL: https://governancedocs.com/product/iso-20000-toolkit/ Price: $99 USD This ISO 20000 Toolkit is the most comprehensive IT Service Management System (ITSMS) documentation pack available today. All templates are provided in fully editable Microsoft Office format, allowing easy customization to meet your organization's specific ITSM requirements. Each ISO 20000 document includes clearly marked sample content to guide you on the type of information to input, ensuring alignment with your IT service management and governance practices. Additionally, the pack includes complete example documents to support a smooth and efficient ISO/IEC 20000 implementation process. ISO 20000 is the international standard for IT service management, certifying that an organisation runs its IT services as a managed system — with service-level agreements, incident and change control, and continual improvement customers can rely on. This toolkit provides templates covering the service-management system policy and service catalogue, the core processes (incident, problem, change, release, capacity, availability and continuity), the SLAs and supplier agreements, and the audit and improvement records certification requires. Aligned to ISO/IEC 20000-1 and complementary to ITIL, each document is written for a service-management function that has to prove control. Everything is editable in Microsoft Office. ### ISO 22000 Toolkit - Comprehensive 35 Templates URL: https://governancedocs.com/product/iso-22000-toolkit/ Price: $99 USD This ISO 22000 toolkit is the most extensive one available today. Designed in Microsoft Office format, the documents are ready for customization to fit your organization's unique requirements. In addition to standard formats and content, the ISO 22000 templates feature sample text, clearly highlighted to guide you on the type of information to provide about your organization. Complete example documents are also included to assist you in the implementation process. Looking for the most comprehensive ISO 22000 toolkit available? You’ve found it! Our meticulously designed toolkit is the ultimate solution for organizations seeking to implement a robust and fully compliant Food Safety Management System (FSMS). ### ISO 22301 Assessment Tool - Premium Quality URL: https://governancedocs.com/product/iso-22301-assessment-tool/ Price: $19 USD The ISO 22301 Assessment Tool is essential for evaluating and enhancing your organization's business continuity management system, ensuring compliance with the ISO 22301 standard. This user-friendly tool identifies vulnerabilities and provides tailored recommendations, helping businesses proactively address potential disruptions and achieve operational resilience. Ideal for organizations seeking to strengthen their business continuity capabilities, this tool is a strategic investment in maintaining excellence and reliability. In today's world of business change, when something sudden can happen without notice, continuity and fast recovery are at the top of anyone's list. The ISO 22301 Assessment Tool is your valuable asset in building a resilient business and e ### ISO 22301 Toolkit - Comprehensive 75+ Templates URL: https://governancedocs.com/product/iso-22301-toolkit/ Price: $99 USD This is the most extensive ISO 22301 toolkit on the market. The documents are provided in Microsoft Office format and can be easily customized to meet your organization's unique requirements. Alongside the standard structure and content, the ISO 22301:2019 template documents feature sample text that is clearly highlighted to demonstrate the kind of information required for your organization. Complete example documents are also included to assist you with your implementation process. This ISO 22301 Toolkit stands as the most comprehensive resource currently available for organizations seeking to implement a Business Continuity Management System (BCMS) in alignment with the standard. ### ISO 27001 Assessment Tool – Premium Quality URL: https://governancedocs.com/product/iso-27001-assessment-tool/ Price: $19 USD Streamline your compliance with our ISO 27001 Assessment Tool. Identify risks, track progress, and receive recommendations for ISMS. Introducing the ISO 27001 Assessment Tool (Excel) - Your Comprehensive Solution for Information Security Management System Compliance! ### ISO 27001 Toolkit - 165 Comprehensive Templates URL: https://governancedocs.com/product/iso-27001-toolkit/ Price: $99 USD This is the most comprehensive ISO 27001 documentation toolkit currently available. The documents are created in Microsoft Office format and are ready to be tailored to your organization’s specific needs. As well as standard format and contents, this ISO 27001 Documentation Repository include example text that is clearly highlighted to illustrate the type of information that needs to be given regarding your organization. Full example documents are also included to help you with your implementation. Last updated 30 August 2026. Aligned to ISO/IEC 27001:2022 including Amendment 1:2024, which added the climate-action requirements to clauses 4.1 and 4.2. Purchase includes 12 months of free updates. ### ISO 27701 Toolkit - Comprehensive 75+ Templates URL: https://governancedocs.com/product/iso-27701-toolkit/ Price: $99 USD This is the most extensive ISO 27701 toolkit on the market. The documents are provided in MS Office format and can be customized to meet your company requirements. Along with standard formats and content, the ISO 27701:2025 template documents feature sample text that is distinctly highlighted to demonstrate the kind of information your organization should provide. Complete example templates are also included to assist you in the implementation process. This ISO 27701 Toolkit is the most comprehensive resource for establishing a Privacy Information Management System (PIMS) that aligns with global privacy standards. ### ISO 42001 Toolkit - Comprehensive AI Governance Templates URL: https://governancedocs.com/product/iso-42001-toolkit/ Price: $199 USD This is the most complete ISO 42001 documentation pack available on the market. The documents are delivered in MS Office format and are fully editable to suit your organization's specific needs for managing Artificial Intelligence systems. In addition to standard structure and content, the ISO 42001 policy templates include example text that is clearly marked to guide you on the type of information required about your organization’s AI governance, ethical practices, and risk controls. Comprehensive example documents are also provided to support your ISO 42001 implementation process. This ISO 42001 Toolkit is the most comprehensive Artificial Intelligence Management System (AIMS) documentation pack available on the market. ### ISO 45001 Assessment Tool - Ultimate Solution URL: https://governancedocs.com/product/iso-45001-assessment-tool/ Price: $19 USD Optimize your Occupational Health and Safety system with the ISO 45001 Self-Assessment Tool. This essential tool helps identify and address gaps, ensuring ISO 45001 compliance and enhancing workplace safety. Ideal for organizations of all sizes, it streamlines the path to certification, reduces compliance costs, and fosters a culture of continuous improvement. Invest in a safer, more productive workplace today. In the bustling corridors of modern industry, where the hum of machinery meets the rhythm of human endeavor, the safety and well-being of the workforce stand as paramount. Enter the ISO 45001 Assessment Tool, a beacon of assurance in the complex landscape of Occupational Health and Safety (OHS) management. This tool is not just a product; it is a transformative journey towards achieving a safer, more compliant workplace. ### ISO 45001 Toolkit - Comprehensive 50+ Templates URL: https://governancedocs.com/product/iso-45001-toolkit/ Price: $99 USD This toolkit is the most extensive collection of ISO 45001:2018 documents available today. Designed in Office format, these documents are ready to be customized to meet the specific needs of your organization. In addition to standard formatting and content, the ISO 45001 template documents feature clearly highlighted example text to guide you on the type of information required for your organization. Complete example documents are also provided to assist with your implementation process. This ISO 45001 Toolkit is the most thorough ISO 45001 document templates pack available today. The documents are provided in Microsoft Office format, ready to be customized for your organization's unique requirements. ### ISO 9001 Toolkit - Comprehensive 45+ Templates URL: https://governancedocs.com/product/iso-9001-toolkit/ Price: $99 USD This is the most complete ISO 9001 documentation pack on the market. The documents are provided in MS Office format and can be customized to meet your organization's requirements. In addition to standard formatting and content, the ISO 9001 policy templates feature example text that is distinctly marked to show the kind of information required about your organization. Comprehensive example documents are also included to assist with your implementation process. This ISO 9001 Toolkit is the most extensive quality management system documentation pack available on the market. ### MiCA Toolkit - 100+ Comprehensive Templates URL: https://governancedocs.com/product/mica-toolkit/ Price: $99 USD This is the most comprehensive MiCA compliance documentation toolkit currently available. The documents are created in Microsoft Office format and are ready to be tailored to your organization's specific needs. As well as standard format and contents, this MiCA Documentation Toolkit includes example text that is clearly highlighted to illustrate the type of information that needs to be provided regarding your organization. Full example documents are also included to help you with your implementation of Regulation (EU) 2023/1114. This MiCA Toolkit is the most comprehensive resource currently available for implementing a crypto-asset regulatory compliance programme in accordance with Regulation (EU) 2023/1114 (Markets in Crypto-Assets Regulation, MiCA). ### NCA Cybersecurity Toolkit URL: https://governancedocs.com/product/nca-cybersecurity-toolkit/ Price: $99 USD This is one of the most comprehensive NCA Cybersecurity documentation toolkits currently available. The documents are created in Microsoft Office format and are ready to be tailored to your organization’s specific needs and regulatory context in the Kingdom of Saudi Arabia. In addition to standard structures and content, this NCA Cybersecurity Documentation Repository includes example text that is clearly highlighted to illustrate the type of information that should be provided for your organization. Full example documents are also included to support you throughout your implementation and compliance journey. Saudi Arabia's National Cybersecurity Authority sets the Essential Cybersecurity Controls (ECC) that government bodies and critical-sector organisations in the Kingdom must implement and be audited against. This toolkit is aligned to the current edition, ECC 2-2024, which replaced ECC-1:2018. This toolkit provides the documentation to meet them — covering the cybersecurity governance and policy set, the risk-management and asset-protection processes, the technical controls across the ECC domains, and the compliance-assessment and reporting records the NCA expects. Each document is written around the ECC's main domains and subdomains, so an organisation can evidence compliance at the level the authority requires. Everything is editable in Microsoft Office and ready to reflect your environment. ### NERC CIP Toolkit – 130 CIP Compliance Templates URL: https://governancedocs.com/product/nerc-cip-toolkit/ Price: $99.00 USD The NERC CIP Toolkit delivers 130 ready-to-use Microsoft Office templates for US-registered Responsible Entities — 90 Word documents and 40 Excel workbooks covering all 46 requirements and 210 requirement parts of the 13 CIP Reliability Standards enforceable today. Sixteen sections follow the standards themselves, one per standard, because that is how a Regional Entity audits you. Includes a dedicated low-impact route, an evidence register pre-loaded with every requirement and part, and the standard-version matrix that tells you which version is enforceable now and what replaces it on 1 July 2028. ### NIS2 Toolkit - 75+ Comprehensive Templates URL: https://governancedocs.com/product/nis2-toolkit/ Price: $99 USD   This is the most comprehensive NIS2 compliance documentation toolkit currently available. The documents are created in Microsoft Office format and are ready to be tailored to your organization's specific needs. As well as standard format and contents, this NIS2 Documentation Toolkit includes example text that is clearly highlighted to illustrate the type of information that needs to be provided regarding your organization. Full example documents are also included to help you with your implementation of Directive (EU) 2022/2555. This NIS2 Toolkit is the most comprehensive resource currently available for implementing a cybersecurity compliance programme in accordance with Directive (EU) 2022/2555 (NIS2). ### NIST CSF Toolkit – 164 Cybersecurity Framework 2.0 Templates URL: https://governancedocs.com/product/nist-csf-toolkit/ Price: $99.00 USD The NIST CSF Toolkit is 164 editable documents covering all 106 Subcategories of the NIST Cybersecurity Framework 2.0 — 118 Word policies and procedures plus 46 Excel workbooks, including a scored assessment and maturity tool, Current and Target Profiles, a two-axis Implementation Tier self-assessment, and crosswalks to SP 800-53 Rev 5, ISO/IEC 27001, SP 800-171 Rev 3 and CIS Controls. Every document names the Framework outcomes it answers, with NIST's own wording reproduced in full. The NIST CSF Toolkit is a complete implementation and assessment pack for the NIST Cybersecurity Framework 2.0. It is 164 editable documents — 118 Word policies, procedures and guides, and 46 Excel workbooks — covering all 106 Subcategories of the Framework Core. ### NIST Cyber Risk Management Toolkit URL: https://governancedocs.com/product/nist-risk-management-toolkit/ Price: $89 USD The NIST Risk Management Toolkit is a comprehensive collection of over 50 professional files, designed to cover all aspects of information security risk management built on the NIST SP 800-30 risk assessment methodology. This all-in-one toolkit facilitates the efficient identification, assessment, mitigation, and monitoring of security risks within an organization. The NIST Risk Management Toolkit is a set of professional collection of over 50 files covering every facet of information security risk management built on the NIST SP 800-30 risk assessment methodology, with a CSF 2.0 maturity workbook included. This toolkit serves as a complete package to streamline the identification, assessment, treatment, and monitoring of security risks within an organization. ### NIST Privacy Framework Toolkit – 145 Privacy Templates URL: https://governancedocs.com/product/nist-privacy-framework-toolkit/ Price: $99.00 USD The NIST Privacy Framework Toolkit delivers 145 ready-to-use Microsoft Office templates for building a privacy program — 108 Word documents and 37 Excel workbooks covering every one of the 102 Subcategories in NIST Privacy Framework 1.1. Nine sections follow the Framework's own five Functions, plus Current and Target Profile workbooks, an Implementation Tier assessment, five crosswalks and a 102-point audit checklist. Written against the Initial Public Draft (CSWP 40 ipd, 14 April 2025) — which we say plainly, because PF 1.1 is not final and nobody can be certified against it. ### PCI PIN Security Toolkit – 149 Templates for PIN v3.1 URL: https://governancedocs.com/product/pci-pin-security-toolkit/ Price: $99.00 USD The PCI PIN Security Toolkit delivers 149 ready-to-use Microsoft Office templates — 118 Word documents and 31 Excel workbooks — covering all 145 sub-requirements of PCI PIN Security Requirements and Testing Procedures v3.1, including Normative Annex A for remote key distribution and certification authorities and Normative Annex B for key-injection facilities. Eleven sections follow the standard's own seven Control Objectives, so a Qualified PIN Assessor can walk the pack in the order they already work in. ### PCI-DSS Toolkit - Comprehensive 180+ Templates URL: https://governancedocs.com/product/pci-dss-toolkit/ Price: $99 USD This toolkit is the most thorough PCI-DSS v4.0.1 document collection available today. Crafted in MS format, these documents are ready for customization to meet your organization’s unique requirements. In addition to the standard format and content, the PCI-DSS v4.0.1 templates feature clearly highlighted example text to guide you in providing relevant information about your organization. To further support your implementation, comprehensive example documents are also included. This is the most comprehensive PCI-DSS toolkit currently available. ### Project Management Toolkit - Comprehensive 370 Templates URL: https://governancedocs.com/product/project-management-toolkit/ Price: $99 USD This is one of the most comprehensive Project Management documentation toolkits available for PMI-aligned project delivery. All documents are provided in Microsoft Office format and are ready to be customized to your organization’s specific needs. In addition to standardized structures and content, this Project Management Documentation Repository includes clearly highlighted example text to show the type of information you should provide for your projects and organization. Full example documents are also included to guide you through setup, implementation, and consistent use across your projects and PMO. Developed in Microsoft Office format, all documents are fully customizable so you can adapt them to your organization’s industry, size, and governance requirements. Each template is pre-structured with standard content and clearly highlighted example text to guide you in inserting organization-specific details. Full example documents are also included to support a smooth and efficient implementation process. ### QHSE Documentation Bundles - Comprehensive 1,395 Templates URL: https://governancedocs.com/product/qhse-documentation-bundles/ Price: $199 USD This is one of the most comprehensive QHSE (Quality, Health, Safety & Environment) documentation bundles available, designed to support organizations in implementing and maintaining structured QHSE management systems aligned with internationally recognized standards, including ISO 9001 (Quality), ISO 14001 (Environment), and ISO 45001 (Occupational Health & Safety). All documents are professionally developed and provided in Microsoft Office formats, allowing full customization to suit your organization’s size, operational activities, regulatory obligations, and industry-specific requirements. The QHSE policies, procedures, and supporting templates include clearly marked guidance and example content to assist users in identifying and completing the required organizational inputs. In addition, ready-to-use sample documents, forms, registers, and checklists are included to enable efficient implementation, consistent application, and ongoing management of an effective QHSE framework. The QHSE Documentation Bundle is a comprehensive, audit-ready documentation package designed to support organizations in establishing, implementing, and maintaining an effective Quality, Health, Safety, and Environmental (QHSE) management framework aligned with internationally recognized ISO standards. ### Saudi PDPL Toolkit – 75 Saudi Data Protection Templates (SDAIA) URL: https://governancedocs.com/product/saudi-pdpl-toolkit/ Price: $99.00 USD Saudi PDPL Toolkit: 75 editable templates for the Saudi Personal Data Protection Law, its Implementing Regulation, the Transfer Regulation and SDAIA's rules. Policy, consent, privacy policy on SDAIA's ten elements, rights, records, processors, cross-border transfers with SDAIA's clauses, breach notification through the National Data Governance Platform, and 18 registers. Instant download. The Personal Data Protection Law has been fully enforceable since 14 September 2024, and the Saudi Data and AI Authority is enforcing it. It shares vocabulary with the GDPR and differs where it matters: consent is the default basis, legitimate interest is a narrow exception barred for sensitive data, rights requests run on 30 days plus 30, controllers register on the National Data Governance Platform, breaches go to SDAIA through that platform within 72 hours, penalties are in riyals, and there is no adequacy list yet. A GDPR template set applied in the Kingdom is wrong in each of those places. ### SOC 1 Toolkit – 87 SSAE 18 / ISAE 3402 Service Organization Templates URL: https://governancedocs.com/product/soc-1-toolkit/ Price: $99.00 USD SOC 1 Toolkit: 87 editable SOC 1 / ISAE 3402 templates built on AT-C section 320 — management's system description in every required section, 19 control objectives with 76 risks and 77 illustrative controls, CUEC and CSOC registers, type 1 and type 2 assertions, the representation-letter checklist and a bridge letter — plus 6 documents for user entities reviewing a vendor's report. Instant download. A SOC 1 report has three parts, and management writes two of them. The service auditor examines management's description of the system and management's assertion; it does not write either. A first engagement turns on whether that description exists, and a folder of policies is not one. ### SOC2 Toolkit - Premium Documentation Pack URL: https://governancedocs.com/product/soc2-toolkit/ Price: $99 USD Safeguard your business and ensure compliance with our SOC 2 Toolkit. Designed specifically for service organizations that process customer data, this comprehensive toolkit equips you with the essential resources to navigate the complexities of SOC 2 Trust Services Criteria and audit requirements. SOC2 Toolkit is used to help organizations strengthen information security, enhance customer trust, and ensure compliance with the SOC 2 framework. ### TPRM Toolkit – 86 Third-Party Risk Management Templates URL: https://governancedocs.com/product/tprm-toolkit/ Price: $99.00 USD TPRM Toolkit: 86 editable third-party risk management templates on the lifecycle every regulator uses — planning, due diligence, contracting, monitoring and exit — mapped to 188 requirements across 12 regimes including the 2023 Interagency Guidance, DORA, NIST CSF 2.0, ISO/IEC 27001, SOC 2, PCI DSS, GDPR, HIPAA and NYDFS. Three vendor security questionnaires arrive already written. Instant download. ### UK GDPR Toolkit – 90 UK Data Protection Templates (DUAA 2025) URL: https://governancedocs.com/product/uk-gdpr-toolkit/ Price: $99.00 USD UK GDPR Toolkit: 90 editable UK data protection templates written for the UK GDPR as amended by the Data (Use and Access) Act 2025, the Data Protection Act 2018 and PECR. Policies, privacy notices, DSAR and complaints procedures, DPIA, IDTA and Addendum guides, breach management, cookies and marketing, and 20 registers. Instant download. The United Kingdom's data protection regime is no longer the EU GDPR with the flags changed. The Data (Use and Access) Act 2025 rewrote the lawful bases, the purpose limitation rules, the time limits for rights requests, automated decision-making, international transfers, the cookie rules and the way complaints are handled, and it did so in stages: 19 June 2025, 20 August 2025, 5 February 2026 and 19 June 2026. A pack that still names an EU regulator instead of the Commissioner, cites the complaint article the UK has omitted, relies on the EU standard contractual clauses without the UK Addendum, or sets the age of digital consent at sixteen is describing a different jurisdiction. ### WISP Toolkit – 74 FTC Safeguards Rule Templates URL: https://governancedocs.com/product/wisp-toolkit/ Price: $99.00 USD Written Information Security Plan toolkit for US tax and accounting practices. 74 editable templates covering all 10 elements of the FTC Safeguards Rule, 16 CFR Part 314 — including the FTC notification obligation that took effect on 13 May 2024. Includes a 19-document fast path for practices holding information on fewer than 5,000 consumers, which 16 CFR 314.6 exempts from four of those ten. Instant download. ## Common questions Q: How are the toolkits delivered? A: As an instant download immediately after purchase - editable Microsoft Word and Excel files, no waiting or shipping. Q: Are the templates ready to use? A: Yes. Each template includes example content and structured headings; you replace the placeholder details with your organization's information. Q: Can consultants use a toolkit for multiple clients? A: Yes. The toolkits are widely used by GRC consultants and advisory firms across multiple client engagements. Q: Is there a guarantee? A: Yes - a 30-day money-back guarantee. Q: Which standards and frameworks are covered? A: 70+ including ISO 27001, ISO 9001, ISO 22301, ISO 42001, SOC 2, GDPR, HIPAA, PCI-DSS, NIST (800-53, 800-171, AI RMF, CSF), CMMC, FedRAMP, DORA, NIS2, EU AI Act, CCPA/CPRA, and more. Last generated: 2026-09-16 (auto-generated from the live catalog).