Management system
A certifiable ISMS is more than a set of controls. ISO 27001 also asks you to run the system: audit it, review it with leadership, fix what’s broken, set measurable objectives, and keep the registers that underpin it. Keel gives each of these its own module, and because they share one graph with your controls, evidence, and risk register, findings and inputs flow between them instead of living in disconnected spreadsheets.
What’s covered
Section titled “What’s covered”| Module | Clause | Where in Keel |
|---|---|---|
| Internal audits | ISO 27001 / 9001 Clause 9.2 | Internal audits |
| Audit programme & calendar | Clause 9.2.2 | Audit programme |
| Management review | ISO 27001 / 9001 Clause 9.3 | Management reviews |
| Nonconformity & corrective action | ISO 27001 / 9001 Clause 10 | Nonconformities |
| Objectives & KPIs | ISO 27001 Clause 6.2 | Objectives & KPIs |
| Information asset register | Annex A 5.9 & 5.12 | Information assets |
| Legal & regulatory register | Annex A 5.31 | Legal & regulatory |
| Documented information | Clause 7.5 | Documented information |
| Competence matrix | ISO 27001 Clause 7.2 | Competence |
Shared with ISO 9001
Section titled “Shared with ISO 9001”The internal-audit, audit-programme, management-review, and corrective-action modules are written to the clauses ISO 27001 and ISO 9001 hold in common (9.2, 9.2.2, 9.3, and 10). If you run both standards, you work these modules once and they serve each management system, the same way a control crosswalks across frameworks.
How it connects
Section titled “How it connects”- An internal audit records findings against a clause-by-clause checklist. A nonconformity finding promotes straight into a nonconformity (CAPA) record.
- Security incidents and control gaps also feed the CAPA register.
- A management review pulls its agenda inputs — open nonconformities, completed audits, audit findings, and incidents — live from these modules, so the review reflects the real state of the program.
Next steps
Section titled “Next steps”- Internal audits, programme & review: plan, audit, and review.
- Nonconformity & CAPA: find root cause and verify the fix.
- Supporting registers: assets, legal, documents, objectives.
- Competence & people: show the right people are competent and know the rules.