Governance, ISO, Cyber Essentials and AI Resources

Access practical tools, templates and guides that support governance, ISO standards, Cyber Essentials readiness and responsible AI use. These resources strengthen control, provide clarity and support audit ready documentation across your organisation.

ISO resources

Guides and templates that support ISO 27001, ISO 9001 and wider governance requirements.

Cyber Essentials resources

Checklists and documentation aligned with Willow guidance to support scoping and evidence preparation.

AI governance resources

Guidance to help you identify AI use, understand data impact and document governance responsibilities.

Templates and tools

Operational templates for governance, risk, audit findings and responsibilities.

ISO resources

ISO 27001 clauses overview guide
A clear breakdown of clauses four to ten in plain language. Explains intent, governance expectations and the areas auditors typically focus on when they review your ISMS.
ISO 27001 risk assessment template
A structured template for identifying, evaluating and treating information security risks. Aligned with clause six and clause eight, and laid out to make audit evidence easy to follow.

Cyber Essentials resources

Practical guides and templates that support Cyber Essentials under Willow guidance. These resources help organisations scope accurately, control their technical setup and prepare evidence with confidence.

Cyber Essentials scoping checklist
A practical checklist that helps you define in scope systems and services. Supports accurate scoping and reduces the risk of missed assets during assessment. Helps organisations document a clear boundary for their certification.
Acceptable use policy template
A practical policy template that defines how staff may use company devices, networks and cloud services. Includes a clear AI usage section aligned with Cyber Essentials expectations, helping organisations explain what tools are allowed, restricted or prohibited.
Firewall rules and allowed connections guide
A clear guide that explains how to document firewall rules, outbound and inbound connections, business justification and review frequency. Supports organisations in meeting Cyber Essentials requirements and demonstrating controlled, understood access.
CE assessment preparation checklist
A practical checklist outlining what organisations should have in place before starting a Cyber Essentials assessment. Covers devices, applications, admin accounts, updates, firewall settings and basic documentation to support a smoother submission.

AI governance resources

AI identification guide
A practical guide that helps you identify where AI is being used across your organisation, what data it interacts with and how its outputs influence decisions. Supports clearer governance and evidence for future regulatory expectations.
AI tool assessment template
A structured worksheet for reviewing AI enabled tools in your business. Helps you record what each tool does with information, capture evidence and calculate a traffic light awareness score. Supports clearer decisions on when a deeper data protection review is needed.

Templates and tools

Practical tools that support governance, risk and audit activity across your organisation. These templates provide clear structure, help maintain accountability and make evidence easier to manage.

Risk register template
A structured register for recording risks, controls, ownership and current status. Designed to improve visibility and ensure risk decisions remain documented and consistent.
Audit finding and corrective action log
A log that supports internal and external audits by tracking findings, root causes, corrective actions, responsible owners and closure progress.

Why these resources matter

These resources support practical governance and help organisations maintain clear structure, strong controls and audit ready evidence.

As standards evolve, more ISO, Cyber Essentials and AI governance material will be added to this library.

Created with