# AES Tech compliance readiness checklist

Source: https://aestech.com.au/compliance-readiness/
Last updated: 2026-06-21

Use this as a practical working checklist for choosing and preparing for ISO 27001, SOC 2, PCI DSS, or ISO 42001. Adapt it to your real systems, customer commitments, suppliers, legal obligations, and audit scope.

## Framework router

### SOC 2

Trigger: US SaaS buyers ask for a security report.
First move: Define system boundaries, Trust Services Criteria, and evidence owners.
Guide: https://aestech.com.au/soc-2/
Templates: https://aestech.com.au/soc-2/templates/

### ISO 27001

Trigger: Enterprise, government, or international customers ask for certification.
First move: Define ISMS scope, risk method, Statement of Applicability, and policy set.
Guide: https://aestech.com.au/iso-27001/
Templates: https://aestech.com.au/iso-27001/templates/

### PCI DSS

Trigger: You process, store, or transmit payment card data.
First move: Map cardholder data flows, reduce scope, and document the CDE boundary.
Guide: https://aestech.com.au/pci-dss/
Templates: https://aestech.com.au/pci-dss/templates/

### ISO 42001

Trigger: You build, provide, buy, or govern AI systems.
First move: Create an AI system inventory, impact assessment, and approved-use policy.
Guide: https://aestech.com.au/iso-42001/
Templates: https://aestech.com.au/policy-templates/#ai-use-and-governance-policy

## 30-minute readiness workshop

1. Confirm the buyer or regulator trigger
   - Write down whether the pressure is customer trust, certification, cardholder data, governed AI systems, or a combination.
   - Link: https://aestech.com.au/compare/soc-2-vs-iso-27001-vs-pci-dss/
2. Draw the first scope boundary
   - List the products, systems, teams, suppliers, locations, and data types that should be inside the first audit or assessment boundary.
   - Link: https://aestech.com.au/compliance-readiness/#framework-router
3. Map controls to policies
   - Use the control-to-policy map to choose the policy templates that cover access, data, suppliers, incidents, development, backups, endpoints, cryptography, and AI use.
   - Link: https://aestech.com.au/policy-templates/control-mapping/
4. Assign owners and evidence
   - For each policy, name the owner, review cadence, evidence source, and exception path before buying software or booking an audit.
   - Link: https://aestech.com.au/policy-templates/
5. Decide when to automate
   - Compare compliance platforms once owners, integrations, recurring evidence, and auditor workflow become difficult to manage manually.
   - Link: https://aestech.com.au/compare/compliance-software/

## Readiness checklist

### Scope and accountability

- [ ] Define the systems, teams, suppliers, and locations in scope. (https://aestech.com.au/iso-27001/templates/)
- [ ] Name one accountable owner for each framework and evidence area. (https://aestech.com.au/policy-templates/#access-control-policy)
- [ ] Write customer commitments in plain language before mapping controls. (https://aestech.com.au/compare/soc-2-vs-iso-27001-vs-pci-dss/)

### Risk and control map

- [ ] Run a risk assessment and record treatment decisions. (https://aestech.com.au/iso-27001/templates/)
- [ ] Map controls to ISO 27001, SOC 2, PCI DSS, or ISO 42001 once, then reuse evidence. (https://aestech.com.au/compare/compliance-software/)
- [ ] Keep exceptions, residual risk, and target dates visible to leadership. (https://aestech.com.au/iso-27001/templates/)

### Policies and procedures

- [ ] Publish access control, acceptable use, incident response, supplier, backup, and encryption policies. (https://aestech.com.au/policy-templates/)
- [ ] Add AI use rules for prompts, sensitive data, approved tools, and human review. (https://aestech.com.au/policy-templates/#ai-use-and-governance-policy)
- [ ] Make each policy show owner, review cadence, evidence, and exception process. (https://aestech.com.au/policy-templates/policy-pack.md)

### Evidence operations

- [ ] Collect access approvals, MFA status, offboarding records, and privileged access reviews. (https://aestech.com.au/policy-templates/#access-control-policy)
- [ ] Collect supplier reports, risk tiers, contracts, and annual reviews. (https://aestech.com.au/policy-templates/#supplier-security-policy)
- [ ] Collect incident tickets, backup tests, change approvals, monitoring alerts, and vulnerability records. (https://aestech.com.au/policy-templates/#incident-response-policy)

### Audit readiness

- [ ] Choose the first external proof customers actually ask for. (https://aestech.com.au/compliance-readiness/#framework-router)
- [ ] Run an internal review before paying for an auditor or assessor. (https://aestech.com.au/iso-27001/requirements/9-performance-evaluation/)
- [ ] Use compliance software when evidence owners, integrations, and audit deadlines become hard to manage manually. (https://aestech.com.au/best/best-iso-27001-compliance-software/)

## Minimum evidence set

- Scope statement and framework decision record.
- Risk register and treatment decisions.
- Statement of Applicability if ISO 27001 applies.
- Access control, acceptable use, supplier security, incident response, backup, encryption, endpoint, secure development, and data handling policies.
- AI use and governance policy if AI tools, AI suppliers, or model outputs are in scope.
- Access approvals, offboarding records, privileged access reviews, supplier reviews, incident tickets, change approvals, backup tests, vulnerability records, and monitoring alerts.

## Template shortcuts

Policy template library: https://aestech.com.au/policy-templates/
Control-to-policy map: https://aestech.com.au/policy-templates/control-mapping/
Full Markdown policy pack: https://aestech.com.au/policy-templates/policy-pack.md
21 templates are available in the full pack.

## Software shortlist

Compare compliance software: https://aestech.com.au/compare/compliance-software/
Best ISO 27001 compliance software: https://aestech.com.au/best/best-iso-27001-compliance-software/
Best SOC 2 compliance software: https://aestech.com.au/best/best-soc-2-compliance-software/

## Common questions

### Should a startup do SOC 2 or ISO 27001 first?

Follow buyer demand. US SaaS customers usually ask for SOC 2 first. International, enterprise, government, and Australian buyers often recognise ISO 27001 more readily. If you sell globally, many teams eventually map both.

### Does PCI DSS replace SOC 2 or ISO 27001?

No. PCI DSS applies when you process, store, or transmit payment card data. SOC 2 and ISO 27001 are broader security assurance frameworks. A card-data business may need PCI DSS plus SOC 2 or ISO 27001.

### What documents should I create first?

Start with scope, risk register, Statement of Applicability if ISO 27001 applies, access control policy, incident response policy, supplier security policy, data handling policy, backup policy, encryption policy, and AI use policy if AI tools are in scope.
