Compliance tools · Cybersecurity and data protection · A-019
Toolkit for ISO 27701 compliance tool
ISO/IEC 27701:2019 · European Union and United Kingdom · Voluntary standard
Appoint the compliance person you already employ. The system trains them.
A member of your own staff, with no compliance background, reads the training module, answers the interview, and finishes with your Toolkit for ISO 27701 documentation cited clause by clause. The knowledge stays in the business.
£495 one-time purchase
Available now. Instant download after checkout. Runs in your own Claude account.
Start the free assessment Buy in your accountThe standard
Toolkit for ISO 27701 is ISO/IEC 27701:2019, a voluntary standard in the European Union and United Kingdom. Privacy information management extension to ISO 27001. The ISO standard document is not included: you purchase your licensed copy separately and this toolkit works alongside it.
Scope
The free assessment screens for Toolkit for ISO 27701 when a business handles personal data.
Sectors named in the register for this instrument: IT and technology; SaaS; health services; marketing and analytics; HR and recruitment services; financial services.
This is a voluntary standard rather than binding law. Businesses adopt it because customers, insurers or public buyers ask for it.
Screen your business against all 87 instruments, free →
The problem it solves
Trained compliance people are scarce and expensive. A compliance consultant charges €800 to €1,500 a day, and when the engagement ends the knowledge leaves with them. Enterprise GRC platforms run to €50,000 and more in setup, then charge per seat, per framework, per year, and most assume you already employ a specialist to drive them.
So in most small and medium businesses the work lands on whoever sits closest to IT, tracked in a spreadsheet. That is a single point of failure carrying the compliance position of the whole company, with no training behind it.
The compliance system
The system is built to take a person who has never read the standard to a completed, cited compliance report. The training module teaches the standard first, in plain language. Then the system interviews them about your organisation in your own Claude account: upload the files, type START, and answer one question at a time. The working files collect the evidence the standard asks for and record what is in place and what is missing, and your documentation is produced with clause citations an auditor can check against the standard.
No consultant, no sales call, no per-seat pricing, no platform you are locked into. A one-time purchase you keep, completed without hiring anyone.
What you finish with
- Your exact position under Toolkit for ISO 27701: what is in place, what is missing, and what to do about each gap.
- Documentation with clause citations, ready for auditors, insurers, customers and public buyers.
- A trained person inside the business who understands what the standard requires, and stays.
- Evidence files you keep on your own systems, with no recurring fee to read your own assessment.
- All of it completed in-house, at your own pace, without booking a single meeting.
Why not just ask an AI?
Ask a general AI whether it can produce your compliance documentation and it will tell you it can. Models are built to agree with you. It cannot, in one sitting or a thousand, because the capability does not live in the model: it lives in the machine engineering around it, the obligations dictionary, the evidence structure, the citation discipline and the current text of the law.
A general model also answers from its training data, and regulation moves faster than training data. An agentic system improvises around the gaps and answers with confidence either way, and you cannot tell which of its answers are current. That is how a business ends up documented against a version of the law that no longer exists.
The ComplianceSME system removes the gamble. Agentic behaviour is engineered out: the AI works inside structured files that hold the accurate, current standard, it follows the interview, and every finding is produced with clause citations you can verify against the standard itself. The system carries the standard in full, so nobody in your business is burdened with reading it cold.
The gap between what you think AI can achieve, what AI will say it can achieve, and what it can really achieve is huge. That gap is the first thing every toolkit teaches: the training module opens with AI literacy before it opens the standard, so the person running the system understands the tool in their hands before they trust it with the law.
Why trust it
Every system in the register is built against a frozen dictionary of 9,904 obligations across 87 instruments, through a documented build method. ComplianceSME's EU AI Act work has been covered in Solicitors Journal. The register, the catalogue and every price are public on this site: no demo call, no quote form, no pipeline.
With the membership, every system you own is updated in your dashboard as the law shifts. ComplianceSME monitors compliance globally and is contributing to the deferred 2027 provisions still to come, the only voice in that process representing 31.6 million SMEs across our 28 nations.
The cost, against the alternatives
A consultant at €800 to €1,500 a day charges again for every question, and the knowledge leaves when the invoice is paid. A GRC platform charges every year, for every seat, and holds your assessment inside its subscription. The Toolkit for ISO 27701 system is £495 once. It trains your own person, and the training, the evidence files and the finished documentation stay in the business.
£495 one-time purchase
Instant download after checkout. Runs in your own Claude account. Yours permanently.
Buy the Toolkit for ISO 27701 system Check it applies first, freeQuestions businesses ask
Does Toolkit for ISO 27701 apply to my business?
The free assessment screens for Toolkit for ISO 27701 when a business handles personal data. Sectors named in the register for this instrument: IT and technology; SaaS; health services; marketing and analytics; HR and recruitment services; financial services. This is a voluntary standard rather than binding law. Businesses adopt it because customers, insurers or public buyers ask for it. The free assessment at compliancesme.com screens your business against all 87 instruments in the register at once, and takes about ten minutes.
What is Toolkit for ISO 27701?
Toolkit for ISO 27701 is ISO/IEC 27701:2019, a voluntary standard in the European Union and United Kingdom. Privacy information management extension to ISO 27001. The ISO standard document is not included: you purchase your licensed copy separately and this toolkit works alongside it.
How much does the Toolkit for ISO 27701 compliance system cost?
The Toolkit for ISO 27701 compliance system costs £495 as a one-time purchase, downloaded immediately after checkout. An optional membership at £500 per month keeps every system you own current when the law changes; the system works without it and remains yours either way.
Do I need a consultant to comply with Toolkit for ISO 27701?
No. The system runs in your own Claude account, interviews you in plain language one question at a time, collects the evidence the instrument asks for, and produces your compliance documentation with article citations. It is a documentation tool, not legal advice.
Who in my business should run the Toolkit for ISO 27701 system?
Any member of staff who is comfortable with a computer. The training module teaches the standard before the interview begins, so no compliance background is required. Owners typically appoint an operations manager, an office manager or an IT lead, and the system takes that person from first reading to finished, cited documentation.
Related in cybersecurity and data protection: GDPR · ePrivacy Directive · NIS2 Directive · CER Directive