COMPLIANCE365
CHECKPOINT

The compliance console that lives in your tenant.

Posture scanning via Microsoft Graph, a linked risk and actions register, a living Statement of Applicability, and one-click audit reports. Every record is stored as SharePoint lists inside your own Microsoft 365 tenant.

Sign-in uses the Microsoft permissions your organisation's administrator approved for Checkpoint, once, for everyone.

Data residencyCheckpoint has no backend and no database. Your registers live in your SharePoint; posture checks are read at scan time and never leave the browser.

Checkpoint

    Working…
    CHECKPOINT SETUP

    Let's get your tenant set up.

    Checkpoint scans your Microsoft 365 tenant's security posture, keeps a linked risk and actions register, and builds a living Statement of Applicability — every record stored as SharePoint lists inside your own tenant.

    Data residencyCheckpoint has no backend and no database. Nothing is copied anywhere else — posture checks are read at scan time straight from Microsoft Graph and never leave your browser. Setup takes about five minutes.

    Before you sign in

    Exactly what Checkpoint asks Microsoft for at sign-in, and why — every one of these is read-only. Nothing here can change your tenant.

    Two more permissions are requested later, only when actually needed: access to create your SharePoint registers, the moment setup provisions them (next in this wizard); and email-send access, only if you ever use the "Email status update" button. Your Microsoft 365 admin approves each the first time it's needed — never all at once.

    Checking what your tenant can tell us

    A quick, read-only check using the permissions you just granted — nothing is written yet.

    Activate this tenant

    Paste or upload the activation file Compliance365 issued for this tenant. It's verified entirely in this browser (Ed25519 signature, tenant match, expiry) — nothing is sent anywhere to check it, and nothing is provisioned until it verifies.

    Where should your records live?

    Checkpoint creates a handful of SharePoint lists to hold your risk register, controls, evidence and more. They hold audit findings and management review minutes, so where they live decides who can read them.

    Which frameworks do you need now?

    ISO 27001 is included as the baseline. Every other framework shown here is one your activation licenses — turn on whichever you need now; every control set provisions either way, so switching one on later needs no reconfiguration.

    Enable the AI assistant?

    Your activation includes the AI assistant add-on — a drafting aid grounded in your own registers, running against your own Azure OpenAI resource in your own tenant. You can set this up now, or skip it and configure it later from the AI assistant view. See AI-SETUP.md for provisioning the resource first.

    Azure OpenAI endpoint
    Deployment name

    Setting up your tenant

    Starting…

    Setup complete

    Here's where things stand from your first scan.

    Who can use Checkpoint?

    Optional, and entirely your call — the whole team can use the Practitioner experience by default, or you can set up two SharePoint groups for tighter control.

    Two roles, set up once per tenant

    Checkpoint Practitioners — full edit access, everything in this app. Create a SharePoint group with exactly this name and grant it Edit (or Contribute) on every Checkpoint * list and the Checkpoint Documents library. Add yourself and anyone who'll be doing the day-to-day work.
    Checkpoint Viewers — read-only. Create a second group with exactly this name and grant it Read on the same lists/library. Add stakeholders you want to give direct Dashboard/Board-view/report access to, instead of emailing status updates.

    Group names must match exactly — Checkpoint looks up your membership by display name. If neither group exists, everyone gets the full Practitioner experience (a deliberate, safe default) — nothing here changes who can actually write to SharePoint; that's always enforced by the permissions above, regardless of what this app's UI shows.

    Brand your documents (optional)

    Add your organisation’s logo now and every policy, procedure and report Checkpoint generates carries it, including the first document set. A small PNG, JPG or SVG under 40 KB. You can change it later in Settings → Client branding.

    — —

    Dashboard

    Live assurance position for this tenant. Every figure below is computed from the registers — nothing is typed into a slide the night before an audit.

    Audit readiness
    Risk & obligations

    Position

    Fingerprint, certification journey, residual risk and the posture trend.

    Certification journey

    Residual risk

    Posture score trend

    Operations

    Automation, drift since the last scan, the assurance pulse, governance and activity.

    Continuous monitoring — drift since last scan

    Assurance pulse

    26 weeks of compliance activity — scans, evidence, attestations, reviews and audits. Click a week to filter the Activity feed below.

    Governance

    Activity

      Integrations

      Where Checkpoint gets its evidence from, whether each source is reporting, and how to set up the ones that are not. Every collector runs in the client's own tenant or account and writes only to the client's own SharePoint; Compliance365 holds no credentials for any of them.

      Board view

      A live, presentation-ready summary — pull this up instead of screen-sharing the full console. Nothing here is editable; it always reflects the current data.

      Certification roadmap

      Top risks

      Upcoming milestones

      Cross-framework mapping

      Which controls earn credit in more than one framework. Implement one of these and every control in its "Also satisfies" column is evidenced too — so the top of this list is the highest-leverage place to spend an hour.

      Posture scan

      A read-only check of your Microsoft 365 security settings. Findings are proposed as business risks for you to approve: nothing changes in your registers without your sign-off.

      — /100
      No scan yet this session

      All checks

      Risk register

      Inherent and residual scoring, linked controls and treatment actions. Residual is estimated from completed treatment actions until someone records an assessed one, which then takes precedence. Open risks not reviewed within the cadence are flagged.

      IDRiskCategoryCIASourceInherentResidualReviewedTreatmentOwnerStatus

      Residual risk heatmap

      Every open risk by likelihood × impact. Click a cell to filter the table.

      Opportunities

      Uncertainty that could help the organisation (ISO 31000), recorded alongside its risks as ISO 27001 Clause 6.1.1 asks. Rated by likelihood and benefit. Kept separate from the risks above, so they never count towards risk levels, the heatmap or the risk appetite.

      IDOpportunityCategoryLikelihood × benefitResponseReviewedOwnerStatus

      Financial risk analysis

      Every open risk's likelihood/impact score, translated into a simulated annual loss distribution — 10,000-trial Monte Carlo, re-run automatically whenever the risk register changes. Loss frequency and magnitude ranges are derived directly from each risk's own residual score (documented, editable assumptions below) — no separate data entry required. Treat this as a defensible order-of-magnitude view, not a measured figure: refine a risk's own numbers by hand wherever real loss history or insurance/actuarial data exists.

      Loss exceedance curve

      The probability that this tenant's total annual loss from open risks exceeds a given amount — read any point as "there's a Y% chance losses exceed $X this year."

      Assumptions

      The illustrative loss-magnitude and event-frequency ranges each residual score maps to — the only inputs this simulation runs on.

      Risk ranking by simulated exposure

      The same open risks as the Risk register, re-ordered by simulated financial exposure (P90 annual loss) rather than ordinal L×I — the two rankings don't always agree.

      IDRiskResidual bandMean annual lossP90 annual lossP99 annual lossAssumptions

      Actions register

      Every action traces to a risk and a control. Completing an action prompts evidence capture and updates the linked risk's residual score — the audit trail builds itself. Also the home for non-conformities and observations raised during internal or external audits.

      IDActionTypeLinked toPriorityOwnerDueStatusEvidence

      Due runway and status by priority

      Where the pressure is on the calendar, and whether the actions that matter most are moving.

      Supplier risk

      Third-party suppliers with access to systems or data, reviewed on a cadence proportional to their criticality. Linked to the supplier-related controls (A.5.19–A.5.23, CC9.2, DISP.26) and to the risk register — an overdue review here is a live gap in the Statement of Applicability, not a separate spreadsheet.

      IDSupplierCriticalityReview statusNext reviewCertificationsOwnerQuestionnaire

      Review status by criticality

      A Critical or High supplier still at Not started is the one that matters most.

      AI systems

      Every AI system in use, its impact assessment status, and the ISO 42001 controls it evidences — the register ISO 42001 certification is actually built on, not a slide deck assembled the week before audit. EU AI Act risk tiers (Prohibited/High/Limited/Minimal) drive how much scrutiny each system gets.

      Impact assessment status by risk tier

      A Prohibited or High-tier system with no impact assessment started is the one an assessor asks about first.

      IDSystemRisk tierImpact assessmentSupplierOwnerLast reviewed

      Threat intel

      Vulnerabilities attackers are exploiting right now (CISA's Known Exploited Vulnerabilities catalog), for the suppliers a Microsoft 365-centred business typically runs. The ones that match your technology come first. Assess each one: does it affect you, is it already patched, or do you not run it? "Affects us" raises a remediation action. The record is your evidence for ISO 27001 A.5.7 (threat intelligence) and A.8.8 (technical vulnerabilities). It complements patch management; it does not replace a vulnerability scanner.

      Frameworks

      Every framework Compliance365 delivers is available in Checkpoint. ISO 27001 is included as the baseline; every additional framework is unlocked by a Compliance365-issued, signed entitlement file — not a self-service toggle. Enabling a framework makes its control set appear in the Statement of Applicability immediately; nothing is deleted when a framework is switched off.

      Licence

      Upload or paste the entitlement file Compliance365 issued for this tenant. It's verified in this browser (Ed25519 signature, tenant match, expiry) before anything changes — nothing is sent anywhere to check it.

      What Checkpoint currently holds
      Framework targets

      Per-framework configuration — the maturity level or reporting shape each framework is being worked towards. Only the frameworks entitled on this tenant appear.

      Settings

      How Checkpoint behaves for this tenant — reporting and branding, the automation cadences, posture thresholds, optional features, and the organisation profile generated documents fill themselves in from. Framework licensing and per-framework targets live in the Frameworks view.

      Setup health

      Checkpoint checks its own setup every time someone signs in: activation, Microsoft Graph permissions, the SharePoint lists and Documents library, framework content, evidence folders and scans. Anything wrong comes with a fix.

      Reporting & branding

      What generated reports and policy documents carry — the client's own name, logo, accent colour and classification marking.

      Scope & context

      The facts ISO 27001 expects this organisation to be specific about — its scope boundaries (Clause 4.3), its interested parties and their requirements (Clause 4.2). Answered once here, then filled into every generated document that needs them, instead of being retyped into each one. Left blank, documents generate with generic wording exactly as before.

      Automation & cadence

      How often Checkpoint expects work to happen, and who it tells when it hasn't. The scheduled monitor (SETUP.md § Continuous monitoring) acts on these unattended once deployed.

      Notifications

      Who Checkpoint tells, and where: the owner reminder emails and the Microsoft Teams channel.

      Thresholds and intervals

      Posture-scan thresholds, and the intervals your ISMS runs on: risk review, document review, management review, internal audit and remediation windows. Generated documents state these intervals rather than a fixed number, so change one here, regenerate, and the documents say what you do. Recurring activities such as access reviews take their frequency from the compliance calendar. Each falls back to the default shown if left blank.

      Features

      Optional dashboard and workflow additions — switch any of these off per client without losing data. Turning one back on picks up exactly where it left off.

      Setup

      Re-run setup

      Step back through the tenant capability check, site selection and framework picks, then re-provision and re-scan. Safe to run again — nothing already in your registers is deleted.

      Data export

      Every register can also be exported as a flat CSV file from its own view — see the "Export CSV" button at the top of Risks, Actions (plus its own progress-log export), the Statement of Applicability, Supplier risk, Internal audits, Management review, the Compliance calendar and the Audit log. The client's data always stays in their own SharePoint lists regardless — this is a portable copy alongside it, for offboarding, an offline backup, or handing a snapshot to an auditor who wants a spreadsheet.

      Export all registers (ZIP)

      Every register's CSV in one download, built entirely in this browser — nothing is uploaded anywhere to produce it.

      Export all registers (Excel)

      One workbook with every register on its own sheet, with a frozen header row and filters. Built in this browser.

      Backups

      A dated zip of every register, the settings and an index of your evidence, saved into your own SharePoint (Documents › Checkpoint backups). The scheduled monitor writes one every week and keeps the newest 13; Back up now writes one straight away and downloads a copy.

      Statement of Applicability

      One control set per purchased framework, cross-mapped to the others so shared evidence is never duplicated. Essential Eight is assessed by maturity level (ML1-ML3) per strategy against your target level, set in Frameworks — every other framework's full published control set ships ready to use.

      Implementation
      ControlTitleScopeStatusAlso satisfiesOwnerAssuranceVerifiedEvidence

      Status by theme

      Implementation mix across this framework's themes.

      Auditor guide

      For the certification body's auditor: where each piece of evidence is, in the order a Stage 1 and Stage 2 audit usually works through it. Everything here is read-only.

      Guided build

      The information security management system, built one stage at a time in the order it is actually done: scope, leadership and the risk framework first, then the risks and the Annex A controls that treat them, then running it, checking it and certification.

      Who does what

      Everyone with a part in the information security management system: their role, and what they are responsible for, from the owners recorded on each register.

      My tasks

      Everything assigned to you in the information security management system, with the one button that does each. Nothing else to learn.

      Management system clauses

      ISO 27001 Clauses 4-10 (and ISO 42001's, when the tenant is entitled to it) — the management-system requirements themselves, as distinct from the Annex A controls in the Statement of Applicability. Every clause here is mandatory: unlike a control, a clause can never be marked Not Applicable, which is why this is its own register rather than more rows in the SoA. Clause 10.2's evidence is the corrective-action loop on each nonconformity in the Actions register; its row here shows how many are still open.

      ClauseTitleStatusOwnerVerifiedEvidence

      Shared evidence

      One artefact often satisfies the same real-world control in every purchased framework at once. Pick a control below to see everywhere its evidence applies — across ALL entitled frameworks, following the cross-mappings already shown as "Also satisfies" on the Statement of Applicability — then attach it once instead of clicking "Link evidence" separately on each row.

      Start from a control

      Documents

      Real evidence storage in this tenant's SharePoint — the ISMS manual, policies, risk treatment plan, training records. Upload here, or upload directly in SharePoint and paste the link when linking evidence to a control or action. Files over 4 MB: upload in SharePoint directly, then paste the link.

      Document control register

      ISO 27001 clause 7.5.2/7.5.3 — every controlled document carries an owner, a version, an approval and a next-review date. These are real SharePoint columns on the library, so the same register is visible natively in SharePoint too.

      DocumentOwnerVersionStatusNext review

      Interpret evidence with AI

      Paste the text of an assurance artefact you already hold — a supplier's SOC 2 report, a penetration test summary, an access review sign-off, a backup job report — and get a draft of which of your controls it evidences, the period it covers, and, just as usefully, what it does not cover. Nothing is linked to a control until you say so.

      Policy template library

      Generate a policy or management-system document, or the full set.

      Starter policies and management-system documents, written for a Microsoft 365 environment and grouped by the frameworks this tenant is licensed for. Personalise, generate a print-ready document, and save a copy straight into Policies & Procedures below — registered as DRAFT with its owner and review date until a practitioner approves it.

      Every document this tenant's frameworks need, in one go — linked to their clauses and controls automatically.

      Upload a document

      Your own policy, procedure or evidence file, up to 4 MB.

      Wrote your own policy or procedure? Choose the Checkpoint document it replaces. Once you record its approval under Details, it updates the clauses and controls exactly as Checkpoint’s own version would, and the generated copy is marked Superseded.

      Policy attestation

      ISO 27001 A.5.1 requires policies to be communicated to — and acknowledged by — relevant personnel, and A.6.3 expects the same of awareness material. An auditor samples individuals, so this records one row per person per policy version, with the date they acknowledged it. Employees see only their own outstanding items.

      My attestations

      Campaigns

      One campaign per policy version. Progress is the share of recipients who have acknowledged it.

      CampaignPolicyLaunchedProgressOutstanding

      All attestation records

      Every individual acknowledgement, which is what an auditor samples.

      PersonPolicyVersionAssignedAcknowledgedStatus

      Training

      ISO 27001 A.6.3 and clause 7.2/7.3 expect awareness and competence to be delivered and demonstrated, not just offered — and an auditor samples individuals. Each course ends in a short comprehension check, and completion is recorded per person against that course version. Phishing simulation is deliberately not duplicated here; Microsoft Defender's Attack Simulation Training does that job.

      My training

      Course catalogue

      Filtered to the frameworks this tenant is licensed for. Anyone can read a course at any time — completion is only recorded against an assignment.

      Training campaigns

      One campaign per assignment run. Completion is the share of recipients who have passed the comprehension check.

      CampaignCourseAssignedCompletionOutstanding

      All training records

      Every individual assignment, which is what an auditor samples.

      PersonCourseVersionAssignedCompletedScoreStatus

      Certification

      Staying certified after the first audit. Record the certificate and Checkpoint lays out the three-year cycle — two surveillance audits, then recertification before the certificate expires — puts each audit on the compliance calendar, tracks what the certification body found, and shows whether this cycle's internal audits have covered every clause and Annex A theme the recertification auditor will expect.

      Internal audits

      ISO 27001 clause 9.2 requires the organisation to run its own internal audit programme, independent of any external certification audit. Schedule audits per framework, record the outcome, and raise findings straight from an audit — each becomes a non-conformity or observation in the Actions register, linked back to the audit, with nonconformities flowing into the corrective-action (Clause 10.2) loop.

      IDFrameworkScopeAuditorPlannedStatus

      Incident register

      ISO 27001 clauses A.5.24–A.5.28 require a planned, documented approach to information security incidents — not just the ones Microsoft Defender can see. Log anything from a phishing click to a laptop left on a train here; a Defender-detected incident can be logged too (set "Discovered via" to Defender alert) so this register is the single record an auditor is shown. Incidents involving personal information are flagged for a privacy-breach assessment, tracked against a 30-day default clock in line with the Privacy Act 1988 Notifiable Data Breaches scheme — check your own jurisdiction's actual deadline; this is a sane default, not legal advice.

      IDTitleCategorySeverityDetectedStatusPrivacy assessment

      Management review

      ISO 27001 Clause 9.3: top management reviews the ISMS at planned intervals and decides whether it is still suitable, adequate and effective. The leadership security meeting does this as part of its normal rhythm: actions, risks, incidents and performance every month, yearly topics when they are due, and the conclusion and sign-off at the meeting set as the management review. The coverage panel shows the auditor every Clause 9.3.2 input over the year. A review held outside the meeting can still be recorded in four steps.

      Management review records

      IDHeldChairConclusionActionsMinutesNext due

      Objectives register

      ISO 27001 clause 6.2 requires information security objectives that are measurable, communicated and monitored — not just restated policy intent. Set a metric and a target for each one, and clause 9.1's requirement to track progress against them is what the status and progress notes below are for.

      ObjectiveOwnerDueStatusProgress notes

      Asset register

      ISO 27001 A.5.9 asks for an inventory of information and other associated assets, each with an owner. Sync from Microsoft 365 brings in Intune devices (with their primary user as owner), your Entra enterprise applications, SharePoint sites and the services in your supplier register, and keeps them current. Add the information itself by hand — the customer database, HR records, source code — because no system can discover what your information is, and a device list alone will not satisfy an auditor.

      IDAssetTypeOwnerClassificationSourceReviewed

      Security questionnaires

      Answer a customer's security questionnaire from what you can actually show. Each question is matched to your Statement of Applicability, your latest posture scan and answers you have already approved. A draft is only written where the evidence says yes. Everything else shows its verdict and the facts behind it, so you can decide what to say.

      New questionnaire

      Excel questionnaires: save the sheet as CSV first. Nothing you paste here leaves your browser unless you choose AI drafting, which goes only to your own Azure OpenAI resource.

      Answer library

      Approved answers are reused the next time a similar question comes in. Each one records what the evidence said when it was approved, so a reused answer is flagged if your posture has changed since.

      IDQuestionApproved answerEvidence at approvalApproved

      Compliance calendar

      Every recurring ISMS activity in one place — access control reviews, BCP/DR and backup restore tests, supplier reviews, awareness training, the external surveillance audit cycle and certificate expiry. Complete an item and, if it recurs, its next due date rolls forward automatically.

      IDActivityCategoryFrequencyOwnerNext dueLast completed

      Audit log

      An append-only, read-only record of who changed what and when — control status changes, evidence links, verifications, risk approvals, action/audit/review/calendar activity and framework toggles. Evidence for ISO 27001 A.8.15 (logging) and SOC 2 CC7.2, distinct from the plain-English Activity feed on the Dashboard.

      WhenActorActionTargetBeforeAfter

      Audit reports

      Generated from the live registers, in Compliance365 brand. What used to be a fortnight of assembly is a button.

      Auditor-facing

      Statement of Applicability

      Full SoA with applicability justifications, implementation status and evidence references. The document your certification auditor opens first.

      Auditor-facing

      Risk register snapshot

      Complete register with heatmap summary, treatment decisions, movement since the last snapshot and Monte Carlo financial analysis.

      Auditor-facing · ISO 27001 6.1.3

      Risk treatment plan

      Every risk mapped to its treatment decision, the controls and actions treating it, its residual score and documented owner acceptance — the artifact an auditor cross-checks against the SoA.

      Audit rehearsal · ISO 27001 Clauses 4-10 and Annex A

      Auditor questions and your answers

      The questions a certification auditor usually asks for each clause and the controls most often sampled, answered from your own records, with what is still missing. Rehearse with the people who will be interviewed.

      Top management · ISO 27001 Clauses 6.3 and 9.3.2 b

      ISMS change log

      What changed in the management system since the last management review: scope, policies, risks, suppliers, people, incidents and audits, in plain words. The "changes" input to the management review.

      Audit rehearsal · ISO 27001 Clause 5

      Top management interview

      The questions a certification auditor asks top management, with their recorded answers beside what the records say, so a contradiction is found before the audit. Record it from Management review.

      Auditor-facing · Clauses 4–10

      Management system evidence pack

      Every clause broken into the requirements an auditor tests, how each is met (Checkpoint's records or a named confirmation) and the evidence behind it, with everything still open listed first.

      Board & management

      Audit readiness report

      Per-framework readiness: control implementation, open critical risks, overdue actions, evidence coverage — and what the auditor will ask about.

      Certified clients

      Pre-audit pack

      Before a surveillance or recertification audit: what changed since the last certification body visit, its findings and where they stand, internal audit coverage this cycle, and everything overdue that the auditor will pick up.

      ISO 27001 · Clause 9.3

      Management review pack

      Quarterly KPI trends, top risks, action throughput and recommendations — satisfies the management review requirement directly.

      Board & C-suite

      Executive summary

      One page: score with trend arrow, implementation %, high/critical risk count, next milestone, top 3 risks. Built for a five-minute board update.

      Self-test

      Pure-logic regression checks — registry integrity, scoring math, residual calculation, entitlement verification, the six report charts, and CSV escaping. Demo-mode-only diagnostics: this is not a substitute for the manual acceptance pass in ACCEPTANCE.md, which is the only thing that ever touches a real tenant.

      ResultGroupCheckDetail

      Trust Center

      A public page for your customers and prospects: the standards you hold or are working towards, your security practices, programme activity, documents they can request, and (if you choose) your sub-processors. Every statement is taken from your own records; nothing is claimed that they do not evidence. Checkpoint generates the page as one self-contained file. Publishing it is your decision: host it on your website or share it from SharePoint.

      Page details

      Company name
      Opening line (optional)
      Security contact email (powers the Request buttons)
      Where customer data is stored (optional)

      What's shown

      Documents

      Readers request "on request" documents by email to your security contact, so you decide who receives them (and under what agreement).

      Sub-processors listed publicly

      Only used when "Sub-processors" is switched on above. Choose which suppliers from the Supplier risk register are named.

      Auditor pack

      Assembles the current Statement of Applicability, an evidence index, a recent audit log excerpt and the latest management review record into one file an external auditor can open via a SharePoint sharing link — no Checkpoint licence needed. Time-boxing and access control are enforced by SharePoint's own sharing-link expiry when you create that link, not by Checkpoint.

      Framework
      Intended validity
      Scope note (optional, shown on the cover page)

      AI tools

      Drafting help and audit rehearsal, all grounded in your own compliance registers. Runs against your own Azure OpenAI resource in your own tenant (see AI-SETUP.md) — nothing is sent to Compliance365 or any third party, and every tool only reads what you choose to include and only ever returns text for you to review. Nothing here writes to any register, and every response carries a visible "AI-assisted draft — review before use" label.

      Azure OpenAI endpoint (your own resource — e.g. https://your-resource.openai.azure.com)
      Deployment name
      Enable the AI tools