An AI system that generates audit-ready ISO 27001, ISO 42001, and SOC 1/2 policy documents for small and mid-sized businesses, in minutes instead of months


A note on disclosure

I cannot name the company or share any client or product metrics from this engagement, under the terms of the internship placement. What follows describes the product, the problem it solved, and the decisions behind it, without company-specific numbers. The traditional compliance benchmark referenced below, a 30 day to 6 month process costing between $500 to $10,000, describes the compliance consulting industry generally, not this company's own results.

Problem

Getting certified against a standard like ISO 27001, ISO 42001, or SOC 1/2 ultimately comes down to producing a specific artifact: a policy document that maps the business's actual practices onto the standard's required controls, in language an auditor recognizes. For a small or mid-sized business, producing that document typically means hiring a consultant or compliance firm, and that engagement commonly runs anywhere from 30 days to 6 months and costs between $500 to $10,000, largely to produce a document the business could not write correctly on its own. For a company trying to win an enterprise deal or satisfy an investor, that timeline and cost is often the actual blocker, not the underlying security or governance work itself.

The product's entire value proposition was collapsing that document, and only that document, from a months-long consulting deliverable into something a business could generate itself.

Discovery

I came onto this as a developer on an existing product vision, not as the person who defined the problem. What I can speak to directly is what I built: a system that maps control requirements across four frameworks, ISO 27001, ISO 42001, SOC 1, and SOC 2, into structured formats, so that a company's own information could be run through a template and turned directly into the finished policy document, the actual artifact an auditor reviews, without a consultant manually drafting it each time.

Decision

Ground the document itself in a fixed, standard template, rather than letting the model draft it freely. This was the vision from day one, not a correction we made after trying something looser. The generated policy document is the entire product; if its language doesn't map to what a framework and an auditor expect, the product has failed at the one thing it exists to do. Letting a language model draft that document unconstrained risked confident, plausible-sounding policy language that did not actually satisfy the standard. Structuring the template first, per framework, and having the model populate it with the client's specific information kept the document itself anchored to language the framework recognizes, rather than anchored to whatever the model found plausible.

Put the accuracy burden on the user, deliberately. The system does not verify whether the information a company enters about itself is true before it flows into the generated document. That is a real trade-off: it kept the product buildable in the scope we had, but it also means the final document, the artifact meant to stand up to an audit, is only as accurate as what the user typed in. I want to name this honestly rather than gloss over it, because it directly shaped what I would change.

Multi-tenant architecture with strict data isolation. I built the backend on Supabase, using row-level security so that each client's data, documents, and generated policies stayed fully isolated from every other client on the same platform. For a product handling sensitive compliance and security information across 50-plus SMB clients, isolation at the data layer was not optional.

Design the UI around the user's expertise level, not the framework's complexity. I owned the UI/UX for the platform. ISO and SOC documentation is dense and technical by nature. The interface had to turn that complexity into a guided, step-by-step flow a non-technical small business owner could complete without a consultant walking them through it. That was as much a product decision as a design one: the entire value proposition collapses if the tool still requires expertise to operate.

Outcome

The MVP reached client pilots with more than 50 small business clients across the four frameworks, and I cannot share performance data beyond that. What I can say is the shape of the value proposition it was built to deliver: a finished, audit-ready policy document generated in minutes, against a process that traditionally takes months and tens of thousands of dollars to produce, for companies that would otherwise not have a realistic path to certification at all.

Reflection

I would have proposed a review or flagging step for user input. At the time, I was a developer on the team, but I already had product instincts, and the gap I would have raised is this: the accuracy of every generated document depends entirely on what the user typed in, with nothing in the product checking it. A lightweight review layer, even something as simple as flagging fields that looked incomplete or inconsistent before generating the final document, would have caught errors before they became compliance paperwork a client might submit to an actual auditor. I did not have the standing to drive that change at the time, but it is the first thing I would raise if I were back on that team today.