
ISO 27001 is the international standard for information security management. Most companies pursue it because a client, an enterprise buyer, or a procurement team now requires it before signing.
Our SharePoint consultants regularly build sites, Power Apps, and Power Automate solutions for companies that need their documents and processes under control. We have delivered SharePoint platforms, migrations, and automated workflows for clients in energy consulting, optical retail, manufacturing, and regulated child care. Our work has been used to link operational evidence directly to regulators.
This article explains what ISO 27001 asks of your documents and systems, where SharePoint setups usually fall short, and how we close those gaps. It is written for teams already paying for Microsoft 365 who want to know if they can use what they have.
SharePoint ISO 27001 compliance means configuring SharePoint Online so it can serve as your Information Security Management System, or ISMS, and satisfy an external auditor.
An ISMS is the set of policies, procedures, records, and controls that prove you manage information security on purpose rather than by accident. ISO 27001 does not require you to buy specific software. It requires you to control your documented information and to produce evidence on demand.
This is one of the most common SharePoint use cases. Versioning, approvals, permissions, metadata, and audit logs are already part of Microsoft 365. Power Apps and Power Automate extend that into structured processes such as incident reporting, access reviews, and document review cycles. The gap is almost never the tooling. It is the configuration and the evidence.
ISO 27001:2022 sets out the requirements in numbered clauses, plus a bunch of Annex A controls. A few of these land right on your document management setup.
7.5 — Documented information. Your docs need to be available where they’re needed, safe from loss or misuse, version-controlled, access-controlled, and either retained or disposed of on a schedule. That’s the bit SharePoint does best.
7.2 and 7.3 — Competence and awareness. Staff need to be aware of the security policies that apply to them. And, of course, you need to be able to prove it – an email thread isn’t going to cut it. You usually need some proof that people opened documents, completed training, etc.
9.2 and 9.3 — Internal audit and management review. You need records of internal audits and of management reviewing the ISMS. These are documents an auditor will be sampling.
10.2 — Nonconformity and corrective action. When something goes wrong, you need to record it, what you did to fix it, and whether it actually worked.
The Annex A controls that affect SharePoint most often are classifying and labelling information (A.5.12 and A.5.13), access control and access rights (A.5.15 and A.5.18), protecting records (A.5.33), written operating procedures (A.5.37), stopping data leakage (A.8.12), and logging (A.8.15).
And the docs that get sampled the most during an audit? That’s your policies and procedures, risk register, risk treatment plan, Statement of Applicability, internal audit records, management review minutes, training evidence, and incident and corrective action logs – yep, that’s a big list!
We do a lot of Microsoft 365 tenant audits, and the same problems keep coming up – and none of them need new software to fix!
Files live in OneDrive instead of SharePoint. Personal OneDrive means the company’s not in control of the file. When someone leaves, the document goes with them – no shared history, no reliable access control.
No version enforcement. An auditor asks to see the access control policy that applied back in March. Most teams can’t produce it, because versioning is off, misconfigured, or nobody knows where to look.
Documents are launched without formal approval. Drafts and approved policies are just jumbled up in the same folder. Anyone can open the wrong one, and it’ll get treated as official.
Policies exist, but there’s no proof anyone actually read them. This totally fails the awareness requirement. “We sent it round” just isn’t evidence.
No named owner, reviewer, or review date on a SOP. SOPs go stale. An auditor sees a procedure last looked at three years ago, and starts asking some harder questions.
Permissions are way too open. Everyone’s an editor. Sharing links have no expiry. This totally undermines the access control requirements.
Key processes are totally undocumented. Work gets done over email and spreadsheets. There’s no record of who did what, when, or whether it got approved.
A dedicated SharePoint site gives your ISMS a single location with defined libraries for policies, risks, audits, training, and incidents. Metadata columns for the ISO clause, document owner, classification, and review date let an auditor filter to what they need. They stop navigating folders and start finding evidence.
Our SharePoint developers built a SharePoint platform for Vedeni Energy LLC, an energy consulting and wholesale power business, to share client information securely. The Managing Director confirmed the platform was fully functional against all requirements and delivered in phases, on time. You can read the review on Clutch.
Once documents carry owners, approval history, and timestamps, evidence stops being something you assemble the week before an audit. It becomes a filtered view you open in front of the auditor. Version history answers the “show me the old one” question in seconds.
Fledglings Child Care Ltd, a residential child care provider, decided to outsource SharePoint development to us so we built a SharePoint site, Power Apps and Power BI reports to monitor children’s progress and link that evidence to regulators. The Director rated Vidi Corp 10 out of 10 for recommendation in their G2 review.
Moving documents out of OneDrive and personal drives removes the copy-paste, the re-sending, and the “which file is current” conversations. SharePoint automation removes the manual compilation that eats hours every month.
For Hakim Group, an optical portfolio group, our SharePoint migration consultants handled the migration alongside RPA workflows. Their Head of Growth reported around 10 working hours saved per month through automated reporting, improved data accuracy, and less manual intervention. The full review is on Clutch.
Power Apps turns an undocumented process into a form with required fields, and Power Automate records every approval and timestamp against it. Steps stop being skipped because the app will not let them be skipped. That record is exactly what an auditor wants to see. You can view our Power Apps examples that standardize common workflows if you are interested.
Lightwave Group, a composite manufacturer and boat builder, asked us to bring quality check data into SharePoint through Power Automate and Power Apps, with Power BI on top. The result was an increase in quality and a decrease in missing inspection points and documentation, as their executive describes on Clutch.
Review dates, approval requests, and escalations can all run on a schedule instead of on someone’s memory. Power Automate flows send the reminder, routes the approval, and logs the outcome. Nothing depends on a person remembering that a policy is due.
We built Power Automate workflows and ERP data extraction for NELO, a trading company. Their General Manager reported a simplified order process, simplified internal processes, and better data for controlling. Their review is on Clutch.
We review how your documents are stored, who can access them, whether versioning is enabled, and what evidence you could produce today. The output is a gap report mapped to the ISO 27001 clauses and Annex A controls each gap affects.
You get a clear picture of what already passes and what does not. Some companies are closer than they expect. Others find that most of their ISMS lives in personal drives.
We move your documents out of individual OneDrive accounts into structured SharePoint libraries for document management. Ownership transfers to the company rather than the employee.
The migration is planned so people keep working during it. We map the existing structure first, agree the target library and metadata design with you, then move content in stages.
Most of what ISO 27001 wants from version control is already available in SharePoint – you just need to get the right settings in place. We sort out major and minor versioning, so that drafts and published versions are easy to tell apart, and set retention limits that match your policy.
We then show your team where all the version history lives – and how to restore or compare a previous version. This five-minute walkthrough is what turns a configured feature into something that actually makes a difference in an audit.
We set up Power Automate document approval workflows on your key documents in SharePoint. A policy stays invisible to the wider team until the named approver signs it off. Once approved, it publishes and everyone sees the current version.
Power Automate records the approver, the date, and any comments against the document. That approval trail is the evidence an auditor asks for when they question whether a policy was formally authorized.
We also set up how policy updates reach your team, so a new version is announced rather than quietly replacing the old one.
Each team gets its own area in SharePoint for holding their procedures – the ones they actually use. Sales people don’t have to wade through engineering SOPs to find what they need.
For every document we define a review period and who is in charge of reviewing it – that’s the person responsible & the player who gives the ok. Power Automate then chases up the reviewer when the date arrives & kicks it up the chain of command if it passes its deadline. No more scrambling to find out about stale procedures at audit time.
We set up a read-and-acknowledge tracker, normally as a Power App that writes to a SharePoint list. Employees confirm they have read a document & we get a timestamp against their name.
Now you have a list showing who has actually read which policy and who’s playing catch up. It gives you a record rather than just taking someone’s word for it, which is what we need to answer the awareness requirements in Clauses 7.2 and 7.3.
Every company has processes that don’t fit the mold. Incident reporting, access reviews, supplier checks, change approvals, and quality inspections come up a lot.
We sit down with you & define how each process should work, then our Power Apps consultants build it as a Power App that writes into SharePoint. This makes sure the required fields are always filled in & we don’t get incomplete submissions. Power Automate handles the ins and outs like sending notifications & keeping track of who approved what.
And the result is a process that kicks in the same way every time, with a complete record to show for it. If it makes sense, we hook up that SharePoint data to Power BI so your managers can keep an eye on open risks, overdue actions, and training completions without having to ask anyone for an update.
We do the bulk of the prep work so your team can keep on doing what they do. This includes tidying up the evidence so a Stage 1 and Stage 2 audit can be run through without having to dig through files.
Remember, certification comes from an accredited certification body, not from us. What we do is get you ready for their audit, then sort out any feedback from them to make sure we don’t have any outstanding issues. If the auditor spots a gap, we sort it out.
A Nice, Tidy ISMS Site with Metadata
Libraries for policies, risks, internal audits, management review, training, & incidents – each tagged with the relevant ISO clause or Annex A control. Auditors can filter down to a specific control and find all the relevant documents attached.
Don’t Publish Until it’s Been Approved
Documents can’t get to the wider team until the person in charge has signed off on them. We keep a permanent record of who gave the ok.
Scheduled Reviews Just Happen
Every controlled document has a review date, a reviewer, and an approver. Power Automate handles the reminders & escalations so reviews just get done on schedule.
Tracking Who’s Read What
A Power App & SharePoint list combination that shows who has read which document, with a timestamp to boot. Reporting on this is just a matter of filtering the data, not asking around like we used to do.
Custom Process Apps with a Full Audit Trail
Power Apps forms for the processes that are unique to your business, writing into SharePoint with Power Automate handling the ins and outs like approvals & routing. Every submission is recorded with who did it, what was submitted, when it was done, and who gave the ok.
If ISO 27001 is blocking a deal or a procurement process, the first step is knowing how far your current setup already takes you. We start with an audit of your SharePoint and Microsoft 365 environment and a gap report mapped to the standard.
Book a SharePoint ISO 27001 readiness audit to find out what you already have and what needs building.
Yes. SharePoint Online supports version control, approval workflows, access control, classification, and audit logging, which covers the documented information requirements in Clause 7.5. It needs correct configuration and a defined process around it to satisfy an auditor.
For most small and mid-sized companies, Microsoft 365 is enough. You are already paying for SharePoint, Power Apps, and Power Automate. Dedicated compliance platforms add value at larger scale or across multiple frameworks, but they are not a requirement of the standard.
It can, once it is configured correctly. Versioning needs to be enabled with appropriate major and minor settings, retention limits set, and your team needs to know how to retrieve previous versions. Default settings alone are usually not enough.
It depends on how much content needs migrating and how many processes need building. The audit and gap report come first, and that gives you a realistic timeline before any build work starts.
Yes. We map the existing structure, agree the target design with you, and migrate in stages so people keep working throughout.
Largely, yes. Document control, access control, approval trails, and awareness records are common to most frameworks. Work done for ISO 27001 usually carries over.