All articles
Product

Stop writing your ISMS from a blank page

4 min readVictor Pettersson, IT-säkerhetschef, Sokigo

Every information security management system runs on documents: policies, procedures, statements of applicability, incident plans. And almost every organization starts them the same way: someone opens an empty document, stares at it, and eventually pastes in a template that was written for a different company with different risks.

The result is documentation that reads fine in an audit binder but doesn't describe how your organization actually works. Aquil approaches the problem from the other direction: start from your context, and let the tooling do the typing.

A first draft in minutes, shaped by your answers

When you generate a document in Aquil, you don't get a generic template. The assistant first asks outline questions about your organization and the document's purpose, and you can hand it up to ten of your existing Aquil documents as context so the draft is consistent with what you have already decided.

You also pick a writing assistant that matches the job: a general one, one specialised for ISO 27001 and ISMS language, or one for HR-adjacent documents. The draft that comes back is a starting point you refine in a chat, with every suggested change shown as a diff that you explicitly apply. Nothing lands in your document without you approving it.

Your documents, not the AI's

Generation is deliberately constrained. The assistant does not invent document IDs, revision histories or references to documents that don't exist. Where information is missing it says "to be defined" instead of making something up. That sounds small, but it is the difference between a draft you can trust and a draft you have to proofread line by line.

Bring what you already have

Most organizations don't start from zero; they have years of Word documents. Aquil converts uploaded documents faithfully: headings, tables of contents, tables and inline images are preserved rather than summarised, and nothing is truncated. If a file can't be converted honestly, Aquil asks whether to keep it as a download-only original instead of silently saving a broken copy.

Ownership and approval are part of the document

A document nobody owns is a document nobody maintains. Every Aquil document can have an accountable owner, and changing that owner goes through an approval flow, so responsibility is always explicit, visible in exports, and never lost in a reorganisation. Combined with review workflows and notifications, documentation stops being a yearly panic and becomes routine.

See what Aquil can do for your team