Skip to content

For consultants, MSPs and vCISOs

Every client's ISO documentation, from one account

Open every client from one portfolio. Each has its own profile, scope, documents and branding, while generation draws from one shared credit pool, so you spend the engagement on judgment, not rewriting.

PolicyMint's Clients page showing several fictional organisations, document progress, the active client, and controls to add or open a client.
Actual PolicyMint product Fictional demo data

The problem

You rebuild the same set for every client

Every engagement starts the same way: copy the last client's folder, find-and-replace the company name, and hope nothing of the old client survives. Then weeks of adapting policies to a business they were never written for, reconciling documents that have drifted apart across engagements, and reformatting everything into the new client's template.

The writing is the least valuable part of your engagement, and it is the part that eats the margin. It is also where the risk lives: one stale reference to the wrong company in a delivered document is a bad email to receive.

The workflow

From new client to delivered set

  1. 1

    Add a client

    Each client is its own workspace with its own company profile, scope and brand. Give it their name, website, logo and colors in one sitting.

  2. 2

    Generate their set

    PolicyMint selects the documents that client actually needs, drafts each one from their profile, checks every section with three independent verifiers, and flags anything only the client can answer.

  3. 3

    Deliver in their branding

    Word, PDF and spreadsheet exports carry the client's logo and colors, with clause mappings and their Statement of Applicability assembled. Switch to the next client in a click.

The catalog

What you can deliver

ISO 27001

The full document set: the core plus the topic policies that fit each client's scope.

See the set →

ISO 42001

The AI management set, for clients building or shipping AI systems.

See the standard →

General cyber

Everyday security policies for clients who want the documents without pursuing certification.

Every document cites the clauses it satisfies, and each client's Statement of Applicability is assembled from what their documents actually cover.

ISO 27001 documents

36

ISO 27001 documents

tiered by what each client actually needs

ISO 42001 documents

21

ISO 42001 documents

for AI management systems

Clauses and controls mapped

182

Clauses and controls mapped

every document cites the ones it satisfies

Verifiers per section

3

Verifiers per section

on a different model to the writer

The economics

One pool, no per-client seats

A$1,360US$889£689€819

inc GST · 4,000 credits · one shared pool

One pool funds every client workspace you manage: each set written, triple-verified and delivered in that client's branding. No per-client license, no per-client platform seat, no procurement conversation per engagement.

Compare that with a GRC platform seat per client, publicly reported at about A$14,000+ (US$10,000+)US$10,000+about £7,400+ (US$10,000+)about €8,700+ (US$10,000+) a year per company, where the documents are a side feature. If a client needs continuous monitoring, use a platform for that; PolicyMint is the documentation layer, and the two work together.

Full consultant pricing →

Complete client sets per pack

~4

complete client sets, with credits left over

Credits per full set

~900

credits per full client set

Per-client seats

A$0US$0£0€0

per-client seats or licenses

Who runs it

Three ways the same workspace earns

The independent consultant

You sell judgment, not typing. Generate the client's baseline set in an afternoon, then spend the engagement on scoping, risk and audit readiness, where your rate is actually earned.

The MSP

Security documentation becomes a productized service. Onboard a client, stand up their set the same day, and keep every client's documents separate, current and in their own brand.

The vCISO

Run several ISMSs without several tools. The switcher keeps each client's scope, profile and documents cleanly apart, and the pool means no per-client procurement conversation.

Be clear

The documentation, not the certificate

Your clients are certified by an accredited certification body, and your judgment is what gets them through it. If your practice also needs the training or exam pathway, the Mindset Cyber family runs PECB-accredited ISO courses, and MindsetPrep covers exam preparation. For tracking each client's control implementation, our sister tool ControlStack maps the same controls in an interactive tracker.

PolicyMint produces the documentation your clients are audited against, not the certificate itself.

Consultant FAQ

Running client documentation, answered

The questions consultants ask before they put a client on it.

Is the output white-label?

Every document carries the client's logo, colours and name, not ours and not yours. It reads as that client's documentation because it is: drafted from their profile, mapped to the clauses that apply to them, and exported in their branding.

How is client data kept separate?

Each client is its own workspace with its own profile, documents and branding. Nothing carries across automatically: what you learn about one client stays theirs. Within a client's workspace, the answers you give are remembered, so later documents for that client never ask the same question twice.

How does the credit pool work across clients?

One prepaid Consultant pool funds every client workspace you manage. Generating for any client draws from the same pool, so there is no per-client license, seat or minimum. You buy capacity once and point it wherever the work is.

How is this different from a GRC platform seat per client?

A platform charges an annual, per-company subscription and does continuous monitoring; documents are a side feature. PolicyMint is the documentation layer: it writes, checks and brands each client's set, priced per document rather than per client per year. Many consultants use both, with PolicyMint producing the documents the platform then tracks.

Which standards can I deliver with it?

ISO/IEC 27001:2022 and ISO/IEC 42001:2023 document sets, including the Statement of Applicability, plus a set of general cyber security policies for clients who want the documents without pursuing certification.

Does this replace my role in the engagement?

No. It replaces the typing. Scoping, risk judgment, implementation guidance and audit preparation remain yours; PolicyMint gets a complete, consistent, verified document set onto the table on day one instead of week six.

PolicyMint / Next issue Ready when you are

Stop rebuilding the same document set

Add a client once. Get their full set, written for their business, in their branding, checked before you hand it over.

Your first document is on us. We ask for a card to begin and you are not charged for it, and there is no sales call. See pricing