Skip to main content
Image coming soon

CMP1797 Assessing and Evidencing ISO 37301 Compliance Systems

$199.00
Adding to cart… The item has been added

The Executive Diagnostic and Governance Toolkit

Assessing and Evidencing ISO 37301 Compliance Systems

Score your own function red, amber or green, find out which part is weakest, and walk into the next budget round able to defend what you want to fix. Built for leaders reviewing they already hold the ISO 37301 compliance management systems playbook: the implementation guide, the roadmap and the working files, so repeating any of that is worthless. What is missing is the layer after implementation. How to assess the function honestly, what evidence to retain, how to score maturity, and how to put the result in front of a manager, an auditor or a client who was not involved. The immediate question: for one month of ISO 37301 compliance management systems work, can you show what was measured, against what target, and what changed as a result.

$199 one-time
30-day money-back guarantee Verified against latest insights, updated access provided within 24h

Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

What you walk out with
A scored, ranked picture of your own function, and a defensible answer to what to fix first.
1 You stop guessing where you stand.
You finish with a score, not an opinion: every part of your function rated red, amber or green, with the weakest ranked first. Evidence: a Quick Scan for the shape of it, then seven domain assessments of 30 scored questions each, 210 in all, rolled into one scorecard, plus a maturity radar and a current-versus-target gap analysis.
2 You can defend the decision.
You walk into the budget round with the gap named, the owner named and done defined, instead of a case built on instinct. Evidence: project charter, scope statement, RACI, requirements traceability and work breakdown structure, pre-filled in your domain's language.
3 The work actually moves.
The month after the decision is already built, so nothing stalls waiting for someone to design a form. Evidence: more than 60 project templates across all five PMBOK process groups, plus runbooks, SOPs, a KPI framework, audit checklists and a risk matrix. 55 to 65 files in total.
4 You use it the day it lands.
No blank templates to interpret. Every workbook opens with what it is, who uses it, when, how, a 1 to 5 scoring guide, what good looks like, and a worked example you delete and type over.
The Quick Scan is one sitting. You will know your weakest area before the day is out.
Nothing in it is generic project management: the build rejects any file that could belong to another course. Updated after you enrol, so it reflects where the work stands now. The 144-chapter course is included behind it, for the parts you want to go deeper on.
You’ve built the system. Now prove it works.

The situation this is built for

You hold the implementation playbook, roadmap, and working files. But when leadership or an auditor asks, 'What changed? How do you know?'—you’re left scrambling for proof. The tools exist to implement ISO 37301, but not to assess it. You need to show measurable outcomes, not just policies. Without a structured way to evaluate maturity and retain evidence, your efforts remain invisible or unverifiable. This gap undermines credibility and exposes your organization to risk.

Who this is for

The compliance practitioner who owns the ISO 37301 compliance management system and has completed implementation but now must assess its effectiveness, retain evidence, and report outcomes to auditors, leadership, or clients.

Who this is not for

This is not for consultants selling implementation services, software vendors, or teams still building their initial compliance framework. If you haven’t operationalized ISO 37301, this course will not help you.

What you walk away with

  • Demonstrate measurable improvement in compliance function maturity
  • Retain defensible, auditable evidence of system performance
  • Score and track compliance effectiveness over time
  • Report outcomes clearly to executives and auditors
  • Align compliance evidence with organizational risk appetite

How this maps to your situation

  • You’ve implemented ISO 37301 and have the playbook ready.
  • You’re asked to prove the system works but lack evidence.
  • Auditors or leadership challenge compliance effectiveness.
  • You need to show measurable outcomes from compliance work.

Before vs. after

Before
You have implemented ISO 37301 but struggle to prove its effectiveness, leaving compliance efforts vulnerable to scrutiny and unable to demonstrate value.
After
You can systematically assess compliance maturity, retain auditable evidence, and report measurable outcomes to leadership and external parties with confidence.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 12 hours of focused work across 12 weeks, with one module completed per week.

If nothing changes
Without a structured approach to assessment and evidence, your compliance function remains unproven. Auditors may issue findings, leadership may underfund compliance, and regulators may question your program’s effectiveness—exposing the organization to legal, financial, and reputational harm.

How this compares to the alternatives

Other resources focus on implementing ISO 37301. This course fills the gap after implementation: assessing performance, gathering evidence, and proving value. No templates or tools alone can replace structured methodology—this course provides the decision logic, meeting structures, and reporting standards you need.

Also included: the full course, for when you want the reasoning behind a finding (12 modules, 144 chapters)

Depth reference. The diagnostic and the templates stand on their own; this is what to read when you want the reasoning behind a finding.

Module 1. Establishing the Purpose of Compliance Assessment
Define why assessment matters beyond certification and align it with organizational objectives.
12 chapters in this module
  1. Understanding the difference between implementation and assessment
  2. Identifying stakeholders who require compliance evidence
  3. Defining the scope of compliance function evaluation
  4. Setting clear objectives for internal and external review
  5. Mapping compliance outcomes to business performance
  6. Determining acceptable levels of compliance risk
  7. Creating a compliance assessment charter document
  8. Establishing ownership of assessment activities
  9. Aligning assessment goals with organizational strategy
  10. Documenting assumptions in compliance performance claims
  11. Integrating legal and regulatory reporting requirements
  12. Initiating the first compliance assessment meeting
Module 2. Designing the Compliance Measurement Framework
Build a repeatable structure to measure compliance system performance using defined metrics.
12 chapters in this module
  1. Selecting key performance indicators for compliance activities
  2. Choosing key risk indicators relevant to control effectiveness
  3. Developing a balanced scorecard for compliance function
  4. Setting thresholds for acceptable compliance performance
  5. Creating measurable definitions for compliance maturity
  6. Linking metrics to ISO 37301 control clauses
  7. Designing data collection methods for compliance metrics
  8. Assigning responsibility for metric ownership
  9. Validating metric relevance with control owners
  10. Building a compliance dashboard structure
  11. Testing measurement definitions with sample data
  12. Documenting the compliance measurement framework
Module 3. Defining Evidence Requirements for Compliance
Specify what constitutes valid, auditable proof of compliance system operation.
12 chapters in this module
  1. Classifying types of compliance evidence by reliability
  2. Mapping evidence to specific ISO 37301 requirements
  3. Establishing retention periods for compliance records
  4. Creating evidence collection protocols for audits
  5. Designing templates for standardized evidence capture
  6. Defining roles in evidence gathering and review
  7. Integrating evidence requirements into workflows
  8. Verifying authenticity of compliance documentation
  9. Using timestamps and digital signatures in evidence
  10. Avoiding over-collection of unnecessary compliance data
  11. Aligning evidence standards with auditor expectations
  12. Maintaining an evidence traceability matrix
Module 4. Scoring Compliance Maturity Objectively
Apply a structured model to evaluate the evolution and robustness of the compliance function.
12 chapters in this module
  1. Understanding maturity model structures for compliance
  2. Defining level one through five compliance maturity
  3. Creating behavior-based criteria for each maturity level
  4. Scoring policy design versus actual implementation
  5. Evaluating consistency of compliance across departments
  6. Measuring integration of compliance into decision making
  7. Assessing leadership engagement with compliance goals
  8. Benchmarking maturity against industry standards
  9. Conducting blind assessments to reduce bias
  10. Documenting maturity scoring decisions transparently
  11. Tracking maturity changes over time
  12. Presenting maturity results to executive leadership
Module 5. Conducting Internal Compliance Reviews
Run structured evaluations to test compliance system performance and identify gaps.
12 chapters in this module
  1. Planning the annual internal compliance review cycle
  2. Selecting review topics based on risk priority
  3. Developing internal review checklists from ISO 37301
  4. Scheduling interviews with control owners
  5. Observing compliance processes in operation
  6. Sampling records for evidence of control execution
  7. Identifying control failures and root causes
  8. Documenting findings in standardized format
  9. Prioritizing issues by impact and likelihood
  10. Assigning action owners for remediation
  11. Tracking issue closure with deadlines
  12. Reporting internal review outcomes to governance
Module 6. Generating Compliance Performance Reports
Translate assessment data into clear, actionable reports for different audiences.
12 chapters in this module
  1. Structuring board-level compliance performance summaries
  2. Creating detailed reports for internal audit teams
  3. Tailoring evidence packages for external auditors
  4. Summarizing compliance trends over time
  5. Visualizing maturity progression with graphs
  6. Including risk heat maps in compliance reporting
  7. Writing executive summaries of compliance status
  8. Embedding evidence references in report footnotes
  9. Using consistent terminology across reports
  10. Validating report accuracy with data owners
  11. Archiving reports for future retrieval
  12. Establishing a compliance reporting calendar
Module 7. Preparing for External Compliance Audits
Organize evidence and responses to meet auditor expectations and reduce findings.
12 chapters in this module
  1. Understanding auditor expectations for ISO 37301
  2. Mapping audit criteria to existing evidence
  3. Creating an audit readiness checklist
  4. Conducting pre-audit mock interviews
  5. Organizing evidence files by clause and theme
  6. Preparing compliance narratives for auditors
  7. Assigning roles during audit engagement
  8. Documenting responses to prior audit findings
  9. Conducting internal gap analysis before audit
  10. Running a final evidence completeness check
  11. Briefing leadership on audit scope and timing
  12. Debriefing after audit to capture lessons
Module 8. Demonstrating Compliance Impact Over Time
Show measurable change in compliance performance across reporting periods.
12 chapters in this module
  1. Establishing baseline measurements for compliance function
  2. Tracking reduction in policy violations over time
  3. Measuring improvement in control test results
  4. Quantifying increase in employee compliance training completion
  5. Monitoring whistleblower report resolution times
  6. Evaluating reduction in audit findings
  7. Assessing speed of compliance incident response
  8. Calculating cost avoidance from compliance interventions
  9. Comparing maturity scores across quarters
  10. Linking compliance data to operational risk events
  11. Showing correlation between training and behavior
  12. Reporting compliance ROI to finance stakeholders
Module 9. Engaging Leadership in Compliance Evaluation
Involve executives in reviewing compliance performance and setting expectations.
12 chapters in this module
  1. Scheduling regular compliance governance meetings
  2. Preparing leadership review dashboards
  3. Presenting compliance maturity to the board
  4. Obtaining executive sign-off on assessment results
  5. Incorporating leadership feedback into improvement plans
  6. Communicating compliance risks to senior management
  7. Documenting leadership decisions on risk tolerance
  8. Tracking follow-up actions from governance meetings
  9. Measuring leadership engagement with compliance goals
  10. Reporting on tone at the top indicators
  11. Aligning compliance objectives with strategic priorities
  12. Creating leadership accountability scorecards
Module 10. Managing Compliance Evidence Lifecycle
Ensure compliance evidence is retained, accessible, and secure over time.
12 chapters in this module
  1. Classifying evidence by sensitivity and retention need
  2. Designing secure storage locations for compliance files
  3. Implementing access controls for evidence repositories
  4. Creating backup procedures for digital evidence
  5. Defining evidence destruction protocols
  6. Conducting periodic evidence integrity checks
  7. Auditing access logs for compliance documentation
  8. Training staff on evidence handling procedures
  9. Integrating evidence management into onboarding
  10. Responding to data subject access requests
  11. Ensuring cross-border data transfer compliance
  12. Updating evidence lifecycle policies annually
Module 11. Improving Compliance Through Feedback Loops
Use assessment results to drive continuous improvement in the compliance function.
12 chapters in this module
  1. Analyzing root causes of compliance failures
  2. Integrating audit findings into action plans
  3. Prioritizing improvements based on risk impact
  4. Tracking effectiveness of corrective actions
  5. Conducting post-implementation compliance reviews
  6. Soliciting feedback from control owners
  7. Benchmarking against peer organizations
  8. Updating compliance policies based on findings
  9. Adjusting maturity targets based on performance
  10. Revising metrics that no longer reflect risk
  11. Incorporating lessons from regulatory updates
  12. Closing the loop with stakeholders on improvements
Module 12. Sustaining Compliance Through Organizational Change
Maintain compliance function integrity during restructuring, M&A, or leadership shifts.
12 chapters in this module
  1. Assessing compliance impact of organizational changes
  2. Conducting compliance due diligence in M&A
  3. Updating compliance frameworks after restructuring
  4. Onboarding new leadership to compliance expectations
  5. Transferring compliance responsibilities securely
  6. Maintaining evidence continuity during transitions
  7. Re-scoring maturity after major changes
  8. Communicating compliance expectations to new teams
  9. Updating compliance training for new roles
  10. Reviewing third-party compliance during integration
  11. Preserving institutional compliance knowledge
  12. Documenting change-related compliance decisions

Frequently asked

Who is this course for?
This course is for practitioners who have already implemented ISO 37301 and now need to assess, evidence, and report on the effectiveness of their compliance management system.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does this course cover implementation of ISO 37301?
No. This course assumes you already have the implementation assets and focuses exclusively on assessment, evidence, and reporting.
Will I receive templates and tools?
Yes. Each chapter includes downloadable templates and worked examples, plus a hand-built implementation playbook delivered alongside course access.
Can I use this for auditor preparation?
Yes. The course includes modules on audit readiness, evidence organization, and response planning tailored to ISO 37301 assessments.
What formats do the templates come in?
The implementation playbook downloads as PDF and editable XLSX. The course reads in your learning environment and exports to PDF for offline use. The files are yours to keep.
Can I share this with my team?
The licence is per person. Team pricing opens from three seats: reply to the order confirmation with TEAM and we will set it up.
How quickly can I start?
The diagnostic is one sitting and the templates work straight out of the kit. Account access takes up to 24 hours rather than being instant, because every order is checked and updated against the latest sources before it is delivered.
$199 one-time. Approximately 12 hours of focused work across 12 weeks, with one module completed per week..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee·Know your weakest area today·210 scored questions·Course included· Account access within 24 hours
30-day money-back guarantee, no questions asked.
Thousands of organisations have bought from The Art of Service since 2000.