ISO Certification. Your Step by Step Checklist

Everything you need is on this page · Tick each box when done · After each step, update Clicarity with Job ID: ISO-001

Your progress0 of 0 done

How to use this checklist

Orange box = ask Puneet
Blue box = find it in Puneet's doc
Teal box = do this in Clicarity
Tick box = step done ✓
1
Set Up Your Google Drive Folder
Do this first · Takes about 30 minutes · You can do this alone
Open Google Drive on your computer
Go to drive.google.com and log in with your Clicarity Google account.
BOTH
Create a new folder called exactly: Clicarity ISO
Click the big + New button on the left → click Folder → type the name → click Create.
BOTH
Share this folder with Puneet so he can also see it
Right-click the folder → Share → type Puneet's email → make sure he has Editor access → click Send.
BOTH
Create these 9 sub-folders inside Clicarity ISO
Open the Clicarity ISO folder. Create one folder for each name below. Copy the names exactly.
1-Scope
2-Policies
3-Risks
4-Assets
5-Objectives
6-Procedures
7-Audit
8-Review
9-CB-Readiness
BOTH
Save Puneet's big Word document (the Toolkit) inside the Clicarity ISO folder
The file is called Clicarity_ISO_Toolkit_v1.docx. Keep it there. You will only open it when this checklist says so, and this checklist will tell you exactly which page to go to.
BOTH
📊 Update in Clicarity now
Job ID:ISO-001
Status:ISO_Setup_Scope → Done
Form:No form fields at this stage
Upload:Nothing to upload yet
done with step 1, move to step 2
2
Fill In the Company Details
Folder: 1-Scope · Takes about 1–2 hours · Ask Puneet for the answers
Open the Toolkit · Go to Section 1, page 4
You will see a table called "1.1 Organisation Profile". It has two columns: the left column has field names, the right column has text in [square brackets]. Those are the placeholders you need to fill in.
📄 What it looks like in Puneet's doc

It is a blue and white table. The first row has a dark blue header. Look for the words "Legal name", "Number of employees", "Udyam registration". Fill in only the rows that have [PLACEHOLDER] written in them.

BOTH
💬 Ask Puneet, write his answers here before filling in the doc
Number of employees:
Udyam number:
Date founded:
Read the two Scope Statements in the same Section 1 · Check they sound right for Clicarity
Scroll down a little from the profile table. You will see a section called "1.2 Scope of Certification". It has two sentences, one green row, one purple row. Read both out loud slowly.
📄 The two sentences are exactly these, read them now
"Design, development, deployment, and customer support of a cloud-based job tracking and operations dashboard platform (Clicarity) for small and medium-sized enterprises, delivered via web and mobile interface, from offices at Lower Parel West, Mumbai."
This sounds correct for Clicarity
"Information security management for the design, development, hosting, and delivery of Clicarity: a SaaS operations platform, including customer data processing, cloud infrastructure (AWS), third-party integrations (WhatsApp, Google Sheets), and internal IT systems at Lower Parel West, Mumbai."
This sounds correct for Clicarity
BOTH
💬 Ask Puneet if anything sounds wrong

I read both scope sentences. Can you check if these are correct? I have marked: ________________________

Save the Toolkit document · Put a copy in folder 1-Scope
After filling in the placeholders, save the file. Then drag a copy into the 1-Scope folder on Google Drive. Name it: Clicarity-Scope-v1.docx
BOTH
📊 Update in Clicarity now
Job ID:ISO-001
Status:ISO_Quality_Policy_Shared → Done
Form fields:Document number: QP-001 · Date signed · Signed by: Puneet · How shared: WhatsApp Group · Date shared
Upload:Quality-Policy-Signed.pdf + Policy-Shared-Proof.jpg
done with step 2, move to step 3
3
Get the Two Policies Printed and Signed
Folder: 2-Policies · Takes 1 day · Puneet must sign both · You do the printing and scanning
Open the Toolkit · Go to Section 2.1, approximately page 8
You will see a large green box with the heading "CLICARITY. QUALITY POLICY" written in green letters at the top. The whole box is the Quality Policy document.
📄 What it looks like, the Quality Policy

It is a big box with a green left border and a light green background. It starts with "CLICARITY. QUALITY POLICY" in large green text. It has the document number QP-001 at the top. It ends with a signature line at the bottom.

9001
Copy the Quality Policy text onto a new Word document · Add Clicarity's logo at the top
Open a blank Word document. Copy everything inside the green box. Paste it. Add Clicarity's logo to the top. Fill in today's date where it says [PLACEHOLDER: Date]. This is the official letterhead version.
9001
Print the Quality Policy · Give it to Puneet to sign with a real pen
He signs on the line that says "Signed: ___". He writes today's date next to it. Do not type the signature, it must be a real pen signature.
9001
💬 What to say to Puneet

This is the Quality Policy for ISO. I need your pen signature on the line at the bottom, and today's date next to it. I will then scan it.

Scan the signed Quality Policy or take a very clear photo · Save as PDF
Use your phone camera or office scanner. Make sure the whole page is visible, the signature is clear, and nothing is cut off. Save the file as: Quality-Policy-Signed.pdf · Upload to folder 2-Policies.
9001
Now do the same for the Information Security Policy · Open Toolkit Section 2.2, approximately page 10
Look for a large box with a purple left border and light purple background. It starts with "CLICARITY. INFORMATION SECURITY POLICY" in purple letters. Document number is ISP-001.
📄 What it looks like, the Security Policy

Same layout as the Quality Policy but purple colour instead of green. It also ends with a signature line. Do exactly the same steps: copy to letterhead → print → get signed → scan → save as Security-Policy-Signed.pdf → upload to 2-Policies.

27001
Send both signed PDFs to the whole team on WhatsApp
Share both PDF files in the team WhatsApp group. Write this exact message: "These are Clicarity's official ISO policies. Please read both." Take a screenshot of the sent message.
BOTH
Save the WhatsApp screenshot into folder 2-Policies
Name it: Policy-WhatsApp-Proof.jpg. This screenshot is your proof that the policies were shared with the team.
BOTH
📊 Update in Clicarity now
Job ID:ISO-001
Status:ISO_Risk_Register_Done → Done
Form fields:Total risks identified · Number of HIGH risks (score ≥15) · Date of risk session · Signed by: Puneet · Next review date (6 months from today)
Upload:Clicarity-Risk-Register-v1.docx (signed version)
done with step 3, move to step 4
4
Fill In the Risk Register
Folder: 3-Risks · Takes 2–3 hours · Do this with Puneet
Open the Toolkit · Go to Section 3, approximately page 13
You will see the heading "Section 3. Combined Risk Register". Below it there are two tables. Read every row. You do not need to understand all the technical words, just read each risk sentence slowly.
📄 What it looks like, the Risk Register

There are two tables with 5 columns each. The column headers are: Risk Description · L (1–5) · I (1–5) · Score · Treatment. The first table is for Quality risks. The second table is for Security risks. Some rows already have scores filled in.

BOTH
💬 Ask Puneet before you start this table

Can you sit with me for 30 minutes to go through the risk list? I will read each risk out loud and you tell me if it applies to us or not. Then I will fill in the numbers.

For every risk row, fill in the L number and the I number
Use the guide below. L = Likelihood (how likely is this problem to happen?). I = Impact (how big is the damage if it happens?). Write a number from 1 to 5 in each column.
1 = Very unlikely to happen / Very small problem
2 = Unlikely / Small problem
3 = Possible / Medium problem
4 = Likely / Big problem
5 = Very likely to happen / Huge problem
BOTH
Save the Risk Register into folder 3-Risks
Save the Toolkit document first. Then copy just the Section 3 content into a new document. Name it: Clicarity-Risk-Register-v1.docx · Save into 3-Risks.
BOTH
📊 Update in Clicarity now
Job ID:ISO-001
Status:ISO_KPI_Tracking_Started → Done
Form fields:Objective 1–4 names + targets · KPI tracking start date (today)
Upload:Clicarity-Assets-v1.docx
Note:Stage 07 KPI tracking now runs in parallel, update it every month
done with step 4, move to step 5
5
Check the Assets and Processes Lists
Folder: 4-Assets · Takes 1–2 hours · Ask Lakshy for tech questions
Open the Toolkit · Go to Section 4, approximately page 17
You will see the heading "Section 4. Asset and Process Inventory". There are two tables on this page.
📄 What the two tables look like

Table 1. Section 4.1: Heading says "Core Business Processes". It lists 8 processes like Onboarding, Development, Support.

Table 2. Section 4.2: Heading says "Information Asset Register". It lists 10 items like customer data, laptops, passwords.

BOTH
Read each row in Table 1 · Does each process actually happen at Clicarity?
Read each row out loud. If something is wrong or missing, highlight that row in yellow. Do not delete anything yourself.
9001
💬 Ask Puneet about Table 1

I highlighted these rows in yellow because I am not sure they are correct: ________________________. Can you tell me what to change?

Read each row in Table 2 · Does each asset exist at Clicarity?
Read each row. If something is missing or wrong, highlight it in yellow. Pay attention to the Classification column, "Restricted" rows are the most important ones.
27001
💬 Ask Lakshy about Table 2 tech items

Lakshy, can you check Table 2 in Section 4.2 of the Toolkit? I need to know if the "Where stored" column is correct for our AWS and GitHub setup.

Save Section 4 into folder 4-Assets
Copy just the Section 4 content into a new document. Name it: Clicarity-Assets-v1.docx · Save into 4-Assets.
BOTH
📊 Update in Clicarity now. Assets & Processes
Job ID:ISO-001
Status:ISO_KPI_Tracking_Started → Done
Form fields:KPI tracking start date: today's date
Upload:Clicarity-Assets-v1.docx
⚠ Monthly reminder:Every month from now, update Job ISO-001 → Status: ISO_KPI_Month1_Done, then Month2, then Month3. Fill in the actual KPI numbers each time.
done with step 5, move to step 6
6
Write the 10 Short Procedure Documents (SOPs)
Folder: 6-Procedures · Biggest step · One SOP per day · Ask Puneet or Lakshy for each one
What is an SOP? Read this first before you start
SOP means Standard Operating Procedure. It is just a simple 1-page document that explains how Clicarity does something. You write it in bullet points. There are no right or wrong words, just describe what actually happens.
SOP Number and Name, example: SOP-01 Customer Onboarding
Version and Date, example: Version 1.0 · April 2026
Owner, the person responsible, example: Prakash
Steps, numbered list of what happens, in order
BOTH
SOP 1. Customer Onboarding · Save as SOP-01-Onboarding.docx
Write what happens from the moment a customer pays, to the moment their Clicarity dashboard is live. Who does what? In what order? How long does each step take?
BOTH
💬 Ask Puneet before writing SOP 1

Can you walk me through the onboarding steps one by one, from the moment someone pays? I will write them down as you talk.

SOP 2. Software Releases · Save as SOP-02-Releases.docx
Write how a new feature or bug fix goes from idea to live. Who tests it? Who approves it? What happens if something breaks after going live?
BOTH
💬 Ask Lakshy before writing SOP 2

Lakshy, how do you release a new feature or fix a bug? I need to write down the steps from start to finish. Can you explain it to me in simple words?

SOP 3. Customer Support · Save as SOP-03-Support.docx
A customer sends a complaint or question. Write exactly what happens next. Who receives it? Who replies? By when? How is it marked as solved?
9001
💬 Ask Jayesh or Puneet before writing SOP 3

How do we handle customer support today? Who gets the message first and what are the steps to resolve it?

SOP 4. Data Backup and Recovery · Save as SOP-04-Backup.docx
Write how Clicarity backs up customer data. How often? Where does it go? If AWS has a problem and data is lost, what are the steps to get it back?
27001
💬 Ask Lakshy before writing SOP 4

Lakshy, can you explain to me in simple steps: how often is our data backed up, where is it stored, and what do we do if we need to restore it? I will write it as a one-page document.

SOP 5. Who Has Access to What · Save as SOP-05-Access.docx
Write a list of all company systems (AWS, GitHub, Google, WhatsApp API). For each one, who has login access? What happens to that access when someone leaves the team?
27001
💬 Ask Lakshy before writing SOP 5

Lakshy, for each system we use (AWS, GitHub, etc.), who has access? And what is the process when someone new joins or someone leaves? I will write this as our official Access Policy.

SOP 6. Security Incident Response · Save as SOP-06-Incident.docx
What do we do if someone hacks our system, or customer data is leaked? Write the steps for the first 24 hours. Who do we call first? Who do we tell? How do we fix it?
27001
💬 Ask Puneet and Lakshy together for SOP 6

If our system is hacked or data is leaked, what do we do? Who is the first person to act? I need to write down the steps for the first 24 hours.

SOP 7. Supplier and Vendor Review · Save as SOP-07-Suppliers.docx
Clicarity uses AWS, Meta (WhatsApp), and Google. Write that we review these providers once a year, check their terms, check if there were any problems, confirm they are still the right choice.
BOTH
SOP 8. Internal Audit Process · Save as SOP-08-Audit.docx
Write that Clicarity runs an internal audit once a year using this checklist. One person checks another person's work. Findings are written down. Problems are fixed. A report is saved.
BOTH
SOP 9. Staff Joining and Leaving · Save as SOP-09-Offboarding.docx
When someone joins: what accounts do they get? Who sets them up? When someone leaves: what accounts are removed? Same day they leave, not later.
27001
💬 Ask Puneet before writing SOP 9

When a new team member joins, what accounts and access do they get? And when someone leaves, what is removed and who removes it?

SOP 10. Document Version Control · Save as SOP-10-Documents.docx
Write how all ISO documents are managed. Every document has a version number (v1.0, v2.0). When something changes, a new version is saved. Old versions are kept but marked OLD. Prakash is responsible for this.
BOTH
Save all 10 SOPs into folder 6-Procedures
Check you have all 10 files: SOP-01 through SOP-10. Each one should be saved with the correct file name as shown above. If any are missing, go back and write them.
BOTH
📊 Update in Clicarity now. SOPs Complete
Job ID:ISO-001
Status:ISO_SOPs_Complete → Done
Form fields:SOP 01–10 status: all Approved · Date all 10 approved · Approved by: Puneet
Upload:10 separate PDFs, upload each SOP individually: SOP-01.pdf through SOP-10.pdf
done with step 6, move to step 7
7
Run the Internal Audit
Folder: 7-Audit · Takes 1 full day · Do this with Puneet, he answers, you write
Print the questions below · Book a full day with Puneet · Go through every question together
You read each question. Puneet answers. You write C, NC, or OFI next to each one. Write what proof Puneet shows in the notes column.
C = Conforming. We do this. We have proof.
NC = Nonconformity. We do NOT do this yet. Must be fixed before real audit.
OFI = Opportunity for Improvement. We do it but not perfectly.
1. Is the Quality Policy signed, dated, and shared with all staff? (show the WhatsApp screenshot)
2. Is the Information Security Policy signed, dated, and shared with all staff?
3. Can Puneet say what our quality and security objectives are from memory?
4. Is the Risk Register completed with scores for every row, quality AND security risks?
5. Has the Risk Register been reviewed in the last 6 months?
6. Are all 10 SOPs written, approved by Puneet, and saved in the correct folder?
7. Do the SOPs describe what actually happens, not what we wish happened? (spot check 2)
8. Do we have training records for every team member with signatures?
9. Do we have 3 months of KPI data recorded?
10. Are our KPI targets being met? If not, is there a corrective action plan?
11. If a customer complained recently, can we show what we did about it?
12. Is there a list of approved suppliers (AWS, Meta, Google)? Have they been reviewed?
13. Is MFA (two-step login) turned on for ALL admin accounts. AWS, GitHub, Google? (Lakshy shows proof)
14. Are all API keys stored in AWS Secrets Manager, not written in code? (Lakshy shows proof)
15. When was the last backup recovery test? Can we show the test record?
16. Have all staff completed security awareness training? Show attendance record.
17. Has a penetration test been conducted? Show the report and remediation log.
18. Are all ISO documents saved in the correct Google Drive folders with version numbers?
19. Has the access rights list been reviewed in the last 6 months? (who has access to what)
BOTH
💬 Ask Puneet to sit with you for this whole step

I need you to sit with me for this audit. I will read each question out loud. You answer yes or no. If yes. I will write C (Conforming). If no. I will write NC (Nonconformity). We need proof for each yes answer.

For every question: write C, NC, or OFI in the Rating column
Use only these three letters. Write the proof or evidence in the Notes column.
C = Conforming. We do this. We have proof.
NC = Nonconformity. We do NOT do this yet. It needs to be fixed.
OFI = Opportunity for Improvement. We do it but not perfectly.
BOTH
Make a list of every row marked NC · Fix every single one before moving to Step 8
For each NC, write what needs to be done, who will do it, and by when. Do not move to Step 8 until every NC is fixed and changed to C.
BOTH
💬 Ask Puneet about each NC

I found these NC items in the audit: ________________________. What do we need to do to fix each one? Can you tell me the action and who is responsible?

Type up the completed audit as a report · Save into folder 7-Audit
Name it: Internal-Audit-Report-v1.docx. Include the date the audit was done, who did it, and a summary of findings at the top.
BOTH
📊 Update in Clicarity now
Job ID:ISO-001
Status:ISO_Audit_Complete → Done
Form fields:Audit date · Auditor name · Total questions: 19 · C count · NC count · OFI count · All NCs fixed: Yes · Date NCs fixed
Upload:Internal-Audit-Report-v1.docx + any NC correction evidence
Also update:Stage 07 KPI, make sure Month 1, 2, and 3 are all marked Done before moving forward
done with step 7, move to step 8
8
Hold the Management Review Meeting
Folder: 8-Review · Takes 2 hours · Puneet runs the meeting · You write the notes
Print the 12 agenda items below · Book a 2-hour meeting with Puneet
This is a formal meeting, not a casual chat. Print this page. During the meeting, Puneet answers each item. You write the notes in the space next to each one. Do not leave any item blank.
1. Actions from last review, are they all completed? _______________
2. Internal audit results, what were the findings? _______________
3. Customer feedback, any complaints this period? _______________
4. KPI performance, are we hitting our targets? _______________
5. Process performance, where are we strong, where are we weak? _______________
6. Security incidents, any breaches or near-misses this period? _______________
7. Supplier performance, any issues with AWS, Meta, or Google? _______________
8. Risks, any new risks identified or changes to existing ones? _______________
9. Resources, do we need more people, tools, or training? _______________
10. Changes, anything new that could affect our quality or security system? _______________
11. Objectives, are our quality and security targets still right for this period? _______________
12. Actions from THIS meeting, who does what by when? _______________
BOTH
💬 What to say to book this meeting

Puneet, can we book 2 hours for the ISO Management Review meeting? I will print the agenda and write the notes. You just need to answer the 12 questions on the list. We must have signed minutes from this meeting before calling the Certification Body.

During the meeting, write notes in the Notes column for every agenda item
Do not leave any row blank. Even if the answer is short, write something. These notes become the official minutes.
BOTH
After the meeting, type up the minutes · Get Puneet to sign the bottom
Type your handwritten notes into the Word document. At the bottom of the document add: Date, Puneet's name, and a signature line. Print it. He signs. Scan it. Save into folder 8-Review as: Management-Review-Minutes-v1.docx
BOTH
📊 Update in Clicarity now
Job ID:ISO-001
Status:ISO_MgmtReview_Signed → Done
Form fields:Meeting date · Format: In-person/Google Meet/WhatsApp Video · Attendees names · Previous actions done: Yes/No · New actions assigned: count · Signed by: Puneet · Next review date (12 months from today)
Upload:Management-Review-Minutes-v1.docx (signed and scanned)
done with step 8, one final step
Contact the Certification Body
Folder: 9-CB-Readiness · Only do this when EVERY box above is ticked
Check that all 9 Google Drive folders have files in them
Open each folder one by one. If any folder is empty, stop and go back to fill it. Do not send any emails until every folder has at least one document.
BOTH
Go through every item below · Every single one must be Done before sending emails to CBs
Read each item. If it is done and the file is saved in Google Drive, tick it. If anything is not done, go back and finish it first. Do not contact any Certification Body until every item below is ticked.
☐ Scope statement agreed and saved in folder 1-Scope
☐ Quality Policy, signed PDF saved in folder 2-Policies
☐ Information Security Policy, signed PDF saved in folder 2-Policies
☐ Both policies shared with whole team. WhatsApp screenshot saved
☐ Roles and responsibilities document saved in folder 2-Policies
☐ Risk Register, quality and security risks rated and signed, saved in folder 3-Risks
☐ Asset and process inventory saved in folder 4-Assets
☐ Quality and security objectives with 3 months of KPI data saved in folder 5-Objectives
☐ All 10 SOPs written, approved by Puneet, saved in folder 6-Procedures
☐ MFA turned on for all admin accounts, screenshot saved as proof
☐ API keys confirmed in AWS Secrets Manager, not in code
☐ Penetration test completed, report and remediation log saved
☐ Internal audit completed, all NCs fixed, report saved in folder 7-Audit
☐ Training records for all staff with signatures, saved in folder 6-Procedures
☐ Management review meeting held, signed minutes saved in folder 8-Review
☐ Backup recovery test completed, test record saved
☐ Udyam registration certificate ready
BOTH
💬 Ask Puneet to check this list with you before sending emails

I have gone through the 17-item list in Section 9 of the Toolkit. Can you check my Done/Not Done marks before I contact the Certification Bodies?

Send this email to 3 Certification Bodies to ask for a quote
Copy the email below exactly. Send it to all three email addresses. Do not change the subject line.

Subject: ISO 9001 + ISO 27001 Certification Quote Request. SaaS Company, 2 employees, Mumbai

Dear Team,

We are Clicarity, a SaaS job tracking platform based in Mumbai. We are seeking ISO 9001:2015 and ISO 27001:2022 certification together as a combined audit.

Our details: 2 employees · Single location · Cloud-based software product (AWS infrastructure) · Udyam registered MSME

Could you please send us a quote for: (1) Combined Stage 1 + Stage 2 audit, (2) Annual surveillance audit cost, (3) Total 3-year cost estimate.

Thank you.
Regards,
[Your name]
Clicarity
[email protected] · +91 98678 00451

Bureau Veritas India: [email protected]
BOTH
💬 Ask Puneet to check before sending

I have written the emails to the 3 Certification Bodies. Can you check my draft before I send? I just need 2 minutes of your time.

Save all quote replies into folder 9-CB-Readiness · Show Puneet all 3 quotes
When the quotes arrive by email, save each one as a PDF into 9-CB-Readiness. Name them: Quote-BureauVeritas.pdf · Quote-SGS.pdf · Quote-DNV.pdf. Puneet decides which one to use, not you.
BOTH
Home·Pricing·Contact·Privacy Policy·Terms & Conditions
© 2026 Clicarity