A step-by-step guide to the world's most comprehensive free ISO & API compliance toolkit — 125+ browser-based gap analysis, risk assessment and audit preparation tools.
A quick map of everything you'll learn. Each chapter stands on its own — jump to the section you need.
ISO Xpert is a free, browser-based compliance toolkit built by UKAS-aligned consultants in London. Every tool runs locally in your browser — no sign-up, no email capture, no data ever leaves your device. Open a tool, answer clause-by-clause questions, view your instant score & heat-map, then export your audit-ready evidence in the format of your choice.

Each tool sits in one of three families. Pick the family that matches the question you need to answer.
Clause-by-clause conformity assessments for every major ISO management-system standard, pre-aligned to the Annex SL high-level structure.
Inspection, integrity and management-system checklists for the oil, gas & refining industry — aligned to the latest API editions.
ISO 31000-aligned likelihood × impact risk matrices tailored to the context of each specific management system.

Everything happens inside your browser. No server, no account, no upload. Total control of your data.
Built with pure HTML, CSS and JavaScript — no server round-trips. Works in Chrome, Edge, Firefox and Safari, online or offline once the page has loaded.
Your answers save automatically to localStorage under an isolated key per tool. Data persists across sessions and only lives on your device.
Nothing is sent to ISO Xpert servers. You control every export — it downloads straight to your machine. GDPR-friendly by design.
Confidential audit findings, non-conformities and risk registers never leave your organisation — making the toolkit safe to use with proprietary and regulated data.

From opening the browser to exporting your first audit pack — typically under 30 minutes per standard.
Go to tool.iso-xpert.com and pick the standard or tool you want from the directory.
Work through each clause. Rate your conformity — Yes, Partial or No — and add evidence notes.
Watch your compliance percentage update live. Open the heat-map to spot weak clauses at a glance.
Download your findings as JSON, CSV, PDF or TXT. Drop it straight into your management review pack.

Every gap-analysis tool follows the same consistent layout — learn one, you know them all.
Official clause number from the published standard.
Plain-English requirement rewritten for auditors.
Yes / Partial / No — click once to toggle.
Optional free-text — record document refs & dates.

A deeper guided tour through a full gap-analysis cycle — from launch to export.
From the directory, click the ISO or API standard you want to assess. The tool opens in a new tab.
Enter the company name and audit scope at the top of the tool — it flows into your exports.
Tick Yes / Partial / No per clause. Drop objective evidence into the notes field.
Every "No" automatically becomes a finding in the action plan — ready for root-cause analysis.
Live compliance %, per-clause score and heat-map refresh as you type.
For each gap, write the action, owner and target date directly in the tool.
Download the pack in JSON, CSV, PDF or TXT — whichever your auditor prefers.
Re-open the tool at your next review — your previous state is loaded from local storage.

How the live percentage is calculated — and how to read the four maturity bands.

Spot your weakest clauses instantly. Each cell represents one clause — colour tells you where to focus.
Red cells are major non-conformities — tackle these first. They almost always block Stage 2 certification.
Amber cells are your medium-term roadmap. Document the plan; they typically become minor findings.
Dark-green clauses are strengths — reference them in your management review as evidence of maturity.

The 12 risk tools use the same Likelihood × Impact matrix recommended by ISO 31000.
List each uncertainty that could affect your objectives — use the template categories (strategic, operational, compliance, etc.).
Pick a likelihood (Rare → Almost Certain) and an impact (Insignificant → Severe). The matrix calculates the rating.
Assign controls, owner and a residual rating. Re-open the tool later to monitor whether the treatment worked.

Your audit data is yours. Here's exactly how persistence and privacy work under the hood.
Every answer, note and risk entry is written to localStorage the moment you change it. Close the tab — your work is waiting when you reopen the page.
The toolkit makes no network calls for your audit data. Every calculation, every score, every export is generated locally by JavaScript in your browser.
Because data lives in your browser, clearing site data, using incognito mode or switching machines will not carry your progress across. Export regularly for backups.

Four formats — pick the one that matches how you'll share the results downstream.
Full state tree — every answer, note and timestamp. Re-import-ready.
Flat table of clause / status / note / action — opens in Excel or Sheets.
Branded PDF with score, heat-map, clause summary & action plan.
Lightweight readable dump — fits into emails, tickets & chat tools.

Battle-tested habits from UKAS-accredited lead auditors who use the toolkit daily.
Even though auto-save is reliable, a weekly JSON export is your disaster-recovery plan against lost browser data.
Use the notes field for exact document IDs & revision numbers — auditors love the audit-trail.
Every "No" needs a named owner and a target closure date — otherwise it's just a wish, not an action.
Assessing multiple sites? Export JSON, then copy the file and edit per site — faster than re-keying everything.
Pair the matching gap-analysis tool with its risk-assessment counterpart (e.g. ISO 9001 + ISO 9001 Risk) for full management-review inputs.
Open the tool every quarter — the trend in your compliance % becomes a headline KPI for leadership.

Quick answers to the questions auditors, consultants and clients ask most.
Need help implementing, training or auditing? Our UKAS-aligned consultants are a message away. Scan the QR or drop us a note.