Regulatory Documentation
Ready for Audit
The absence of documentary evidence is the No. 1 cause of non-conformities in audits. With Kit Docs you have 307 DOCX templates ready the same day you buy them.
Choose the Pack You Need
Each pack is organised by regulatory domain. Buy only what you need, or combine them for full coverage.
- Gobernanza y Estrategia 10
- Gestión de Activos 4
- Gestión de Riesgos 6
- Control de Accesos 5
- Protección Técnica 9
- Gestión de Incidentes 12
- Continuidad Operacional 7
- Terceros y Proveedores 8
- Cultura y Concientización 4
- Auditoría y Cumplimiento 7
- SGSI y Estrategia 33
- Gestión de Riesgos 4
- Controles Organizacionales (A.5) 33
- Controles de Personas (A.6) 17
- Controles Físicos (A.7) 9
- Controles Tecnológicos (A.8) 42
- Continuidad del Negocio 15
- Soporte y Operación del SGSI 28
- Gobernanza de Privacidad 7
- Inventario y Registro 4
- Legitimidad y Consentimiento 5
- Derechos de Titulares 5
- Seguridad de Datos 6
- Categorías Especiales 2
- Notificación de Brechas 5
- Transferencias y Cesiones 5
- Evaluación de Impacto (DPIA) 4
- Inteligencia Artificial 5
- Capacitación 4
- Tecnologías Web y Cookies 2
In Preparation
We are building the document catalogue for these standards. They cannot be purchased yet; let us know and we will write to you the day yours is ready.
It will cover
- PIMS context and scope
- Privacy policy and roles
- Record of processing activities
- Impact assessments
- Data subject rights
- Transferencias internacionales
- Statement of applicability
The 2025 edition turned it into a standalone standard. The transition from the 2019 one expires in October 2028.
It will cover
- AIMS context and scope
- AI policy and responsibilities
- AI risk assessment
- AI system impact assessment
- Annex A controls
- Life cycle and training data
- Internal audit and improvement
First edition of December 2023. Its AI system impact assessment has no equivalent in other standards.
It will cover
- Context and interested parties
- Quality policy and objectives
- Process map
- Control of documented information
- Production and service provision
- Supplier evaluation
- Non-conformities and corrective action
The management system standard most demanded in public tenders and in contracts with large companies in Chile.
It will cover
- Scope of the service management system
- Service portfolio
- Service level agreements
- Supply and demand management
- Service design, build and transition
- Resolution of incidents and requests
- Service assurance and continuity
- Service reports
Chilean standard from the INN, an identical adoption of ISO/IEC 20000-1:2018. It is the one cited in the State's IT service tender documents.
It will cover
- Scope of the continuity system
- Business impact analysis (BIA)
- Continuity risk assessment
- Continuity strategies and solutions
- Continuity plans and procedures
- Exercise and testing programme
- Evaluation of capabilities
- Crisis management and communication
Chilean standard from the INN, an adoption of ISO 22301:2019. Its exercise programme is what separates a plan that works from one that is merely written.
All five are already available as consulting programmes: a consultant produces the documentation with you, adapted to your organisation, without waiting for the pack to be released.
Cybersecurity
Framework Law
(Law 21,663)
The law requires institutions of vital importance to demonstrate compliance to the ANCI with technical documentation. Auditors do not assess intentions, they assess evidence. Our templates cover every enforceable requirement.
Critical Asset Register and Classification
A formal inventory of the assets that must be notified to the ANCI, with criticality and an assigned owner.
Incident Reporting Protocol
The mandatory notification flow to the ANCI within the legal deadlines. Without this document, the fine is automatic.
Operational Continuity Plan
BCP and DRP aligned with the requirements of article 8 of the law. Essential for the first-line audit.
ISMS + Cybersecurity Governance
A documented governance structure, including roles, responsibilities and the security committee.
ISO 27001/27002:2022 — Complete ISMS
The most internationally recognised standard in security management. 181 documents organised into 8 categories cover every clause and every Annex A control.
Statement of Applicability (SoA)
The master document mapping every Annex A control to its implementation status. Required by the certification body.
ISO 27005 Risk Matrix
Risk identification, analysis and evaluation with a recognised methodology. Includes acceptance criteria and a treatment plan.
17 HR and People documents
Job profiles for CISO, ISMS Auditor, ISO Manager and several technical roles. Contracts, confidentiality agreements and training.
17 Technological documents
Access control, patch management, cryptography, backup and secure deletion policies aligned with the 8.x controls.
Internal Audit Programme
Annual plan, checklists by domain, and forms for findings and non-conformities. Everything the external auditor will ask for.
- Statement of Applicability (SoA)
- Information Security Policy
- ISO 27005 Risk Matrix
- 33 Strategic documents (Policies and Manuals)
- Continuity and Recovery Plan (BCP/DRP)
- Management Review Templates
Personal Data
Protection Law
(Law 21,719)
Chile modernised its privacy legislation by aligning it with the European GDPR. The new law creates the Data Protection Agency and sets penalties of up to 5,000 UTM. The documentation is mandatory in order to demonstrate compliance.
Records of Processing Activities
An inventory of all the data your organisation processes. Mandatory and auditable by the Agency.
Data Subject Rights and Consent Forms
Access, rectification, cancellation and objection. Data subjects must receive a reply within 30 days, under penalty.
Agreements with Data Processors
Agreements with suppliers (cloud, HR, marketing) processing data on your behalf. Mandatory, without exception.
Data Protection Impact Assessment (DPIA)
The mandatory analysis before processing high-risk data. Without a documented DPIA, the operation can be suspended.
Save Time and Money
Buying the pack saves you up to 77% compared with buying each document separately. Your DOCX templates ready the same day, with no hours of drafting.
Immediate Download
After payment, you get the pack in seconds. No waiting, no manual delivery process.
100% Editable DOCX
Open in Word or LibreOffice and personalise with your company's logo, name and details. No DRM, no restrictions.
Written by GRC Experts
Every document was checked against the original regulatory texts by consultants holding CISA and CISSP certifications.
Updated to the Current Version
ISO 27001:2022, Law 21,663 with its ANCI regulations, and Law 21,719 in its final text. No obsolete versions.