Halfway through an ISO 27001 audit the team could not locate half the documents they were asked for. When the auditor asked to see the data retention policy, it turned out nobody had ever written one down.
The ISO 27001 template went live, evidence collection was automated, and every missing policy was written from scratch. Each control ended up with a named owner, a link to its evidence, and a documented implementation status.
Passed ISO 27001 audit with zero findings, averting six figures in potential contract losses