Skip to content

Compliance

Evidence, not a transcription exercise

The point of modelling the register on the standards is that you can show the tool to an auditor rather than exporting it into a separate spreadsheet and reformatting it the week before the visit.

Why it holds up

Three properties an auditor tends to probe

Can the record have been edited after the fact?

The audit trail is append-only. There is no update path and no delete path for an event. Only a project administrator deleting an entire improvement removes its history, and that action is logged.

Could an event be missing?

Each improvement's events carry a monotonic sequence number. Two events written in the same millisecond still have a defined order, and a gap in the sequence is detectable rather than invisible.

Is the benefit figure real?

Realised benefit is counted only from verified and closed records, verification requires evidence, and verification cannot be reached without implementation. The lifecycle enforces the claim.

Audit trail — CSI-1
An ImproveDesk audit trail listing seven sequenced events with dates, the person responsible, and the fields changed at each step.
A complete trail from creation to closure. Each entry carries its sequence number, the date, the person and the fields that changed.

ISO/IEC 20000-1:2018

Service management system

ClauseTitleHow ImproveDesk serves it
10.2Continual improvementThe register itself. Opportunities are recorded with a source, evaluated against documented criteria (RICE and the composite score), prioritised, actioned through the lifecycle and verified before closure.
9.3Management reviewThe dashboard is the review pack: open and overdue counts, realisation rate, return on cost, median cycle time, raised against closed over twelve months, and the ageing of open work.
8.6.3Problem managementImprovements sourced from incidents, major incident reviews and problems, with the delivery issues that implement them linked from Jira.
9.1Monitoring and measurementBaseline, target and actual per measure, with lower-is-better handled correctly, and a weekly snapshot that preserves the figures over time.

ISO/IEC 27001:2022

Information security management system

ClauseTitleHow ImproveDesk serves it
10.1Continual improvementThe same register serves the ISMS. Tag improvements with the clause or control you are evidencing.
10.2Nonconformity and corrective actionAudit findings are a first-class source. The record captures the finding, the correction, the owner, the target date and the verification that it worked — with dates that cannot be back-fitted.
9.2Internal audit"Internal audit" and "external audit" are sources on the record, so audit-driven work is reportable separately from service-driven work.

ITIL 4

The seven-step continual improvement model

The record is shaped so that each step of the model has somewhere to live, rather than being a discipline people are asked to remember.

StepQuestionWhere it lives in the record
Step 1What is the vision?Sponsor and benefit narrative on every record.
Step 2Where are we now?Baseline captured per measure.
Step 3Where do we want to be?Target per measure, and a target date.
Step 4How do we get there?Linked Jira delivery issues, risks and dependencies.
Step 5Take actionApproved and In progress, with an owner accountable.
Step 6Did we get there?Actual per measure, realised benefit, and the Verified gate.
Step 7How do we keep the momentum?Review cadence, the daily attention sweep and the weekly snapshot.

An honest note on clause references

Standard references on a record are free text. That is deliberate — a fixed clause list goes stale with every revision of a standard, and a tool that ships one quietly becomes wrong. The trade-off is real: ImproveDesk cannot validate your references against a controlled clause set, so pick a convention and apply it. The clause numbers on this page are given to show intent, and you should confirm them against your own certification scope and the current text of the standard.

What ImproveDesk is not

It is not a certification, an assessment, or a guarantee that you will pass an audit. It is a register that records improvement work in a form an auditor can read, with controls that stop the most common ways such a register becomes untrustworthy. The judgement remains yours and your auditor's.

Where the data actually lives

A fair question before any compliance conversation. The answer is short: inside your own Atlassian tenancy.