Zavior
For Schools

Can you run a compliance program in Notion or Confluence?

You can document a compliance program in Notion or Confluence, but you can't operate one there. A wiki has no link between controls and live evidence, no auditor view.

By Sean Teh · Head Of Growth, Zavior

6 min readInsight
Can you run a compliance program in Notion or Confluence?

You can document a compliance program in Notion or Confluence, but you can't operate one there. A wiki holds policies well, yet it has no link between controls and live evidence, no expiry tracking, and no auditor view. Teams that start in a wiki typically migrate at their first multi-framework audit.

What does a wiki do well?

A wiki is genuinely good at three compliance jobs: writing and versioning policies, onboarding staff to those policies, and recording who owns what. If your program today is "we need an information security policy, an acceptable use policy, and somewhere new hires can read them", Notion or Confluence does that job properly. You should not apologise for it.

Page history shows who changed a policy and what the previous wording was, which covers the version control ISO 27001 expects for documented information. A Confluence page tree can mirror your document hierarchy cleanly. A Notion database can hold owner, review date and status against every policy. That is more structure than most small teams manage in a shared drive.

For an Australian startup drafting its first policy suite ahead of an enterprise deal that asks about ISO 27001, this is real coverage, not theatre. Policies change slowly, they are prose, and prose is what wikis are built for. The trouble starts when the program stops being about documents.

Where does it silently fail?

It fails at evidence, which is the thing an audit actually tests. An auditor does not certify that your policies exist; they certify that your controls operate. That means access review exports, MFA configuration screenshots, backup logs and offboarding tickets, each tied to a specific control and each current for the audit period.

The hidden cost is the quarterly evidence refresh with no expiry alerts. Evidence ages quietly. An access review from February is stale by the September audit, but the wiki page it's pasted into looks exactly as healthy as it did the day you wrote it. Nothing flags it. Nothing tells the control owner it's due.

You discover the gap when the auditor asks for twelve months of operating evidence and you have one screenshot and a good story.

The second silent failure is mapping. ISO 27001 and the Essential Eight overlap heavily (patching, privileged access, backups, MFA), but a wiki has no way to say "this one control satisfies both frameworks, and here is its evidence". You end up with duplicated pages that drift apart, or one page an auditor can't trace to either framework.

CapabilityWiki (Notion / Confluence)Compliance platform
Policy authoring and version historyStrong, built for exactly thisAdequate, often thinner
Control register mapped to frameworksManual tables that driftNative, per framework
Evidence linked to controlsPasted attachments, no structureStructured, per control and period
Evidence expiry and refresh alertsNoneAutomatic, with owner reminders
Cross-framework mapping (ISO 27001 and Essential Eight)Duplicated pagesOne control, both frameworks
Auditor accessGuest licence to your whole workspaceScoped read-only view
Task ownership and review cadenceReminders you set by handBuilt into each control

What does the hybrid look like?

Keep the wiki as your policy library and run controls, evidence and tasks in a platform, with links between the two. Policies are prose that changes a few times a year. Leave them where your team already reads them. Controls and evidence change every quarter, and they need the structure a wiki can't give.

In practice, the platform holds your control register, mapped to ISO 27001 and the Essential Eight. Each control links out to the Confluence or Notion page that states the governing policy, and holds its own evidence and owner, plus a refresh date. The wiki stays the answer to "what do we say we do"; the platform becomes the answer to "can we prove we did it".

The hybrid demands one discipline. A policy lives in the wiki and nowhere else; a control lives in the platform and nowhere else. The moment someone copies the control list back into a Notion table for visibility, you have two registers, and one of them is wrong.

When is a full platform justified?

A platform earns its keep when your program crosses from writing to proving. Specific triggers tell you when that has happened. Any one of them is a reasonable prompt; two or more means the wiki is already costing you audit-week panic.

  • A second framework arrives. ISO 27001 plus Essential Eight maturity reporting for a government buyer, say, or SOC 2 for US customers. Cross-mapping in a wiki means duplicated pages that drift.
  • An external audit is booked. The auditor needs a scoped view of controls and evidence, not a guest login to your entire workspace.
  • Recurring evidence outgrows memory. Once more than a handful of controls need quarterly refresh, "someone will remember" stops being a control.
  • Security questionnaires become routine. Answering from a live control register takes minutes. Answering from page trees takes an afternoon, every time.
  • A government or regulated customer asks for maturity evidence. Essential Eight claims need current, traceable evidence behind each mitigation strategy, not a page saying you patch promptly.

Below these triggers, the honest advice is to stay put. A wiki plus a disciplined spreadsheet is enough for a program that hasn't faced its first audit, and buying tooling before you have controls to put in it just gives you an empty register with a subscription attached. For what auditors actually ask to see, see our guide to audit evidence.

If you're at the hybrid stage, Zavior's control register maps each control to ISO 27001 and the Essential Eight and flags evidence before it expires, while your policies stay in the wiki your team already reads.

Frequently asked questions

Will an auditor accept Notion screenshots?

Usually yes. Auditors care about what evidence shows, not which tool stores it, so a dated screenshot that is current for the period under review is fine. The problem is scale; a wiki cannot show that evidence across dozens of controls is fresh, so expect heavier sampling and more follow-up requests.

Are there free alternatives?

Yes. Free tiers of compliance platforms and open-source GRC tools exist, and a spreadsheet with an expiry-date column you can sort already beats a wiki for evidence tracking. Free options tend to run out at multi-framework mapping and automated refresh reminders, which is also where paying starts to make sense.

How much effort is migration?

Moving documents is the easy part, and in a hybrid setup your policies don't move at all. The real work is retro-building the structure the wiki never had, meaning a control register mapped to ISO 27001 and the Essential Eight with current evidence attached to each control. The documents move in days; that mapping is where the time goes.

Zavior · Data Protection

The same gap shows up in data protection: a policy page is not a running programme. Zavior builds the programme regulators and enterprise buyers actually test, with policies written for your real data flows, DPIAs where the law expects them, and classification staff can follow day to day. A named DPO is available when appointing one in-house makes no sense.

Book a free 30-minute business assessment →

Sources: auditor guidance on evidence and documented information, ISO/IEC 27001 framework requirements, and the ACSC Essential Eight maturity model.

Written by

Sean Teh

Head Of Growth, Zavior

Share

Let us be your Zavior.

Zavior helps Australian businesses build cyber resilience aligned to the ACSC Essential Eight, the Privacy Act, and ISO 27001.

Continue reading