CIAO Standard Document Registry

Protected Framework This framework is protected under CC BY-NC-ND 4.0patent pending. See Multitier Licensing.
CIAO COMMONS — STANDARD
C-AO/STD/002:2026 PUBLIC
CIAO Standard Document Registry
An authoritative index of all governing documents
Date Issued  1 January 2026
Review Date  1 January 2027
Cite as: CIAO Standard. (2026). CIAO Standard Document Registry. v1.0. C-AO/STD/002:2026. www.c-ao.com

An authoritative index of all governing documents published under the CIAO Standard, for governance, assurance, and oversight practitioners.

1. Registry Overview

The CIAO Standard Document Registry is a structured, version-controlled index of all governing documents published under the CIAO Standard. Each entry is assigned a unique document reference—for example, C-AO/POL/ISP/001:2026—encoding the document type, tier, and year of issue to ensure consistent traceability. All documents are web-native and accessible without download, with each record displaying the current version, ACTIVE status, classification, and Review Date for full transparency.

Organised across six membership tiers—Commons, Core, Essential, Professional, Enterprise, and Conglomerate—the registry reflects the progressive scope of the standard. The foundational document set is active at Version 1.0, providing a complete baseline for governance, policy, and compliance frameworks. Whether establishing a new programme or auditing an existing one, this registry offers a clear, authoritative view of the controls and supporting materials that constitute the CIAO Standard, maintained with version integrity to support governance continuity and regulatory alignment.

2. Document Registry Table

#Document TitleDoc RefTypeTierVerStatusReview DateMVELicence
1CIAO1.0ACTIVECC BY-SA 4.0
2CIAO Standard Document RegistryC-AO/STD/002:2026StandardCommons1.0ACTIVE1 January 2027Registry maintained; new documents recorded within 30 days of issuance; review cadence logged.CC BY-NC-ND 4.0
3CIAO Standard v1.0C-AO/STD/001:2026StandardCommons1.1ACTIVE1 January 2027Adoption attested by accountable executive; referenced in the organisation’s compliance framework.CC BY-SA 4.0
4Open PrinciplesC-AO/PRI/001:2026StandardCommons1.0ACTIVE1 January 2027Principles acknowledged in the organisation’s code of conduct or ethics register.CC BY-SA 4.0
5Governance CharterC-AO/GOV/001:2026CharterCommons1.0ACTIVE1 January 2027Internal to CIAO governance — no adopter MVE required.CC BY-SA 4.0
6Code of PracticeC-AO/COP/001:2026PracticeCommons1.0ACTIVE1 January 2027Code acknowledged and filed with the internal ethics or compliance register.CC BY-SA 4.0
7Membership GuidelinesC-AO/MEM/001:2026GuidelinesCommons1.0ACTIVE1 January 2027Active CIAO membership on file; tier attestation recorded.CC BY-SA 4.0
8Panel Advisor GuidelinesC-AO/PAG/001:2026GuidelinesCommons1.0ACTIVE1 January 2027Internal to CIAO governance — no adopter MVE required.CC BY-SA 4.0
9Partnership GuidelinesC-AO/PNG/001:2026GuidelinesCommons1.0ACTIVE1 January 2027Signed partnership MOU on file; CIAO partner mark usage governed.CC BY-SA 4.0
10Practitioners GuidelinesC-AO/PRG/001:2026GuidelinesCommons1.0ACTIVE1 January 2027Named Practitioners logged in capability register; evidence of current certification.CC BY-SA 4.0
11Multitier LicensingC-AO/LIC/001:2026StandardCommons1.0ACTIVE1 January 2027Licence terms published per tier; member tier visible to credential check; download attempts respect tier licence.CC BY-SA 4.0
12Framework MappingC-AO/STD/004:2026MappingCommons1.0ACTIVE1 January 2027Mapping table published; source standards register current; clause references verified per Panel review cycle.CC BY-SA 4.0
13Usage TermsC-AO/LEG/001:2026LegalCommons1.0ACTIVE1 January 2027Usage Terms accepted at member onboarding; binding obligations recorded against member account.CC BY-SA 4.0
14Volunteer Contribution & Compensation DisclosureC-AO/GOV/004:2026DisclosureCommons1.0ACTIVE25 April 2027Disclosure published; volunteer-only governance status visible on every governance-body page footer.CC BY-SA 4.0
15Standard Architecture & Tier Content DepthC-AO/STD/002:2026ArchitectureCommons1.0ACTIVE25 April 2027Architecture published; CAO domain spine and tier ladder mapped to CIAO Standard v1.0.CC BY-SA 4.0
16Dynamic Selection EngineC-AO/STD/003:2026SpecificationCommons1.0ACTIVE25 April 2027Specification published; engine implementation scoped per Implementation Plan; live deployment Phase 1 pending.CC BY-SA 4.0
17CIAO Assessment v1.0C-AO/AST/001:2026AssessmentCommons1.0ACTIVE1 January 2027Assessment tool published; tier recommendation logic current; self-assessment results saved per logged-in member.CC BY-SA 4.0
18Change Management & Versioning ProcessC-AO/PRC/CMV/001:2026ProcessCommons1.0ACTIVE26 April 2027Process documented; Release Calendar to be published; change log live; quarterly errata summary scheduled.CC BY-SA 4.0
19Editorial Submission FrameworkC-AO/PRC/ESF/001:2026ProcessCommons1.0ACTIVE26 April 2027Framework documented; Practitioner Submission template available; triage queue live; quarterly submission summary scheduled.CC BY-SA 4.0
20ConstitutionC-AO/CON/001:2026ConstitutionCommons1.0ACTIVE26 April 2029Constitution published; amendment procedure in force; Oversight Board seating tracked; Constitutional hierarchy enforced.CC BY-SA 4.0
21Release CalendarC-AO/CAL/REL/001:2026CalendarCommons1.0ACTIVE26 April 2027Calendar published; major release horizon current; pipeline categories active; release event log append-only.CC BY-SA 4.0
22Quarterly Errata & Submission SummaryC-AO/SUM/QES/001:2026SummaryCommons1.0ACTIVEQuarterly cadenceSummary published; quarterly cadence active; errata stream reflected; submission stream reflected.CC BY-SA 4.0
23Canonical Source Standards RegisterC-AO/REG/SSR/001:2026RegisterCommons1.0ACTIVE26 April 2027Register published; 26 source standards catalogued; family taxonomy current; source-standard re-issue trigger active; Register Addition Request pathway codified.CC BY-SA 4.0
24Document Quality ControlC-AO/PRC/DQC/001:2026ProcessCommons1.0ACTIVE26 April 2027Quality gates documented; footer rendering active on all controlled documents; six gate categories defined; gate enforcement integrated into Change Management workflow.CC BY-SA 4.0
25Glossary of Base ConceptsC-AO/REF/GLO/001:2026GlossaryCommons1.0ACTIVE4 May 2027Glossary v0.2 published; 25 base concepts catalogued across two families (source-artefact, audit-and-assurance); reference attribution to ISO/IEC Guide 2:2004, ISO/IEC 17000:2020, ISO 19011:2018, IoDSA King V 2025, AICPA TSC 2017, IAASB ISAE 3402, TFEU Article 288, Vienna Convention 1969; ontology relationship layer scheduled for v0.3.CC BY-SA 4.0
26Information Security PolicyC-AO/POL/ISP/001:2026PolicyCore1.0ACTIVE1 January 2027Policy in force; ISMS scope documented; risk register current; named owner.CC BY-SA 4.0
27Data Protection & Privacy PolicyC-AO/POL/DPP/001:2026PolicyCore1.0ACTIVE1 January 2027Policy in force; DPO named where required; records-of-processing current; named owner.CC BY-SA 4.0
28Cybersecurity Awareness & Training PolicyC-AO/POL/CAT/001:2026PolicyCore1.0ACTIVE1 January 2027Policy in force; training completion records current; named owner.CC BY-SA 4.0
29Acceptable Use PolicyC-AO/POL/AUP/001:2026PolicyEssential1.0ACTIVE1 January 2027Policy in force; employee acknowledgements on file; breach register current; named owner.CC BY-SA 4.0
30Business Continuity and Disaster Recovery PolicyC-AO/POL/BCP/001:2026PolicyEssential1.0ACTIVE1 January 2027Policy in force; latest DR exercise outcome on file; BIA current; named owner.CC BY-SA 4.0
31Cryptography and Data Encryption PolicyC-AO/POL/CDE/001:2026PolicyEssential1.0ACTIVE1 January 2027Policy in force; key-management records; algorithm inventory current; named owner.CC BY-SA 4.0
32Human Resources Security PolicyC-AO/POL/HRS/001:2026PolicyEssential1.0ACTIVE1 January 2027Policy in force; onboarding/offboarding evidence collected; named owner.CC BY-SA 4.0
33Incident Response PolicyC-AO/POL/IRP/001:2026PolicyEssential1.0ACTIVE1 January 2027Policy in force; incident log maintained; latest tabletop outcome on file; named owner.CC BY-SA 4.0
34Physical Security PolicyC-AO/POL/PSP/001:2026PolicyEssential1.0ACTIVE1 January 2027Policy in force; physical access logs reviewed; visitor register current; named owner.CC BY-SA 4.0
35Vendor and Third-Party Risk Management PolicyC-AO/POL/VRM/001:2026PolicyEssential1.0ACTIVE1 January 2027Policy in force; vendor assessment register current; tiered risk register; named owner.CC BY-SA 4.0
36IMS LITE MANUALC-AO/MAN/IMS-L/001:2026ManualEssential1.0ACTIVE1 January 2027IMS Manual (Lite) adopted; published internally; accountable owner named.CC BY-NC-ND 4.0
37Essential Information Compliance UniverseC-AO/REF/EICU/001:2026ReferenceEssential1.0ACTIVE1 January 2027Essential ICU mapped to organisation’s compliance stack; review cadence logged.CC BY-NC-ND 4.0
38Information Compliance UniverseC-AO/REF/ICU/001:2026ReferenceEssential1.0ACTIVE1 January 2027ICU mapped to the organisation’s compliance stack; cross-framework register maintained.CC BY-NC-ND 4.0
39OPF LITE FrameworkC-AO/FWK/OPF-L/001:2026FrameworkProfessional1.0ACTIVE1 January 2027OPF (Lite) deployed; policies owned and version-controlled; coverage mapped.CC BY-NC-ND 4.0
40ECF LITE FrameworkC-AO/FWK/ECF-L/001:2026FrameworkProfessional1.0ACTIVE1 January 2027ECF (Lite) deployed; mapping to organisation controls documented.CC BY-NC-ND 4.0
41IMS CORE ManualC-AO/MAN/IMS-C/001:2026ManualProfessional1.0ACTIVE1 January 2027IMS Manual (Core) adopted; operational evidence linked to each control.CC BY-NC-ND 4.0
42ECF CORE FrameworkC-AO/FWK/ECF-C/001:2026FrameworkEnterprise1.0ACTIVE1 January 2027ECF (Core) deployed; control-owner log current; evidence linked per control.Proprietary — CIAO Member Licence

3. Document Access and Use

All Commons through Professional tier documents in the CIAO Standard Document Registry are web-native and freely accessible without download, published under the Creative Commons Attribution-ShareAlike 4.0 International Licence (CC BY-SA 4.0). Enterprise and Conglomerate tier documents are issued under a proprietary licence and are accessible to credentialled members only. Each document may be cited using its unique document reference in the format C-AO/[TYPE]/[CODE]/001:YYYY. Users are encouraged to reference the registry as the single authoritative source for validated, current versions.

4. Review and Update Protocols

All CIAO Standard documents are subject to a scheduled annual review cycle. The Review Date field in the registry table indicates when each document is next due for assessment. Upon review, documents may be reissued at an incremented version number, amended in scope, or withdrawn. Any changes to document status or version are recorded in the Version History section below. The maintained-by field for all documents is www.c-ao.com.

5. Governance Context

The Document Registry sits at the centre of the CIAO Standard governance framework. All registered documents are published under the parent standard C-AO/STD/001:2026. Documents are organised across six membership tiers — Commons, Core, Essential, Professional, Enterprise, and Conglomerate — each tier building cumulatively on the one below. Commons through Professional tier documents are licensed under CC BY-SA 4.0. Enterprise and Conglomerate tier documents are issued under proprietary licence terms. Higher-tier documents reference and extend the policies and frameworks established at lower tiers, forming an integrated and interdependent governance system.

6. Version History Details

Version Date Change Summary Status
1.0 1 January 2026 Inaugural edition — foundational document set published across Commons, Core, Essential, Professional, and Enterprise tiers. Commons through Professional documents issued under CC BY-SA 4.0 licence. Enterprise and Conglomerate documents issued under proprietary licence. ACTIVE

● LIVE CONTENT  ·  Verified 29 May 2026 at 15:31 UTC  ·  Version 1.0  ·  Always current at c-ao.com  ·  © CIAO Standard Secretariat 2026