Membership Guidelines

CIAO COMMONS — GUIDELINES
C-AO/MEM/001:2026 PUBLIC
Membership Guidelines
Membership Tier Guidelines of the CIAO Standard
Date Issued  1 January 2026
Review Date  1 January 2027
Cite as: CIAO Standard. (2026). Membership Guidelines. v1.0. C-AO/MEM/001:2026. www.c-ao.com
🟢 Commons — Visible to all members

CIAO offers six membership tiers, each designed for a specific organisational profile. Every paid tier includes all content from the tiers below it — your compliance infrastructure grows without losing what you have already built.

Use this page to identify where your organisation sits today. Then follow the link to your tier for the full picture.


🔵 Core — Core membership and above
🔒 Core membership required — Core membership required for full Tier Guidelines content.  Login  or become a member →

How to identify your tier

Consider three things: your organisation’s size, your current compliance maturity, and your regulatory exposure. The tier profiles below maps these to the appropriate CIAO tier.


Tier Profiles

COMMONS — Free Your organisation wants to understand CIAO and access foundational compliance resources before committing to a paid tier. You require a structured starting point with no financial barrier. Registration is free and gives you permanent access to the CIAO meta-standard and compliance self-assessment tools.

Suits: Any organisation at any size exploring structured compliance for the first time.


CORE — Entry Compliance Baseline Your organisation has between 1 and 10 people. Compliance is not your primary focus but you are facing external pressure — tenders, cyber insurance requirements, client due diligence, or supply chain assurance requests. You need credible, professionally maintained policies immediately, without internal expertise or consultant costs.

Suits: Start-ups and micro-enterprises requiring an immediate, deployable compliance baseline.


ESSENTIAL — Foundation Governance Your organisation has between 10 and 100 people. You have basic policies in place but no structured governance system. Regulatory exposure is growing as your business footprint expands. A compliance failure at this stage carries serious operational and reputational risk. You need a complete governance foundation — not just documents, but a functioning system.

Suits: Small to medium businesses building their first structured compliance programme.


PROFESSIONAL — Active Compliance Programme Your organisation has between 100 and 1,000 people. A compliance function exists but is managing fragmented frameworks with duplicated effort. Certifications are either held or being pursued. The challenge is maintaining alignment across multiple standards simultaneously without unsustainable internal cost. You need a unified operational system, not a collection of parallel documentation projects.

Suits: Mid-sized organisations with active compliance programmes requiring integrated framework coverage.


ENTERPRISE — Full Governance Suite Your organisation has between 1,000 and 10,000 people. Multi-framework compliance is a permanent operational discipline. Large compliance teams manage multiple annual certification and assurance cycles. The cost of fragmentation, inconsistency, and duplication is measured in audit failures and strategic delays. You need the complete CIAO governance architecture — fully maintained, unlimited users, confidentially protected.

Suits: Large enterprises managing complex, multi-framework compliance at scale.


CONGLOMERATE — Bespoke Compliance Operations Your organisation exceeds 10,000 people, or operates as a holding group or conglomerate spanning multiple subsidiaries, jurisdictions, and regulatory environments. Core membership structures cannot accommodate your compliance architecture. You require a fully integrated, fully managed compliance operation built specifically around your organisation.

Suits: Very large enterprises, holding groups, and conglomerates requiring non-standard, dedicated compliance integration. Also required for CIAO Partners.


Not sure which tier fits? Start with Commons at no cost and use the Compliance Readiness Self-Assessment to identify your organisation’s exact position.

Register for Commons →

⚫ Enterprise & Conglomerate — Implementation artifacts
🔒 Enterprise membership required — Enterprise membership required for implementation artifacts.  Login  or become a member →

Enterprise and Conglomerate implementation content will be added here.

Full tier comparison

A side-by-side comparison of all six CIAO Standard tiers on the dimensions that most commonly determine fit: price, scale of deployment, included content, users, classification, and framework coverage.

CIAO Standard — Canonical tier comparison
 CommonsCoreEssentialProfessionalEnterpriseConglomerate
Price FreeAlways €9per user / year €99per user / year €999per user / year €9,999per org / year From €99,999per year
Maturity target 0 → 2 2 → 3 3 → 4 4 → 5 5+
Organisation size Any organisation exploring the Standard Micro (1–9 employees) SME (10–99) Mid-market (100–999) Large enterprise (1,000–9,999) Group / multi-jurisdiction (10,000–99,999)
Compliance function None or minimal 0–1 non-specialist Up to ~3 non-specialist staff Compliance department of ~5 specialists Large compliance department, specialised disciplines Co-run with CIAO Standard team
Content depth The Standard; Manual previews All CAO Manuals + Operating Policy Frameworks + Sub-Policies & Control Frameworks + Processes, Procedures & Implementation artefacts + Bespoke group-level extensions
Standards mapping Dynamic Selection Engine Dynamic Selection Engine Dynamic Selection Engine Dynamic Selection Engine Dynamic Selection Engine Dynamic Selection Engine + custom portfolio
Self-assessment tools Included Included Included Included Included Included
Users Unlimited (free) Per-user Per-user Per-user Up to 9,999 employees covered Up to 99,999 covered; larger groups quoted bespoke
Minimum term No commitment Annual Annual Annual Annual 3-year minimum cycle
Classification Public Public Public Public Shared Confidential Confidential, bespoke
Legal pre-requisites None None None None NDA required NDA + Data Processing Agreement (DPA)
Dedicated environment Shared platform Shared platform Shared platform Shared platform Dedicated secure environment White-label portal, multi-entity architecture
Partner delivered Self-service Self-service Self-service Self-service Self-service Fully managed partnership
Take action Join Commons Join Core Join Essential Join Professional Join Enterprise Enquire

For details on what each tier unlocks across the canonical artefact ladder, see Standard Architecture & Tier Content Depth.

● LIVE CONTENT  ·  Verified 6 May 2026 at 09:47 UTC  ·  Version 1.0  ·  Always current at c-ao.com  ·  © CIAO Standard Secretariat 2026