ISO/IEC 42001: what an AI management system actually requires
The first certifiable AI management system standard, read the way an auditor reads it: what you have to build, and what you will be asked to evidence.
Notes from the audit floor: what standards actually require, where implementations usually fail, and what changed in the frameworks you have to answer to.
Featured
The first certifiable AI management system standard, read the way an auditor reads it: what you have to build, and what you will be asked to evidence.
Most SoAs are written to be filed, not read. Here is what a lead auditor checks first, and the three inconsistencies that show up almost every time.
Scope statements are where supplier assurance quietly falls apart. A short guide to reading one properly before you accept it as evidence.
Browse
Six streams, each written by someone who works in it. New articles publish as they are written, we would rather post six good pieces a year than a weekly filler.
Controls that work, controls that only look like they work, and the incidents that tell the difference.
Clause-level readings of ISO/IEC 27001, ISO 9001, ISO 22301 and the transitions between editions.
ISO/IEC 42001, AI impact assessment, and what regulators are converging on across jurisdictions.
Governance, risk and compliance as a working discipline rather than a spreadsheet nobody opens.
ISO/IEC 27701, India's DPDP Act, GDPR, and the gap between a privacy policy and a privacy programme.
Technique: sampling, evidence, writing findings that hold, and closing meetings that do not turn into negotiations.