Blog
Implementing ISO 42001: example audit report
In our previous article on the AI Risk Management System, we explained how an AIMS can help organizations structure AI governance and support compliance efforts with the AI Act. Here we introduce our new template for auditing and structuring your AIMS and prepare for ISO 42001 certification. What is the AIMS? ISO 42001 requires organizations…
Pavlo Burda
The AI Act Risk Management System
In this article we explain what an AI Risk Management System (RMS) is, and why it is required by the AI Act for high-risk AI systems. We outline the components of the AI RMS and how you can potentially leverage, for example, your existing ISO 27001 work for ISO 42001 compliance. The AI Act:…
Pieter t Hoen
The ISO 27001 Harmonized Structure
In this article, we walk through the Harmonized Structure of the ISO 27001 (Chapters 4-10) and explain how to implement it using the Plan-Do-Check-Act (PDCA) cycle. This will be the basis for your Information Security Management System (ISMS) according to the standard. The “engine” of the ISMS: Chapters 4 to 10 ISO 27001 is structured…
Pavlo Burda
HCAI-ep 2026: Human-Centered AI in Practice
The Human-Centered AI Education & Practice (HCAI-ep) conference focuses on how to design and evaluate AI systems that remain aligned with human values and real-world constraints. This is exactly where many organisations struggle today, especially in light of emerging regulation such as the EU AI Act. At HCAI-ep, we presented our work on fairness requirements…
Pavlo Burda
What documentation do you need for ISO 27001?
If you want an external auditor to certify your information security management system, you need to store documentation of for all elements in your policy. To make audits to go swiftly and smoothly, you should store all documented information in one easy-to-access place. In this post we provide an overview of what information needs to be stored and…
Sieuwert van Otterloo
