Change management for AI systems: ISO 42001 clauses 6.3 and 8.1
A retrained model behaves differently even when no line of code changed. How to control changes to AI systems and to your AI management system, and what evidence an auditor asks for.
Articles, whitepapers and insights into IT audit, information security, compliance and risk management.
A retrained model behaves differently even when no line of code changed. How to control changes to AI systems and to your AI management system, and what evidence an auditor asks for.
When an AI incident happens, the first question is always who was responsible for what. Annex A.10 of ISO 42001 asks you to settle that split in advance, towards suppliers and towards your own customers.
On 11 September 2026 the reporting obligations of the Cyber Resilience Act start to apply. Manufacturers of digital products must report actively exploited vulnerabilities and severe incidents within 24 hours. Includes self-assessment.
More organizations pursue ISO 42001 certification for AI governance. But the practice is tougher than the theory. These are the seven things we encounter.
A SOC 2 report is an attestation rather than a certificate. What the Trust Services Criteria are, what sits in the four parts of the report and what to look for when you receive one.
ISAE 3402 and SOC 2 are often confused, but they answer different questions. The choice comes down to one thing: does your service affect your clients' financial statements, or their security?
Planning your ISO 27001 certification? This step-by-step roadmap covers scoping, risk assessment, implementation and the certification audit itself.
Traditional audits look back. Continuous auditing looks forward. Learn how real-time monitoring and automated testing are transforming IT audit.
Type I assesses the design of your controls at a point in time, Type II also their operation over a period. What does that mean for your clients, your planning and your budget, and when do you skip Type I?
ISAE 3402 is the international standard for assurance reports on controls at service organizations. What does the report contain, how does the audit work, what separates Type I from Type II, and what does an engagement cost?
A scan finds known vulnerabilities; a pentester finds the combinations that are in no database. Differences in depth, cost, reporting and what standards expect.
ISO 9001 provides a solid quality management foundation that integrates naturally with ISO 27001 and other standards. Here is why it matters for IT services.
ISO 22301 provides the framework for business continuity management. From business impact analysis to continuity testing, here is what you need to know.
ISO 27017 adds cloud-specific security controls to your ISO 27001 framework. Learn about shared responsibility, the seven new controls, and practical implementation.
ISO 27018 sets the standard for PII protection in cloud environments. Learn how it connects to GDPR, ISO 27001, and ISO 27017.
ISO 27701 extends ISO 27001 with a Privacy Information Management System. Learn how it supports GDPR compliance and what certification involves.
The eIDAS regulation governs electronic identification and trust services across the EU. With eIDAS 2.0 and the European Digital Identity Wallet on the horizon, understanding this framework is essential.
Internal audits are a mandatory component of every ISO management system. Done well, they drive real improvement. Done poorly, they become a compliance checkbox.
Your first SOC 2 audit does not have to be overwhelming. This practical checklist covers scope definition, control design, gap remediation and evidence collection.
The ISAE 3402 Type II observation period requires a minimum of six months. Learn why this period matters, what auditors test, and how to manage evidence collection.
SaaS providers in the DigiD chain face specific assessment requirements. From network segmentation to multi-tenant challenges, here is what you need to know.
DORA creates new obligations for ICT providers serving financial institutions. Understanding the requirements early turns compliance into a commercial advantage.
Good evidence management can make or break an audit engagement. Learn the fundamentals of audit evidence, common pitfalls, and how to organize evidence efficiently.
The EU AI Act takes full effect for high-risk AI systems in August 2026, with fines up to 35 million euros. How to classify your AI systems, meet compliance requirements, and prepare for conformity assessment.
The Cyber Resilience Act introduces mandatory cybersecurity requirements for all digital products on the EU market. From IoT devices to software: what manufacturers, importers, and distributors need to know.
The transition period to ISO 27001:2022 expired on 31 October 2025. Organizations still certified to the 2013 version need to take action. Here is what changed and how to approach the transition audit.
More organizations combine ISO 27001, ISO 42001, NEN 7510, or ISO 9001 in a single management system. An integrated audit saves time and cost. But how does it work in practice?
The biggest cyberattacks of recent years came through the supply chain: SolarWinds, Kaseya, MOVEit. NIS2 mandates supply chain management. How do you audit the security of your supply chain?
Quantum computers threaten the cryptography that protects virtually all digital communication. NIST has published the first post-quantum standards. What does this mean for your organization?
ISO/IEC 42005:2025 is the first international standard dedicated specifically to conducting AI system impact assessments. It helps organizations map how their AI systems affect individuals, groups, and society in a structured way. Not a certifiable standard, but a practical guide that aligns seamlessly with ISO 42001 and the EU AI Act.
Since 2 February 2025, Article 4 of the EU AI Act requires every organization that uses AI to ensure a sufficient level of AI literacy among its staff. It is the first concrete obligation already in force, and it affects almost every organization. What exactly does the requirement entail and how do you meet it?
Since 2 August 2025, the EU AI Act imposes specific obligations on providers of general-purpose AI models, the models behind tools like GPT, Claude, and Gemini. Transparency, documentation, copyright and, for the most capable models, requirements around systemic risk. What does this mean for those who provide or embed such models?
Two leading frameworks for AI governance: the NIST AI Risk Management Framework and ISO 42001. One is a voluntary risk model with the functions Govern, Map, Measure, and Manage; the other a certifiable management system standard. They do not compete, they complement each other. Here is how to choose and combine them.
Employees use AI tools nobody approved, vendors quietly add AI features, and the organization has no overview. That is shadow AI, and it is the biggest blind spot in any AI governance. A complete AI inventory is the first and indispensable step, whether you are implementing ISO 42001 or preparing for the EU AI Act.
In May 2026 the EU institutions reached an agreement on the Digital Omnibus, the first amendment package to the EU AI Act since its adoption. The obligations for high-risk AI systems shift to December 2027 and August 2028. What changes, what stays, and why is a delay no reason to sit still?
Broken Access Control has topped the OWASP Top 10 for years and produces the most impactful findings in pentests. We explain how we attack it and how to prevent it.
The risk assessment is the foundation of ISO 27001, yet it often stalls in practice. This guide shows how to build a risk assessment that stays usable.
The NIS2 directive introduces strict cybersecurity requirements for Dutch organisations. Read everything about the implementation and your obligations.
DORA has applied directly across the EU since 17 January 2025. The five pillars, exactly who falls in scope, what supervisors ask for, and where implementations stall in practice.
ISO 27001:2022 introduced significant changes. Discover the latest updates and what this means for your information security.
The Normenkader 3.0 consists of 21 norms, five of which are also tested on operating effectiveness. Per norm group: what evidence you need and where it goes wrong.
A strong IT internal control framework is essential for reliable operations. This article guides you through COSO and COBIT.
ISO/IEC 42001 is the first certifiable standard for an AI management system. What the clauses and Annex A domains require, how certification works and how it relates to the EU AI Act.
BIO (Baseline Information Security Government) sets cybersecurity requirements for Dutch government organisations. Learn what this involves.
DNB, AFM and other regulators scrutinise IT risk management closely. Discover what they are looking for.
ISAE 3000 is the broad international assurance standard for non-financial subject matter: from information security and privacy to algorithms and sustainability. How does it relate to ISAE 3402 and SOC 2, and when do you use it?
ScanZeker.nl scans your domain in 30 seconds across twelve security modules. From SSL/TLS and security headers to open ports, data breaches, subdomain takeover and attack paths. Free, without an account and without storing results.
The NIS2 directive is in force and the Dutch implementation act is approaching. Many organisations know they have to do something, but not what. This article describes the concrete steps that organisations must take now to become compliant.
Attackers are using AI to scale up phishing, deepfakes and automated attacks. At the same time, AI offers new defensive capabilities. How do you, as an organisation, navigate this rapidly changing threat landscape?
How do you test the security of your website without being a security expert? From HTTP headers and SSL configuration to email security and DNS. A step-by-step approach for IT managers and business owners.
Logius has once again tightened the ICT security assessment for DigiD. What is changing in 2026 and how do you prepare your organisation?
The EU AI Act is in force and ISO 42001 provides the management system to comply with it. But how do they relate to each other? And where are the gaps?
More and more enterprise customers require a SOC 2 report. But how exactly does the process work, what does it cost, and when do you choose Type I or Type II?
The Cybersecurity Act is the Dutch implementation of the European NIS2 directive. Adopted by the House of Representatives on 15 April 2026, with entry into force on 1 July 2026. This article explains what the law entails, who falls under it and what you need to arrange now.
IT general controls form the foundation beneath almost every IT audit and assurance engagement, from SOC 2 to ISAE 3402. What exactly do ITGC cover, which domains do they span, and why does their quality determine whether an auditor can rely on your automated controls?
SQL injection has been known for over 25 years and is still in the OWASP Top 10. We explain the variants, how we test for it during a web application pentest, and why parameterized queries are the only structural fix.
Weak authentication and poor session management are among the most impactful findings in a web application pentest. We explain the mistakes we encounter, how we test for them and how to prevent them structurally.
Healthcare organizations and their suppliers often wonder whether they need ISO 27001, NEN 7510 or both. We explain the differences and overlap and help you make a choice.
Most AI in organizations is bought, not built. ISO 42001 expects you to control those vendors. This is how to set up practical AI due diligence.
"A human always checks" is the most cited AI control, and often the weakest in practice. This is how to design human oversight that actually works and is auditable.
The AI policy is the anchor of your AI management system and the first document an auditor requests. This is how to write policy that works instead of a paper list of prohibitions.
A chatbot making false commitments or a model that discriminates: AI incidents fit poorly into classic incident management. This is how to get it right.
Poor data leads to poor AI outcomes, and bias is rarely visible in a demo. This is what ISO 42001 and the EU AI Act concretely require of your data governance and bias testing.
ISO 42001 and ISO 23894 both address AI risk, but they do fundamentally different things. One is certifiable, the other is not. This is how to choose the right combination.
AI governance rarely fails on documents and almost always on ownership. This is how to assign roles in an AI management system, from top management to AI system owner.
Without logging you cannot explain an AI decision after the fact, and without transparency nobody knows there was an AI decision at all. Here is what ISO 42001 and the EU AI Act concretely require.
Many organizations think they are ready for their ISO 42001 audit until the auditor starts probing. This readiness checklist shows what really needs to be on the table before the certification audit begins.
An ISO 42001 certificate reflects the moment of the audit, not next year. AI models degrade quietly. Here is what the standard requires after certification, and how to set up monitoring in practice.
DAST scanners and penetration tests both test a running web application, but deliver fundamentally different results. We explain what each finds, what each misses and how to combine them.
Penetration test costs range from a few thousand to tens of thousands of euros. We explain how pricing works, which factors matter most and what to look for in proposals.
Your vendor sends you an eighty-page SOC 2 or ISAE 3402 report. Where do you start? A practical reading guide: the opinion, scope, exceptions, CUECs and subservice organizations.
SOC 2 and ISO 27001 are often mentioned in the same breath, but they are fundamentally different instruments. We line up the differences and show how to combine both tracks without doing the work twice.
Almost every service organization outsources parts of its own operation, from hosting to email delivery. For the assurance report you then face a choice: carve-out or inclusive method. We explain the difference and offer a decision framework.
The cost of a SOC 2 engagement goes well beyond the audit invoice. We break the investment down into preparation, tooling, audit fees and internal hours, and show which choices drive the price.
A bridge letter covers the period between the end of a SOC 2 or ISAE 3402 review period and the reporting date of the user organization. We explain what it contains, what it is and is not worth, and how to prepare one.
The system description is the heart of every SOC 2 and ISAE 3402 report, and the only part management writes itself. We explain what it must contain, how the auditor uses it and which mistakes to avoid.
Customers, regulators and boards increasingly ask for demonstrable control over algorithms and AI. ISAE 3000 offers a mature assurance framework for exactly that. How does algorithm assurance work and when is it worthwhile?
The first SOC 2 year is the hardest. From an overly broad scope to evidence collected only at the end: these are the mistakes we see most often as auditors, and how to avoid them.
Every SOC 2 and ISAE 3402 report contains a statement written by management itself: the management assertion. What exactly do you assert, who signs it, and which mistakes do we see in practice?
Besides SOC 1 and SOC 2 there is a third variant: the SOC 3 report. A publicly shareable report based on the same audit as SOC 2. What does it contain, what does it leave out, and when is it worth it?
The EU AI Act requires providers of generative AI to mark synthetic content in a machine-readable way. But how do you do that technically? A practical guide to C2PA, watermarks and metadata, including their limitations.
On 2 August 2026, Article 50 of the EU AI Act becomes applicable: transparency obligations for chatbots, AI-generated content, deepfakes and emotion recognition. Who must do what, and what has been postponed via the Digital Omnibus?
From 2 August 2026, chatbots and voicebots must be designed so users know they are talking to AI. What Article 50 requires, where the grey areas are, and how to implement the disclosure in practice.
From 2 August 2026, organizations publishing deepfakes or AI-generated media must disclose it. When does content qualify as a deepfake, who must label it, and how do you do it without spoiling your content?
On 2 August 2026 the transparency obligations of Article 50 EU AI Act apply. Use this checklist to verify readiness: from AI inventory to chatbot disclosure, content labels and vendor contracts.
The pentest report is in. Now what? How to prioritize findings, fix root causes instead of patching symptoms, and what a retest delivers for your security and your audit evidence.
Every SOC 2 and ISAE 3402 report contains a list of controls the service organization assumes you have implemented as a customer: the complementary user entity controls. Ignore that list and you are leaning on assurance that is not there.
Article 5 of the EU AI Act bans eight AI practices and has applied since 2 February 2025, carrying the highest fines in the regulation. Two of the bans directly affect HR and marketing tooling that ordinary companies buy today.
ISO 42001 contains two assessments that are often confused: the AI risk assessment (clause 6.1.2) and the AI system impact assessment (clause 6.1.4). What is the difference, and how do you set up both properly?
The scope of your AI management system determines which AI systems, departments and life cycle stages fall under your certification. What do you include, what may you exclude and where does it go wrong?
ISO 42001 requires a Statement of Applicability covering all 38 Annex A controls. What goes in it, how do you justify exclusions and which mistakes do we see most often?
Where do ISO 42001 audits usually go wrong? An overview of the nonconformities auditors record most often, organized by chapter of the standard, with tips on preventing each one.
Article 27 of the EU AI Act requires certain deployers of high-risk AI to carry out a fundamental rights impact assessment (FRIA) before first use. Who does this apply to, what are the six required elements and how does the FRIA relate to your DPIA?
ISO 42001 requires documented information in dozens of places. This overview walks through the documents a certification auditor wants to see for each clause, from context analysis to nonconformity register.
Annex A.6 of ISO 42001 follows an AI system from design objectives to production logging. Stage by stage: what the controls require, what evidence an auditor expects and where things go wrong in practice.
Finding a nonconformity is step one. Clause 10.2 of ISO 42001 requires correction, root cause analysis, corrective actions and verification of effectiveness. Here is how to set up that process for AI.
Who performs your AI risk assessments, and what shows they are able to? Clauses 7.2 and 7.3 of ISO 42001 set requirements for competence and awareness. Here is how to meet them, including the link with AI literacy under the EU AI Act.
Most organisations do not build AI, they use it. For anyone operating a high-risk AI system, Article 26 of the EU AI Act contains its own list of obligations: human oversight, monitoring, logging and information duties. An overview per paragraph.
Fines up to 35 million euros or 7% of worldwide turnover: the numbers from the EU AI Act make every slide deck. How the penalty regime of Article 99 actually works is less well known. The three tiers, the SME rule, the factors that set the amount and the question of who enforces.
Which data does your AI system run on, which tooling was it built with and who can maintain it? Annex A.4 of ISO 42001 requires documentation of all resources per AI system. This is what belongs in it, including the nonconformities auditors see most often.
The first SOC 2 report is in, and then the question comes: what now? SOC 2 is an annual cycle. How to make observation periods connect, what changes in year two and the mistakes organizations make most often after their first report.
Who may use an AI system, for what purpose, and what happens when someone steps outside those boundaries? Annex A.9 of ISO 42001 sets three requirements for the use of AI systems. What an auditor expects and which nonconformities come up most often.
Anyone who works with your AI systems or is affected by them needs to know where they stand. Annex A.8 of ISO 42001 sets four requirements for documentation, reporting channels and communication. What an auditor expects per control and the most common nonconformities.
Cross-site scripting remains one of the most frequently reported vulnerabilities in web application pentests. What distinguishes reflected, stored and DOM-based XSS, how a pentester hunts for it and which measures actually solve the problem.
An AI system is only as reliable as the data it runs on. Annex A.7 of ISO 42001 therefore sets requirements for data management, acquisition, quality, provenance and preparation. For each control: what an auditor expects and which deviations we see most often.
Clause 9.2 of ISO 42001 requires internal audits and an audit programme that drives them. How to set that up, what an auditor actually tests, and the nonconformities we see most often.
Clause 9.3 of ISO 42001 is fairly precise about what has to be on the table at the management review and what has to come out of it. A practical take on inputs, outputs and frequency.
Get our latest articles and insights on IT audit, compliance and information security.