Knowledge Base

Articles, whitepapers and insights into IT audit, information security, compliance and risk management.

IT-audit8 min read

Change management for AI systems: ISO 42001 clauses 6.3 and 8.1

A retrained model behaves differently even when no line of code changed. How to control changes to AI systems and to your AI management system, and what evidence an auditor asks for.

By Kees van der Vlies
Read more
Compliance8 min read

Who is responsible for what in the AI value chain? ISO 42001 Annex A.10

When an AI incident happens, the first question is always who was responsible for what. Annex A.10 of ISO 42001 asks you to settle that split in advance, towards suppliers and towards your own customers.

By Kees van der Vlies
Read more
Security9 min read

CRA reporting obligations from 11 September 2026: what you need in place before that date

On 11 September 2026 the reporting obligations of the Cyber Resilience Act start to apply. Manufacturers of digital products must report actively exploited vulnerabilities and severe incidents within 24 hours. Includes self-assessment.

By Kees van der Vlies
Read more
Compliance7 min read

ISO 42001 certification: 7 lessons from the field

More organizations pursue ISO 42001 certification for AI governance. But the practice is tougher than the theory. These are the seven things we encounter.

By Kees van der Vlies
Read more
IT-audit9 min read

SOC 2 explained: what is in the report and how to read it

A SOC 2 report is an attestation rather than a certificate. What the Trust Services Criteria are, what sits in the four parts of the report and what to look for when you receive one.

By Kees van der Vlies
Read more
IT-audit8 min read

ISAE 3402 or SOC 2: which report does your organization need?

ISAE 3402 and SOC 2 are often confused, but they answer different questions. The choice comes down to one thing: does your service affect your clients' financial statements, or their security?

By Kees van der Vlies
Read more
Security8 min read

ISO 27001 certification: a practical roadmap

Planning your ISO 27001 certification? This step-by-step roadmap covers scoping, risk assessment, implementation and the certification audit itself.

By Kees van der Vlies
Read more
IT-audit6 min read

Continuous auditing: real-time assurance for modern organizations

Traditional audits look back. Continuous auditing looks forward. Learn how real-time monitoring and automated testing are transforming IT audit.

By Kees van der Vlies
Read more
IT-audit7 min read

SOC 2 Type I or Type II: the difference, the cost and the right order

Type I assesses the design of your controls at a point in time, Type II also their operation over a period. What does that mean for your clients, your planning and your budget, and when do you skip Type I?

By Kees van der Vlies
Read more
IT-audit11 min read

What is ISAE 3402? The report, the audit and Type I vs Type II explained

ISAE 3402 is the international standard for assurance reports on controls at service organizations. What does the report contain, how does the audit work, what separates Type I from Type II, and what does an engagement cost?

By Kees van der Vlies
Read more
Security10 min read

Penetration test or vulnerability scan: what is the difference and when to use which

A scan finds known vulnerabilities; a pentester finds the combinations that are in no database. Differences in depth, cost, reporting and what standards expect.

By Kees van der Vlies
Read more
Compliance7 min read

ISO 9001 quality management for IT service providers

ISO 9001 provides a solid quality management foundation that integrates naturally with ISO 27001 and other standards. Here is why it matters for IT services.

By Kees van der Vlies
Read more
Compliance7 min read

ISO 22301 business continuity: building organizational resilience

ISO 22301 provides the framework for business continuity management. From business impact analysis to continuity testing, here is what you need to know.

By Kees van der Vlies
Read more
Security6 min read

ISO 27017: cloud security controls beyond ISO 27001

ISO 27017 adds cloud-specific security controls to your ISO 27001 framework. Learn about shared responsibility, the seven new controls, and practical implementation.

By Kees van der Vlies
Read more
Compliance6 min read

ISO 27018: protecting personal data in the public cloud

ISO 27018 sets the standard for PII protection in cloud environments. Learn how it connects to GDPR, ISO 27001, and ISO 27017.

By Kees van der Vlies
Read more
Compliance7 min read

ISO 27701: bridging information security and privacy management

ISO 27701 extends ISO 27001 with a Privacy Information Management System. Learn how it supports GDPR compliance and what certification involves.

By Kees van der Vlies
Read more
Compliance8 min read

eIDAS regulation: electronic identification and trust services explained

The eIDAS regulation governs electronic identification and trust services across the EU. With eIDAS 2.0 and the European Digital Identity Wallet on the horizon, understanding this framework is essential.

By Kees van der Vlies
Read more
IT-audit8 min read

Internal audits for ISO certification: requirements and best practices

Internal audits are a mandatory component of every ISO management system. Done well, they drive real improvement. Done poorly, they become a compliance checkbox.

By Kees van der Vlies
Read more
IT-audit7 min read

Preparing for your first SOC 2 audit: a practical checklist

Your first SOC 2 audit does not have to be overwhelming. This practical checklist covers scope definition, control design, gap remediation and evidence collection.

By Kees van der Vlies
Read more
IT-audit8 min read

ISAE 3402 Type II: understanding the observation period

The ISAE 3402 Type II observation period requires a minimum of six months. Learn why this period matters, what auditors test, and how to manage evidence collection.

By Kees van der Vlies
Read more
IT-audit7 min read

DigiD assessment for SaaS providers: scope and requirements

SaaS providers in the DigiD chain face specific assessment requirements. From network segmentation to multi-tenant challenges, here is what you need to know.

By Kees van der Vlies
Read more
Compliance8 min read

DORA compliance for ICT providers: obligations and opportunities

DORA creates new obligations for ICT providers serving financial institutions. Understanding the requirements early turns compliance into a commercial advantage.

By Kees van der Vlies
Read more
IT-audit7 min read

IT audit evidence management: from chaos to control

Good evidence management can make or break an audit engagement. Learn the fundamentals of audit evidence, common pitfalls, and how to organize evidence efficiently.

By Kees van der Vlies
Read more
Compliance9 min read

EU AI Act 2026: high-risk AI classification and conformity assessment guide

The EU AI Act takes full effect for high-risk AI systems in August 2026, with fines up to 35 million euros. How to classify your AI systems, meet compliance requirements, and prepare for conformity assessment.

By Kees van der Vlies
Read more
Security8 min read

Cyber Resilience Act (CRA): cybersecurity requirements for digital products

The Cyber Resilience Act introduces mandatory cybersecurity requirements for all digital products on the EU market. From IoT devices to software: what manufacturers, importers, and distributors need to know.

By Kees van der Vlies
Read more
Compliance8 min read

ISO 27001:2022 transition: what if you are still on the 2013 version?

The transition period to ISO 27001:2022 expired on 31 October 2025. Organizations still certified to the 2013 version need to take action. Here is what changed and how to approach the transition audit.

By Kees van der Vlies
Read more
IT-audit7 min read

Integrated audits: multiple ISO standards in one engagement

More organizations combine ISO 27001, ISO 42001, NEN 7510, or ISO 9001 in a single management system. An integrated audit saves time and cost. But how does it work in practice?

By Kees van der Vlies
Read more
Security8 min read

Supply chain security: auditing and improving your vendor ecosystem

The biggest cyberattacks of recent years came through the supply chain: SolarWinds, Kaseya, MOVEit. NIS2 mandates supply chain management. How do you audit the security of your supply chain?

By Kees van der Vlies
Read more
Security8 min read

Post-quantum cryptography: preparing for the quantum threat

Quantum computers threaten the cryptography that protects virtually all digital communication. NIST has published the first post-quantum standards. What does this mean for your organization?

By Kees van der Vlies
Read more
Compliance7 min read

ISO 42005: the new standard for AI impact assessments

ISO/IEC 42005:2025 is the first international standard dedicated specifically to conducting AI system impact assessments. It helps organizations map how their AI systems affect individuals, groups, and society in a structured way. Not a certifiable standard, but a practical guide that aligns seamlessly with ISO 42001 and the EU AI Act.

By Kees van der Vlies
Read more
Compliance6 min read

AI literacy: the obligation under Article 4 of the EU AI Act

Since 2 February 2025, Article 4 of the EU AI Act requires every organization that uses AI to ensure a sufficient level of AI literacy among its staff. It is the first concrete obligation already in force, and it affects almost every organization. What exactly does the requirement entail and how do you meet it?

By Kees van der Vlies
Read more
Compliance7 min read

GPAI: obligations for general-purpose AI models under the EU AI Act

Since 2 August 2025, the EU AI Act imposes specific obligations on providers of general-purpose AI models, the models behind tools like GPT, Claude, and Gemini. Transparency, documentation, copyright and, for the most capable models, requirements around systemic risk. What does this mean for those who provide or embed such models?

By Kees van der Vlies
Read more
Risk7 min read

NIST AI RMF vs ISO 42001: which framework for AI governance?

Two leading frameworks for AI governance: the NIST AI Risk Management Framework and ISO 42001. One is a voluntary risk model with the functions Govern, Map, Measure, and Manage; the other a certifiable management system standard. They do not compete, they complement each other. Here is how to choose and combine them.

By Kees van der Vlies
Read more
Compliance6 min read

Shadow AI: why an AI inventory is the foundation of AI governance

Employees use AI tools nobody approved, vendors quietly add AI features, and the organization has no overview. That is shadow AI, and it is the biggest blind spot in any AI governance. A complete AI inventory is the first and indispensable step, whether you are implementing ISO 42001 or preparing for the EU AI Act.

By Kees van der Vlies
Read more
Compliance6 min read

EU AI Act delayed: the Digital Omnibus and the new deadlines for high-risk AI

In May 2026 the EU institutions reached an agreement on the Digital Omnibus, the first amendment package to the EU AI Act since its adoption. The obligations for high-risk AI systems shift to December 2027 and August 2028. What changes, what stays, and why is a delay no reason to sit still?

By Kees van der Vlies
Read more
Security9 min read

Broken Access Control: why it remains OWASP number one

Broken Access Control has topped the OWASP Top 10 for years and produces the most impactful findings in pentests. We explain how we attack it and how to prevent it.

By Kees van der Vlies
Read more
Risk8 min read

Information security risk assessment: a practical step-by-step guide

The risk assessment is the foundation of ISO 27001, yet it often stalls in practice. This guide shows how to build a risk assessment that stays usable.

By Kees van der Vlies
Read more
Compliance7 min read

NIS2 directive

The NIS2 directive introduces strict cybersecurity requirements for Dutch organisations. Read everything about the implementation and your obligations.

By Kees van der Vlies
Read more
Compliance9 min read

DORA: what the regulation requires of financial institutions

DORA has applied directly across the EU since 17 January 2025. The five pillars, exactly who falls in scope, what supervisors ask for, and where implementations stall in practice.

By Kees van der Vlies
Read more
Security6 min read

ISO 27001:2022 update

ISO 27001:2022 introduced significant changes. Discover the latest updates and what this means for your information security.

By Kees van der Vlies
Read more
IT-audit10 min read

DigiD assessment checklist: the 21 norms and what you need ready for each

The Normenkader 3.0 consists of 21 norms, five of which are also tested on operating effectiveness. Per norm group: what evidence you need and where it goes wrong.

By Kees van der Vlies
Read more
Risk7 min read

How do you build an effective IT internal control framework?

A strong IT internal control framework is essential for reliable operations. This article guides you through COSO and COBIT.

By Kees van der Vlies
Read more
Compliance10 min read

ISO 42001 explained: the AI management system from standard to certificate

ISO/IEC 42001 is the first certifiable standard for an AI management system. What the clauses and Annex A domains require, how certification works and how it relates to the EU AI Act.

By Kees van der Vlies
Read more
Security5 min read

BIO: information security in government

BIO (Baseline Information Security Government) sets cybersecurity requirements for Dutch government organisations. Learn what this involves.

By Kees van der Vlies
Read more
Risk6 min read

IT risk management under the scrutiny of regulators

DNB, AFM and other regulators scrutinise IT risk management closely. Discover what they are looking for.

By Kees van der Vlies
Read more
IT-audit8 min read

ISAE 3000: the standard for assurance on everything except the financial statements

ISAE 3000 is the broad international assurance standard for non-financial subject matter: from information security and privacy to algorithms and sustainability. How does it relate to ISAE 3402 and SOC 2, and when do you use it?

By Kees van der Vlies
Read more
Security8 min read

ScanZeker.nl: a free security scan for your domain

ScanZeker.nl scans your domain in 30 seconds across twelve security modules. From SSL/TLS and security headers to open ports, data breaches, subdomain takeover and attack paths. Free, without an account and without storing results.

By Kees van der Vlies
Read more
Compliance8 min read

NIS2 compliance in 2026: what do you need to do now, concretely?

The NIS2 directive is in force and the Dutch implementation act is approaching. Many organisations know they have to do something, but not what. This article describes the concrete steps that organisations must take now to become compliant.

By Kees van der Vlies
Read more
Security7 min read

AI-driven cyber threats in 2026: what every organisation needs to know

Attackers are using AI to scale up phishing, deepfakes and automated attacks. At the same time, AI offers new defensive capabilities. How do you, as an organisation, navigate this rapidly changing threat landscape?

By Kees van der Vlies
Read more
Security8 min read

Testing domain security: a practical guide

How do you test the security of your website without being a security expert? From HTTP headers and SSL configuration to email security and DNS. A step-by-step approach for IT managers and business owners.

By Kees van der Vlies
Read more
IT-audit8 min read

DigiD assessment 2026: these are the new requirements

Logius has once again tightened the ICT security assessment for DigiD. What is changing in 2026 and how do you prepare your organisation?

By Kees van der Vlies
Read more
Compliance9 min read

ISO 42001 and the EU AI Act: how they connect and why you need both

The EU AI Act is in force and ISO 42001 provides the management system to comply with it. But how do they relate to each other? And where are the gaps?

By Kees van der Vlies
Read more
IT-audit10 min read

SOC 2 for SaaS companies: from first question to report

More and more enterprise customers require a SOC 2 report. But how exactly does the process work, what does it cost, and when do you choose Type I or Type II?

By Kees van der Vlies
Read more
Compliance9 min read

The Cybersecurity Act (Cbw): what does the Dutch NIS2 law mean for your organisation?

The Cybersecurity Act is the Dutch implementation of the European NIS2 directive. Adopted by the House of Representatives on 15 April 2026, with entry into force on 1 July 2026. This article explains what the law entails, who falls under it and what you need to arrange now.

By Kees van der Vlies
Read more
IT-audit8 min read

IT general controls (ITGC): what they are and why auditors focus on them

IT general controls form the foundation beneath almost every IT audit and assurance engagement, from SOC 2 to ISAE 3402. What exactly do ITGC cover, which domains do they span, and why does their quality determine whether an auditor can rely on your automated controls?

By Kees van der Vlies
Read more
Security8 min read

SQL injection: how pentesters find it and how you prevent it

SQL injection has been known for over 25 years and is still in the OWASP Top 10. We explain the variants, how we test for it during a web application pentest, and why parameterized queries are the only structural fix.

By Kees van der Vlies
Read more
Security8 min read

Broken authentication: testing authentication and session weaknesses in a pentest

Weak authentication and poor session management are among the most impactful findings in a web application pentest. We explain the mistakes we encounter, how we test for them and how to prevent them structurally.

By Kees van der Vlies
Read more
Compliance8 min read

ISO 27001 vs NEN 7510: what is the difference and what do you need?

Healthcare organizations and their suppliers often wonder whether they need ISO 27001, NEN 7510 or both. We explain the differences and overlap and help you make a choice.

By Kees van der Vlies
Read more
Compliance9 min read

AI vendor assessment under ISO 42001: due diligence on the AI you buy

Most AI in organizations is bought, not built. ISO 42001 expects you to control those vendors. This is how to set up practical AI due diligence.

By Kees van der Vlies
Read more
Compliance8 min read

Human oversight of AI: making human-in-the-loop work under ISO 42001 and the EU AI Act

"A human always checks" is the most cited AI control, and often the weakest in practice. This is how to design human oversight that actually works and is auditable.

By Kees van der Vlies
Read more
Compliance8 min read

Writing an AI policy that meets ISO 42001: step-by-step plan and checklist

The AI policy is the anchor of your AI management system and the first document an auditor requests. This is how to write policy that works instead of a paper list of prohibitions.

By Kees van der Vlies
Read more
Compliance9 min read

AI incident management under ISO 42001 and the EU AI Act: from detection to reporting duty

A chatbot making false commitments or a model that discriminates: AI incidents fit poorly into classic incident management. This is how to get it right.

By Kees van der Vlies
Read more
Compliance9 min read

Bias and data governance under ISO 42001: what auditors expect

Poor data leads to poor AI outcomes, and bias is rarely visible in a demo. This is what ISO 42001 and the EU AI Act concretely require of your data governance and bias testing.

By Kees van der Vlies
Read more
Compliance8 min read

ISO 42001 vs ISO 23894: which standard do you need for AI risk management?

ISO 42001 and ISO 23894 both address AI risk, but they do fundamentally different things. One is certifiable, the other is not. This is how to choose the right combination.

By Kees van der Vlies
Read more
Compliance9 min read

Roles and responsibilities in an AIMS: who does what under ISO 42001?

AI governance rarely fails on documents and almost always on ownership. This is how to assign roles in an AI management system, from top management to AI system owner.

By Kees van der Vlies
Read more
Compliance9 min read

Transparency and logging for AI systems: what ISO 42001 and the EU AI Act require

Without logging you cannot explain an AI decision after the fact, and without transparency nobody knows there was an AI decision at all. Here is what ISO 42001 and the EU AI Act concretely require.

By Kees van der Vlies
Read more
Compliance9 min read

AI audit readiness: are you ready for the ISO 42001 certification audit? (checklist)

Many organizations think they are ready for their ISO 42001 audit until the auditor starts probing. This readiness checklist shows what really needs to be on the table before the certification audit begins.

By Kees van der Vlies
Read more
Compliance9 min read

Monitoring AI models after certification: drift, performance and what ISO 42001 requires

An ISO 42001 certificate reflects the moment of the audit, not next year. AI models degrade quietly. Here is what the standard requires after certification, and how to set up monitoring in practice.

By Kees van der Vlies
Read more
Security9 min read

DAST vs pentest: what is the difference and when do you choose which?

DAST scanners and penetration tests both test a running web application, but deliver fundamentally different results. We explain what each finds, what each misses and how to combine them.

By Kees van der Vlies
Read more
Security9 min read

How much does a penetration test cost? Price indication, factors and common mistakes

Penetration test costs range from a few thousand to tens of thousands of euros. We explain how pricing works, which factors matter most and what to look for in proposals.

By Kees van der Vlies
Read more
IT-audit9 min read

How to read and assess a SOC 2 or ISAE report as a customer

Your vendor sends you an eighty-page SOC 2 or ISAE 3402 report. Where do you start? A practical reading guide: the opinion, scope, exceptions, CUECs and subservice organizations.

By Kees van der Vlies
Read more
IT-audit9 min read

SOC 2 vs ISO 27001: the difference and when to combine them

SOC 2 and ISO 27001 are often mentioned in the same breath, but they are fundamentally different instruments. We line up the differences and show how to combine both tracks without doing the work twice.

By Kees van der Vlies
Read more
IT-audit8 min read

Carve-out vs inclusive method: subservice organizations in your SOC 2 or ISAE 3402 report

Almost every service organization outsources parts of its own operation, from hosting to email delivery. For the assurance report you then face a choice: carve-out or inclusive method. We explain the difference and offer a decision framework.

By Kees van der Vlies
Read more
IT-audit8 min read

How much does SOC 2 cost? Cost breakdown, pricing factors and saving tips

The cost of a SOC 2 engagement goes well beyond the audit invoice. We break the investment down into preparation, tooling, audit fees and internal hours, and show which choices drive the price.

By Kees van der Vlies
Read more
IT-audit7 min read

Bridge letters for SOC 2 and ISAE 3402: what they are, who issues them and when you need one

A bridge letter covers the period between the end of a SOC 2 or ISAE 3402 review period and the reporting date of the user organization. We explain what it contains, what it is and is not worth, and how to prepare one.

By Kees van der Vlies
Read more
IT-audit8 min read

Writing the system description for SOC 2 and ISAE 3402: structure, pitfalls and practical tips

The system description is the heart of every SOC 2 and ISAE 3402 report, and the only part management writes itself. We explain what it must contain, how the auditor uses it and which mistakes to avoid.

By Kees van der Vlies
Read more
IT-audit8 min read

Algorithm assurance under ISAE 3000: independent assurance over AI and algorithms

Customers, regulators and boards increasingly ask for demonstrable control over algorithms and AI. ISAE 3000 offers a mature assurance framework for exactly that. How does algorithm assurance work and when is it worthwhile?

By Kees van der Vlies
Read more
IT-audit8 min read

Common mistakes in your first SOC 2 year (and how to avoid them)

The first SOC 2 year is the hardest. From an overly broad scope to evidence collected only at the end: these are the mistakes we see most often as auditors, and how to avoid them.

By Kees van der Vlies
Read more
IT-audit7 min read

The management assertion in SOC 2 and ISAE 3402: what it is and how to write it

Every SOC 2 and ISAE 3402 report contains a statement written by management itself: the management assertion. What exactly do you assert, who signs it, and which mistakes do we see in practice?

By Kees van der Vlies
Read more
IT-audit6 min read

SOC 3 report: what is it, and when is it useful?

Besides SOC 1 and SOC 2 there is a third variant: the SOC 3 report. A publicly shareable report based on the same audit as SOC 2. What does it contain, what does it leave out, and when is it worth it?

By Kees van der Vlies
Read more
Compliance7 min read

Marking AI-generated content: how it works in practice (C2PA, watermarks, metadata)

The EU AI Act requires providers of generative AI to mark synthetic content in a machine-readable way. But how do you do that technically? A practical guide to C2PA, watermarks and metadata, including their limitations.

By Kees van der Vlies
Read more
Compliance7 min read

EU AI Act Article 50: which transparency obligations apply from 2 August 2026?

On 2 August 2026, Article 50 of the EU AI Act becomes applicable: transparency obligations for chatbots, AI-generated content, deepfakes and emotion recognition. Who must do what, and what has been postponed via the Digital Omnibus?

By Kees van der Vlies
Read more
Compliance8 min read

Chatbot transparency under the EU AI Act: meeting Article 50 from 2 August 2026

From 2 August 2026, chatbots and voicebots must be designed so users know they are talking to AI. What Article 50 requires, where the grey areas are, and how to implement the disclosure in practice.

By Kees van der Vlies
Read more
Compliance8 min read

Labelling deepfakes and synthetic media: what the EU AI Act requires from your organization

From 2 August 2026, organizations publishing deepfakes or AI-generated media must disclose it. When does content qualify as a deepfake, who must label it, and how do you do it without spoiling your content?

By Kees van der Vlies
Read more
Compliance8 min read

Checklist: is your organization ready for Article 50 of the EU AI Act on 2 August 2026?

On 2 August 2026 the transparency obligations of Article 50 EU AI Act apply. Use this checklist to verify readiness: from AI inventory to chatbot disclosure, content labels and vendor contracts.

By Kees van der Vlies
Read more
Security8 min read

After the pentest: prioritizing findings, fixing root causes and making the retest count

The pentest report is in. Now what? How to prioritize findings, fix root causes instead of patching symptoms, and what a retest delivers for your security and your audit evidence.

By Kees van der Vlies
Read more
IT-audit7 min read

Complementary user entity controls in SOC 2 and ISAE 3402: your share of the work

Every SOC 2 and ISAE 3402 report contains a list of controls the service organization assumes you have implemented as a customer: the complementary user entity controls. Ignore that list and you are leaning on assurance that is not there.

By Kees van der Vlies
Read more
Compliance8 min read

Prohibited AI practices under Article 5 of the EU AI Act: what has been banned since February 2025?

Article 5 of the EU AI Act bans eight AI practices and has applied since 2 February 2025, carrying the highest fines in the regulation. Two of the bans directly affect HR and marketing tooling that ordinary companies buy today.

By Kees van der Vlies
Read more
Compliance8 min read

AI risk assessment versus AI system impact assessment: the difference between 6.1.2 and 6.1.4

ISO 42001 contains two assessments that are often confused: the AI risk assessment (clause 6.1.2) and the AI system impact assessment (clause 6.1.4). What is the difference, and how do you set up both properly?

By Kees van der Vlies
Read more
Compliance8 min read

Determining the scope of your AIMS: ISO 42001 clause 4.3 in practice

The scope of your AI management system determines which AI systems, departments and life cycle stages fall under your certification. What do you include, what may you exclude and where does it go wrong?

By Kees van der Vlies
Read more
Compliance8 min read

Statement of Applicability for ISO 42001: how to draw it up

ISO 42001 requires a Statement of Applicability covering all 38 Annex A controls. What goes in it, how do you justify exclusions and which mistakes do we see most often?

By Kees van der Vlies
Read more
Compliance9 min read

Common nonconformities in ISO 42001 audits, chapter by chapter

Where do ISO 42001 audits usually go wrong? An overview of the nonconformities auditors record most often, organized by chapter of the standard, with tips on preventing each one.

By Kees van der Vlies
Read more
Compliance9 min read

The FRIA under the EU AI Act: who must carry out a fundamental rights impact assessment and what goes into it?

Article 27 of the EU AI Act requires certain deployers of high-risk AI to carry out a fundamental rights impact assessment (FRIA) before first use. Who does this apply to, what are the six required elements and how does the FRIA relate to your DPIA?

By Kees van der Vlies
Read more
Compliance9 min read

Which documents does an ISO 42001 auditor expect? A checklist per clause

ISO 42001 requires documented information in dozens of places. This overview walks through the documents a certification auditor wants to see for each clause, from context analysis to nonconformity register.

By Kees van der Vlies
Read more
Compliance10 min read

The AI system life cycle in ISO 42001: what Annex A.6 asks of you at each stage

Annex A.6 of ISO 42001 follows an AI system from design objectives to production logging. Stage by stage: what the controls require, what evidence an auditor expects and where things go wrong in practice.

By Kees van der Vlies
Read more
Compliance8 min read

Corrective actions in the AIMS: how to set up clause 10.2 of ISO 42001

Finding a nonconformity is step one. Clause 10.2 of ISO 42001 requires correction, root cause analysis, corrective actions and verification of effectiveness. Here is how to set up that process for AI.

By Kees van der Vlies
Read more
Compliance8 min read

Competence and awareness in the AIMS: meeting clauses 7.2 and 7.3 of ISO 42001

Who performs your AI risk assessments, and what shows they are able to? Clauses 7.2 and 7.3 of ISO 42001 set requirements for competence and awareness. Here is how to meet them, including the link with AI literacy under the EU AI Act.

By Kees van der Vlies
Read more
Compliance9 min read

Article 26 EU AI Act: the obligations for deployers of high-risk AI explained

Most organisations do not build AI, they use it. For anyone operating a high-risk AI system, Article 26 of the EU AI Act contains its own list of obligations: human oversight, monitoring, logging and information duties. An overview per paragraph.

By Kees van der Vlies
Read more
Compliance8 min read

Fines under the EU AI Act: how Article 99 works, who enforces it and what applies today

Fines up to 35 million euros or 7% of worldwide turnover: the numbers from the EU AI Act make every slide deck. How the penalty regime of Article 99 actually works is less well known. The three tiers, the SME rule, the factors that set the amount and the question of who enforces.

By Kees van der Vlies
Read more
Compliance8 min read

Resources for AI systems: what Annex A.4 of ISO 42001 requires and how to document it

Which data does your AI system run on, which tooling was it built with and who can maintain it? Annex A.4 of ISO 42001 requires documentation of all resources per AI system. This is what belongs in it, including the nonconformities auditors see most often.

By Kees van der Vlies
Read more
IT-audit8 min read

After your first SOC 2 report: setting up the annual audit cycle

The first SOC 2 report is in, and then the question comes: what now? SOC 2 is an annual cycle. How to make observation periods connect, what changes in year two and the mistakes organizations make most often after their first report.

By Kees van der Vlies
Read more
Compliance8 min read

Responsible use of AI systems: what Annex A.9 of ISO 42001 requires

Who may use an AI system, for what purpose, and what happens when someone steps outside those boundaries? Annex A.9 of ISO 42001 sets three requirements for the use of AI systems. What an auditor expects and which nonconformities come up most often.

By Kees van der Vlies
Read more
Compliance8 min read

Information for interested parties: what Annex A.8 of ISO 42001 requires

Anyone who works with your AI systems or is affected by them needs to know where they stand. Annex A.8 of ISO 42001 sets four requirements for documentation, reporting channels and communication. What an auditor expects per control and the most common nonconformities.

By Kees van der Vlies
Read more
Security8 min read

Cross-site scripting (XSS): how pentesters find it and how you prevent it

Cross-site scripting remains one of the most frequently reported vulnerabilities in web application pentests. What distinguishes reflected, stored and DOM-based XSS, how a pentester hunts for it and which measures actually solve the problem.

By Kees van der Vlies
Read more
Compliance9 min read

Data for AI systems: the five controls of ISO 42001 Annex A.7

An AI system is only as reliable as the data it runs on. Annex A.7 of ISO 42001 therefore sets requirements for data management, acquisition, quality, provenance and preparation. For each control: what an auditor expects and which deviations we see most often.

By Kees van der Vlies
Read more
IT-audit9 min read

Internal audit of your AI management system: ISO 42001 clause 9.2 in practice

Clause 9.2 of ISO 42001 requires internal audits and an audit programme that drives them. How to set that up, what an auditor actually tests, and the nonconformities we see most often.

By Kees van der Vlies
Read more
Compliance9 min read

Management review of your AI management system: inputs, outputs and frequency (ISO 42001 clause 9.3)

Clause 9.3 of ISO 42001 is fairly precise about what has to be on the table at the management review and what has to come out of it. A practical take on inputs, outputs and frequency.

By Kees van der Vlies
Read more

Stay informed

Get our latest articles and insights on IT audit, compliance and information security.