ISO/IEC 42001 makes AI governance auditable
ISO/IEC 42001 does not prescribe seven named documents; it requires controlled evidence that AI risks, responsibilities, and decisions are managed.
AI-assisted development, compliance software, security, and building products in the open. Written and video posts by Tim Crouch.
Editorial series
Follow a thread through the work, from product decisions and AI security to experiments and recorded talks.
Product decisions, regulatory constraints, and human-in-the-loop review for compliance software that has to stand up to scrutiny.
Explore seriesHow we use AI-assisted development in real work — including the limits, missed expectations, and failure modes.
Explore seriesPractical notes for regulated European teams navigating security, governance, and compliance requirements.
Explore seriesPractical AI security: protecting systems, data, and people as AI becomes part of everyday operations.
Explore seriesExperiments, research notes, and launch updates from the ideas and products we are building in the open.
Explore seriesRecorded walkthroughs and talks, with written summaries for readers who would rather scan than press play.
Explore seriesISO/IEC 42001 does not prescribe seven named documents; it requires controlled evidence that AI risks, responsibilities, and decisions are managed.
Europe didn't ban AI. It ranked the harm — and the high-risk band is where most real systems actually live.
The Cloud Security Alliance's trait-based approach maps agent behavior and architectural choices to concrete security risks and controls.
Why we tore down our own website and rebuilt it around what we actually do: services, products in progress, experiments, and a blog that brings our writing into one home.
AI can read a marketing document against MiFID II requirements faster than any human. It still shouldn't be the one who approves it. That's a design principle, not a limitation.
The OWASP AI Exchange provides a lifecycle map for moving from AI governance and threat analysis to testing, operations, and residual-risk decisions.
NIST's attack taxonomy helps security teams connect adversary goals, access, lifecycle stages, and mitigations across predictive and generative AI.
Microsoft's experience across 100 generative-AI products shows why testing must follow real system risks, not a generic attack checklist.
OWASP's 2025 list shows that securing an LLM application requires architecture, testing, and development controls around the model.
The EU AI Act is not only a legal classification scheme; it requires organizations to connect AI risk, data governance, oversight, and evidence.
NIST's Generative AI Profile extends the AI RMF with concrete actions for governance, data provenance, testing, and incident disclosure.
BaFin's central point is simple: AI security has to cover the whole decision process, not just the model.
Google's SAIF implementation guide turns six security principles into an organizational process for designing, deploying, and operating AI safely.
Google's one-page SAIF summary provides a useful executive test for whether AI security covers architecture, operations, and business risk.
The NIST AI RMF gives organizations a lifecycle structure for connecting AI governance, assets, architecture, measurement, and risk treatment.