Ændringslog

Hvad vi sagde manglede, og hvornår det holdt op med at mangle.

Vi offentliggør et register, afsnit for afsnit, over hvor hvert krav i et ISO-ledelsessystem lever i produktet, også de dele, der endnu ikke var bygget. Dette er fortegnelsen over, hvordan de indrømmelser blev lukket. 40 af dem, hver citeret præcis som den blev offentliggjort.

Genereret fra registrene selv, ikke skrevet bagefter. Et hul kommer på denne side ved først at have stået på dækningssiden, og det er den eneste grund til, at siden er værd at læse.

Citaterne er på engelsk, det sprog de blev offentliggjort på. Et oversat citat ville ikke længere være den sætning, vi offentliggjorde.

28. august 2026

  • 8.6Frigivelse af produkter og ydelser mod de planlagte forholdISO 9001

    Var: No release records and no evidence of conformity to acceptance criteria, nor of the person authorising release.

22. august 2026

  • 6.2Kvalitetsmål, målbare, overvågede og planlagteISO 9001

    Var: The machinery is right and the labelling is not: objectives are measurable, monitored and evidenced, but they are stored and presented as security objectives. 9001 6.2.1 asks for quality objectives at relevant functions and levels, and an auditor reads the screen. 6.2.2 also asks what will be done, with what resources, by whom, when, and how results are evaluated, and only the last of those is captured.

  • 7.1.6Den viden organisationen har brug for, vedligeholdt og tilgængeligISO 9001

    Var: Organizational knowledge is a 9001-only clause with no 27001 counterpart. Documents can hold the knowledge itself, but there is no way to mark a document as organizational knowledge, give it an owner, or review it for currency, so nothing answers 7.1.6 as a clause.

13. august 2026

  • 7.1.5Ressourcer til overvågning og måling, og deres sporbarhedISO 9001

    Var: No calibration records, no equipment identification, no measurement traceability to international or national standards. For a manufacturer this is a routine audit finding and there is nothing here to answer it with. For a pure service company it is often not applicable, but that determination itself has to be recorded and cannot be.

  • 9.1.2Kundetilfredshed, overvåget som en opfattelseISO 9001

    Var: A 9001-only clause with nothing behind it. It asks the organization to monitor customers' perception of the degree to which their needs have been met, and to determine the methods for obtaining and reviewing that information.

4. august 2026

  • 6.1.2Hvordan risiko vurderes, på jeres egen skalaISO/IEC 27001

    Var: Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. The assessment event itself is now recorded (8.2).

  • 6.1.2Hvordan AI-risiko vurderes, inklusive skade uden for jeres organisationISO/IEC 42001

    Var: Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. 42001 additionally asks that the criteria account for consequences to individuals and to society, not only to the organization, and the register has no field that separates them.

3. august 2026

  • 4.1Forstå organisationen og det, der omgiver denISO/IEC 27001

    Var: Issues are captured as text. Nothing links an issue to the risk or objective it drives, and there is no review cadence.

  • 4.2Hvem der har en interesse, og hvad de kræverISO/IEC 27001

    Var: One free-text field conflates needs with requirements, and there is no field for which requirements the ISMS will address (4.2 c).

  • 4.3Afgør hvad ISMS'et dækkerISO/IEC 27001

    Var: The scope statement is an unversioned, unapproved column outside the document module, and has no field for interfaces and dependencies (4.3 c).

  • 5.2En politik for informationssikkerhedISO/IEC 27001

    Var: Versioning and approval are strong. No flag identifies which document is *the* policy, and there is no record of it being communicated or made available (5.2 f, g).

  • 6.1.3Vælge foranstaltninger og angive hvilke der gælderISO/IEC 27001

    Var: The SoA renders and hashes server-side. There is no Annex A catalogue in the database, so the 6.1.3 c) check that no necessary control was omitted cannot be performed by the system.

  • 6.2Sikkerhedsmål og hvordan de nåsISO/IEC 27001

    Var: Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated (6.2 e–i).

  • 7.3Gøre mennesker bevidsteISO/IEC 27001

    Var: Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.

  • 7.5Styre dokumenteret informationISO/IEC 27001

    Var: Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.

  • 8.1Planlægge og styre ISMS'ets driftISO/IEC 27001

    Var: Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes.

  • 8.2Vurdere risiko med planlagte mellemrum og når noget ændrer sigISO/IEC 27001

    Var: Assessments are recorded as events with retained results, and the interval is planned rather than inferred. But a change-triggered assessment is one someone remembered to raise, and nothing in the product detects that a significant change occurred.

  • 8.3Gennemføre risikohåndteringsplanenISO/IEC 27001

    Var: Per-risk treatment plan and status. No record of the results of implementation, which 8.3 requires be retained.

  • 9.1Overvågning, måling, analyse og evalueringISO/IEC 27001

    Var: Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom (9.1 b–f).

  • 9.3Ledelsens evalueringISO/IEC 27001

    Var: Sign-off is immutable and the required inputs are prompted. Two of the 9.3.2 inputs are not prompted for, and inputs are retyped rather than derived from records the product already holds.

  • 10.2Afvigelse og korrigerende handlingISO/IEC 27001

    Var: Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting ISMS change.

  • 4.1Forstå organisationen og det, der omgiver denISO/IEC 42001

    Var: Issues are captured as text. 42001 also asks you to determine the organization's role for each AI system (provider, developer, deployer or user) and nothing here records that, so a system you deploy and a system you build carry the same context entry.

  • 4.2Hvem der har en interesse, og hvad de kræverISO/IEC 42001

    Var: One free-text field conflates needs with requirements, and there is no field for which requirements the management system will address. For AI this omission bites harder: the parties affected by an AI system are frequently not its customers, and nothing distinguishes the two.

  • 4.3Afgør hvad AI-ledelsessystemet dækkerISO/IEC 42001

    Var: The scope statement is an unversioned, unapproved column outside the document module, with no field for interfaces and dependencies. It also has no place to list the AI systems in scope, which is how a 42001 scope is normally read.

  • 5.2En AI-politikISO/IEC 42001

    Var: Versioning and approval are strong. No flag identifies which document is the AI policy, and there is no record of it being communicated or made available. 42001 also expects the AI policy to be reconciled with other organizational policies, and nothing models that relationship.

  • 6.1.3Vælge foranstaltninger og angive hvilke der gælderISO/IEC 42001

    Var: The Statement of Applicability renders and hashes server-side, in this standard's own vocabulary. The seeded 42001 pack is a starting set rather than the full Annex A control list, so the check that no necessary control was omitted cannot yet be performed by the system.

  • 6.1.4Vurdere hvad et AI-system gør ved de mennesker, det berørerISO/IEC 42001

    Var: This has no counterpart in ISO 27001 and is the clause 42001 is really about. Impacts can be recorded as risks today, which is where an auditor will look, but there is no dedicated impact assessment holding the affected groups, the intended purpose and reasonably foreseeable misuse per AI system.

  • 6.2AI-mål og hvordan de nåsISO/IEC 42001

    Var: Objectives are captured and measured. Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated.

  • 7.3Gøre mennesker bevidsteISO/IEC 42001

    Var: Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.

  • 7.5Styre dokumenteret informationISO/IEC 42001

    Var: Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.

  • 8.1Planlægge og styre systemets driftISO/IEC 42001

    Var: Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes, the last of which matters more for AI, where a model can change behaviour without anyone changing the system.

  • 8.2Vurdere AI-risiko med planlagte mellemrum og når noget ændrer sigISO/IEC 42001

    Var: Assessments are recorded as events with retained results, and the interval is planned rather than inferred. A change-triggered assessment is still one someone remembered to raise, and nothing in the product detects that a model, its data or its purpose changed.

  • 8.3Gennemføre planen for håndtering af AI-risikoISO/IEC 42001

    Var: Per-risk treatment plan and status. No record of the results of implementation, which this clause requires be retained.

  • 8.4Gennemføre konsekvensvurderingen og gemme resultatetISO/IEC 42001

    Var: The operational counterpart of 6.1.4, and it inherits the same gap: the result is retained as a risk record rather than as an impact assessment in its own right, so an auditor asking for the assessment of one named AI system is handed a filtered risk list.

  • 9.1Overvågning, måling, analyse og evalueringISO/IEC 42001

    Var: Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom.

  • 9.3Ledelsens evalueringISO/IEC 42001

    Var: Sign-off is immutable and the required inputs are prompted. Inputs are retyped rather than derived from records the product already holds, and the prompts are the shared Harmonized Structure ones rather than 42001's own.

  • 10.2Afvigelse og korrigerende handlingISO/IEC 42001

    Var: Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting change to the management system.

1. august 2026

  • 4.4ISMS'et og de processer, det består afISO/IEC 27001

    Var: No process register and no record of how the processes interact.

  • 7.1De ressourcer ISMS'et kræverISO/IEC 27001

    Var: Not modelled.

  • 7.4Kommunikere om sikkerhedISO/IEC 27001

    Var: No record of what is communicated, when, to whom, or how.

Ikke lukket, omklassificeret

2 poster blev ændret, fordi vi besluttede, at hullet var en grænse for al software og ikke en mangel hos os. At tælle det som levering ville være samme overdrivelse i den anden retning, så det står her i stedet for ovenfor.

  • 5.1En ledelse der reelt ejer systemet3. august 2026

    Var: All eight demonstrations are answered from records held elsewhere in the ISMS, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.

  • 5.1En ledelse der reelt ejer systemet3. august 2026

    Var: The demonstrations are answered from records held elsewhere in the management system, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.

Hvorfor der ikke står andet på denne side

Leverede funktioner er lette at opremse og beviser lidt, for enhver leverandørs ændringslog er fuld af dem. Huller, der er indrømmet offentligt og derefter lukket, er de eneste poster, det koster noget at offentliggøre, fordi de kræver, at man har sagt, at noget manglede, mens det manglede. Registret er der, hvor den aktuelle tilstand lever, og det er stadig det ærlige at læse først.