Registro de cambios

Lo que dijimos que faltaba, y cuándo dejó de faltar.

Publicamos un registro, cláusula por cláusula, de dónde vive en el producto cada requisito de un sistema de gestión ISO, incluidas las partes que aún no estaban construidas. Este es el historial de cómo se cerraron esas admisiones. 40 de ellas, cada una citada exactamente como se publicó.

Generado a partir de los propios registros, no escrito después. Una carencia llega a esta página por haber estado antes en la página de cobertura, que es la única razón por la que merece leerse.

Las citas están en inglés, el idioma en que se publicaron. Una cita traducida ya no sería la frase que publicamos.

28 de agosto de 2026

  • 8.6Liberación de los productos y servicios frente a lo planificadoISO 9001

    Era: No release records and no evidence of conformity to acceptance criteria, nor of the person authorising release.

22 de agosto de 2026

  • 6.2Objetivos de la calidad, medibles, supervisados y planificadosISO 9001

    Era: The machinery is right and the labelling is not: objectives are measurable, monitored and evidenced, but they are stored and presented as security objectives. 9001 6.2.1 asks for quality objectives at relevant functions and levels, and an auditor reads the screen. 6.2.2 also asks what will be done, with what resources, by whom, when, and how results are evaluated, and only the last of those is captured.

  • 7.1.6El conocimiento que la organización necesita, mantenido y disponibleISO 9001

    Era: Organizational knowledge is a 9001-only clause with no 27001 counterpart. Documents can hold the knowledge itself, but there is no way to mark a document as organizational knowledge, give it an owner, or review it for currency, so nothing answers 7.1.6 as a clause.

13 de agosto de 2026

  • 7.1.5Recursos de seguimiento y medición, y su trazabilidadISO 9001

    Era: No calibration records, no equipment identification, no measurement traceability to international or national standards. For a manufacturer this is a routine audit finding and there is nothing here to answer it with. For a pure service company it is often not applicable, but that determination itself has to be recorded and cannot be.

  • 9.1.2La satisfacción del cliente, supervisada como percepciónISO 9001

    Era: A 9001-only clause with nothing behind it. It asks the organization to monitor customers' perception of the degree to which their needs have been met, and to determine the methods for obtaining and reviewing that information.

4 de agosto de 2026

  • 6.1.2Cómo se evalúa el riesgo, en su propia escalaISO/IEC 27001

    Era: Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. The assessment event itself is now recorded (8.2).

  • 6.1.2Cómo se evalúa el riesgo de IA, incluido el daño fuera de su organizaciónISO/IEC 42001

    Era: Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. 42001 additionally asks that the criteria account for consequences to individuals and to society, not only to the organization, and the register has no field that separates them.

3 de agosto de 2026

  • 4.1Comprender la organización y lo que la rodeaISO/IEC 27001

    Era: Issues are captured as text. Nothing links an issue to the risk or objective it drives, and there is no review cadence.

  • 4.2Quién tiene interés, y qué exigeISO/IEC 27001

    Era: One free-text field conflates needs with requirements, and there is no field for which requirements the ISMS will address (4.2 c).

  • 4.3Decidir qué cubre el SGSIISO/IEC 27001

    Era: The scope statement is an unversioned, unapproved column outside the document module, and has no field for interfaces and dependencies (4.3 c).

  • 5.2Una política de seguridad de la informaciónISO/IEC 27001

    Era: Versioning and approval are strong. No flag identifies which document is *the* policy, and there is no record of it being communicated or made available (5.2 f, g).

  • 6.1.3Elegir controles y declarar cuáles aplicanISO/IEC 27001

    Era: The SoA renders and hashes server-side. There is no Annex A catalogue in the database, so the 6.1.3 c) check that no necessary control was omitted cannot be performed by the system.

  • 6.2Objetivos de seguridad y cómo se alcanzaránISO/IEC 27001

    Era: Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated (6.2 e–i).

  • 7.3Hacer conscientes a las personasISO/IEC 27001

    Era: Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.

  • 7.5Controlar la información documentadaISO/IEC 27001

    Era: Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.

  • 8.1Planificar y controlar el funcionamiento del SGSIISO/IEC 27001

    Era: Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes.

  • 8.2Evaluar el riesgo a intervalos planificados y cuando algo cambiaISO/IEC 27001

    Era: Assessments are recorded as events with retained results, and the interval is planned rather than inferred. But a change-triggered assessment is one someone remembered to raise, and nothing in the product detects that a significant change occurred.

  • 8.3Ejecutar el plan de tratamiento del riesgoISO/IEC 27001

    Era: Per-risk treatment plan and status. No record of the results of implementation, which 8.3 requires be retained.

  • 9.1Seguimiento, medición, análisis y evaluaciónISO/IEC 27001

    Era: Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom (9.1 b–f).

  • 9.3Revisión por la direcciónISO/IEC 27001

    Era: Sign-off is immutable and the required inputs are prompted. Two of the 9.3.2 inputs are not prompted for, and inputs are retyped rather than derived from records the product already holds.

  • 10.2No conformidad y acción correctivaISO/IEC 27001

    Era: Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting ISMS change.

  • 4.1Comprender la organización y lo que la rodeaISO/IEC 42001

    Era: Issues are captured as text. 42001 also asks you to determine the organization's role for each AI system (provider, developer, deployer or user) and nothing here records that, so a system you deploy and a system you build carry the same context entry.

  • 4.2Quién tiene interés, y qué exigeISO/IEC 42001

    Era: One free-text field conflates needs with requirements, and there is no field for which requirements the management system will address. For AI this omission bites harder: the parties affected by an AI system are frequently not its customers, and nothing distinguishes the two.

  • 4.3Decidir qué cubre el sistema de gestión de IAISO/IEC 42001

    Era: The scope statement is an unversioned, unapproved column outside the document module, with no field for interfaces and dependencies. It also has no place to list the AI systems in scope, which is how a 42001 scope is normally read.

  • 5.2Una política de IAISO/IEC 42001

    Era: Versioning and approval are strong. No flag identifies which document is the AI policy, and there is no record of it being communicated or made available. 42001 also expects the AI policy to be reconciled with other organizational policies, and nothing models that relationship.

  • 6.1.3Elegir controles y declarar cuáles aplicanISO/IEC 42001

    Era: The Statement of Applicability renders and hashes server-side, in this standard's own vocabulary. The seeded 42001 pack is a starting set rather than the full Annex A control list, so the check that no necessary control was omitted cannot yet be performed by the system.

  • 6.1.4Evaluar qué hace un sistema de IA a las personas a las que alcanzaISO/IEC 42001

    Era: This has no counterpart in ISO 27001 and is the clause 42001 is really about. Impacts can be recorded as risks today, which is where an auditor will look, but there is no dedicated impact assessment holding the affected groups, the intended purpose and reasonably foreseeable misuse per AI system.

  • 6.2Objetivos de IA y cómo se alcanzaránISO/IEC 42001

    Era: Objectives are captured and measured. Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated.

  • 7.3Hacer conscientes a las personasISO/IEC 42001

    Era: Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.

  • 7.5Controlar la información documentadaISO/IEC 42001

    Era: Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.

  • 8.1Planificar y controlar el funcionamiento del sistemaISO/IEC 42001

    Era: Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes, the last of which matters more for AI, where a model can change behaviour without anyone changing the system.

  • 8.2Evaluar el riesgo de IA a intervalos planificados y cuando algo cambiaISO/IEC 42001

    Era: Assessments are recorded as events with retained results, and the interval is planned rather than inferred. A change-triggered assessment is still one someone remembered to raise, and nothing in the product detects that a model, its data or its purpose changed.

  • 8.3Ejecutar el plan de tratamiento del riesgo de IAISO/IEC 42001

    Era: Per-risk treatment plan and status. No record of the results of implementation, which this clause requires be retained.

  • 8.4Realizar la evaluación de impacto y conservar su resultadoISO/IEC 42001

    Era: The operational counterpart of 6.1.4, and it inherits the same gap: the result is retained as a risk record rather than as an impact assessment in its own right, so an auditor asking for the assessment of one named AI system is handed a filtered risk list.

  • 9.1Seguimiento, medición, análisis y evaluaciónISO/IEC 42001

    Era: Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom.

  • 9.3Revisión por la direcciónISO/IEC 42001

    Era: Sign-off is immutable and the required inputs are prompted. Inputs are retyped rather than derived from records the product already holds, and the prompts are the shared Harmonized Structure ones rather than 42001's own.

  • 10.2No conformidad y acción correctivaISO/IEC 42001

    Era: Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting change to the management system.

1 de agosto de 2026

  • 4.4El SGSI y los procesos que lo componenISO/IEC 27001

    Era: No process register and no record of how the processes interact.

  • 7.1Los recursos que el SGSI necesitaISO/IEC 27001

    Era: Not modelled.

  • 7.4Comunicar sobre seguridadISO/IEC 27001

    Era: No record of what is communicated, when, to whom, or how.

No cerrado, reclasificado

2 entradas cambiaron porque decidimos que la carencia era un límite de cualquier software y no una falta nuestra. Contarlo como entrega sería la misma exageración en sentido contrario, así que figura aquí en lugar de arriba.

  • 5.1Una dirección que asume de verdad el sistema3 de agosto de 2026

    Era: All eight demonstrations are answered from records held elsewhere in the ISMS, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.

  • 5.1Una dirección que asume de verdad el sistema3 de agosto de 2026

    Era: The demonstrations are answered from records held elsewhere in the management system, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.

Por qué esta página no tiene nada más

Las funciones entregadas son fáciles de enumerar y demuestran poco, porque el registro de cambios de cualquier proveedor está lleno de ellas. Las carencias admitidas en público y después cerradas son las únicas entradas que cuesta algo publicar, porque exigen haber dicho que algo faltaba mientras faltaba. El registro es donde vive el estado actual, y sigue siendo lo honesto leerlo primero.