Wijzigingslogboek

Wat wij zeiden dat ontbrak, en wanneer het niet meer ontbrak.

Wij publiceren een register, clausule voor clausule, van waar elke eis van een ISO-managementsysteem in het product leeft, inclusief de delen die nog niet gebouwd waren. Dit is het verslag van het dichten van die bekentenissen. 40 ervan, elk precies geciteerd zoals het is gepubliceerd.

Gegenereerd uit de registers zelf, niet achteraf geschreven. Een leemte komt op deze pagina door eerst op de dekkingspagina te hebben gestaan, en dat is de enige reden waarom ze het lezen waard is.

De citaten zijn in het Engels, de taal waarin ze zijn gepubliceerd. Een vertaald citaat zou niet meer de zin zijn die wij hebben gepubliceerd.

28 augustus 2026

  • 8.6Vrijgave van producten en diensten tegen de geplande regelingenISO 9001

    Was: No release records and no evidence of conformity to acceptance criteria, nor of the person authorising release.

22 augustus 2026

  • 6.2Kwaliteitsdoelstellingen, meetbaar, bewaakt en geplandISO 9001

    Was: The machinery is right and the labelling is not: objectives are measurable, monitored and evidenced, but they are stored and presented as security objectives. 9001 6.2.1 asks for quality objectives at relevant functions and levels, and an auditor reads the screen. 6.2.2 also asks what will be done, with what resources, by whom, when, and how results are evaluated, and only the last of those is captured.

  • 7.1.6De kennis die de organisatie nodig heeft, onderhouden en beschikbaarISO 9001

    Was: Organizational knowledge is a 9001-only clause with no 27001 counterpart. Documents can hold the knowledge itself, but there is no way to mark a document as organizational knowledge, give it an owner, or review it for currency, so nothing answers 7.1.6 as a clause.

13 augustus 2026

  • 7.1.5Middelen voor monitoring en meting, en hun herleidbaarheidISO 9001

    Was: No calibration records, no equipment identification, no measurement traceability to international or national standards. For a manufacturer this is a routine audit finding and there is nothing here to answer it with. For a pure service company it is often not applicable, but that determination itself has to be recorded and cannot be.

  • 9.1.2Klanttevredenheid, bewaakt als een belevingISO 9001

    Was: A 9001-only clause with nothing behind it. It asks the organization to monitor customers' perception of the degree to which their needs have been met, and to determine the methods for obtaining and reviewing that information.

4 augustus 2026

  • 6.1.2Hoe risico wordt beoordeeld, op uw eigen schaalISO/IEC 27001

    Was: Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. The assessment event itself is now recorded (8.2).

  • 6.1.2Hoe AI-risico wordt beoordeeld, inclusief schade buiten uw organisatieISO/IEC 42001

    Was: Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. 42001 additionally asks that the criteria account for consequences to individuals and to society, not only to the organization, and the register has no field that separates them.

3 augustus 2026

  • 4.1De organisatie en haar omgeving begrijpenISO/IEC 27001

    Was: Issues are captured as text. Nothing links an issue to the risk or objective it drives, and there is no review cadence.

  • 4.2Wie belang heeft, en wat die eistISO/IEC 27001

    Was: One free-text field conflates needs with requirements, and there is no field for which requirements the ISMS will address (4.2 c).

  • 4.3Bepalen wat het ISMS dektISO/IEC 27001

    Was: The scope statement is an unversioned, unapproved column outside the document module, and has no field for interfaces and dependencies (4.3 c).

  • 5.2Een informatiebeveiligingsbeleidISO/IEC 27001

    Was: Versioning and approval are strong. No flag identifies which document is *the* policy, and there is no record of it being communicated or made available (5.2 f, g).

  • 6.1.3Maatregelen kiezen en vermelden welke geldenISO/IEC 27001

    Was: The SoA renders and hashes server-side. There is no Annex A catalogue in the database, so the 6.1.3 c) check that no necessary control was omitted cannot be performed by the system.

  • 6.2Beveiligingsdoelstellingen en hoe ze worden gehaaldISO/IEC 27001

    Was: Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated (6.2 e–i).

  • 7.3Mensen bewust makenISO/IEC 27001

    Was: Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.

  • 7.5Gedocumenteerde informatie beheersenISO/IEC 27001

    Was: Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.

  • 8.1De werking van het ISMS plannen en beheersenISO/IEC 27001

    Was: Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes.

  • 8.2Risico beoordelen op geplande momenten en als er iets verandertISO/IEC 27001

    Was: Assessments are recorded as events with retained results, and the interval is planned rather than inferred. But a change-triggered assessment is one someone remembered to raise, and nothing in the product detects that a significant change occurred.

  • 8.3Het risicobehandelplan uitvoerenISO/IEC 27001

    Was: Per-risk treatment plan and status. No record of the results of implementation, which 8.3 requires be retained.

  • 9.1Bewaken, meten, analyseren en evaluerenISO/IEC 27001

    Was: Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom (9.1 b–f).

  • 9.3DirectiebeoordelingISO/IEC 27001

    Was: Sign-off is immutable and the required inputs are prompted. Two of the 9.3.2 inputs are not prompted for, and inputs are retyped rather than derived from records the product already holds.

  • 10.2Afwijking en corrigerende maatregelISO/IEC 27001

    Was: Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting ISMS change.

  • 4.1De organisatie en haar omgeving begrijpenISO/IEC 42001

    Was: Issues are captured as text. 42001 also asks you to determine the organization's role for each AI system (provider, developer, deployer or user) and nothing here records that, so a system you deploy and a system you build carry the same context entry.

  • 4.2Wie belang heeft, en wat die eistISO/IEC 42001

    Was: One free-text field conflates needs with requirements, and there is no field for which requirements the management system will address. For AI this omission bites harder: the parties affected by an AI system are frequently not its customers, and nothing distinguishes the two.

  • 4.3Bepalen wat het AI-managementsysteem dektISO/IEC 42001

    Was: The scope statement is an unversioned, unapproved column outside the document module, with no field for interfaces and dependencies. It also has no place to list the AI systems in scope, which is how a 42001 scope is normally read.

  • 5.2Een AI-beleidISO/IEC 42001

    Was: Versioning and approval are strong. No flag identifies which document is the AI policy, and there is no record of it being communicated or made available. 42001 also expects the AI policy to be reconciled with other organizational policies, and nothing models that relationship.

  • 6.1.3Maatregelen kiezen en vermelden welke geldenISO/IEC 42001

    Was: The Statement of Applicability renders and hashes server-side, in this standard's own vocabulary. The seeded 42001 pack is a starting set rather than the full Annex A control list, so the check that no necessary control was omitted cannot yet be performed by the system.

  • 6.1.4Beoordelen wat een AI-systeem doet met de mensen die het raaktISO/IEC 42001

    Was: This has no counterpart in ISO 27001 and is the clause 42001 is really about. Impacts can be recorded as risks today, which is where an auditor will look, but there is no dedicated impact assessment holding the affected groups, the intended purpose and reasonably foreseeable misuse per AI system.

  • 6.2AI-doelstellingen en hoe ze worden gehaaldISO/IEC 42001

    Was: Objectives are captured and measured. Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated.

  • 7.3Mensen bewust makenISO/IEC 42001

    Was: Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.

  • 7.5Gedocumenteerde informatie beheersenISO/IEC 42001

    Was: Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.

  • 8.1De werking van het systeem plannen en beheersenISO/IEC 42001

    Was: Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes, the last of which matters more for AI, where a model can change behaviour without anyone changing the system.

  • 8.2AI-risico beoordelen op geplande momenten en als er iets verandertISO/IEC 42001

    Was: Assessments are recorded as events with retained results, and the interval is planned rather than inferred. A change-triggered assessment is still one someone remembered to raise, and nothing in the product detects that a model, its data or its purpose changed.

  • 8.3Het plan voor AI-risicobehandeling uitvoerenISO/IEC 42001

    Was: Per-risk treatment plan and status. No record of the results of implementation, which this clause requires be retained.

  • 8.4De effectbeoordeling uitvoeren en de uitkomst bewarenISO/IEC 42001

    Was: The operational counterpart of 6.1.4, and it inherits the same gap: the result is retained as a risk record rather than as an impact assessment in its own right, so an auditor asking for the assessment of one named AI system is handed a filtered risk list.

  • 9.1Bewaken, meten, analyseren en evaluerenISO/IEC 42001

    Was: Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom.

  • 9.3DirectiebeoordelingISO/IEC 42001

    Was: Sign-off is immutable and the required inputs are prompted. Inputs are retyped rather than derived from records the product already holds, and the prompts are the shared Harmonized Structure ones rather than 42001's own.

  • 10.2Afwijking en corrigerende maatregelISO/IEC 42001

    Was: Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting change to the management system.

1 augustus 2026

  • 4.4Het ISMS en de processen waaruit het bestaatISO/IEC 27001

    Was: No process register and no record of how the processes interact.

  • 7.1De middelen die het ISMS nodig heeftISO/IEC 27001

    Was: Not modelled.

  • 7.4Communiceren over beveiligingISO/IEC 27001

    Was: No record of what is communicated, when, to whom, or how.

Niet gedicht, geherclassificeerd

2 regels zijn gewijzigd omdat wij besloten dat de leemte een grens van elke software was en geen tekortkoming van ons. Dat als levering tellen zou dezelfde overdrijving in de andere richting zijn, dus staat het hier in plaats van hierboven.

  • 5.1Een leiding die het systeem echt draagt3 augustus 2026

    Was: All eight demonstrations are answered from records held elsewhere in the ISMS, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.

  • 5.1Een leiding die het systeem echt draagt3 augustus 2026

    Was: The demonstrations are answered from records held elsewhere in the management system, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.

Waarom er verder niets op deze pagina staat

Uitgebrachte functies zijn makkelijk op te sommen en bewijzen weinig, omdat het wijzigingslogboek van elke leverancier er vol mee staat. In het openbaar toegegeven en daarna gedichte leemtes zijn de enige regels die iets kosten om te publiceren, omdat ze vereisen dat je hebt gezegd dat iets ontbrak terwijl het ontbrak. Het register is waar de huidige stand leeft, en dat blijft de eerlijke plek om eerst te lezen.