Wijzigingslogboek
Wat wij zeiden dat ontbrak, en wanneer het niet meer ontbrak.
Wij publiceren een register, clausule voor clausule, van waar elke eis van een ISO-managementsysteem in het product leeft, inclusief de delen die nog niet gebouwd waren. Dit is het verslag van het dichten van die bekentenissen. 40 ervan, elk precies geciteerd zoals het is gepubliceerd.
Gegenereerd uit de registers zelf, niet achteraf geschreven. Een leemte komt op deze pagina door eerst op de dekkingspagina te hebben gestaan, en dat is de enige reden waarom ze het lezen waard is.
De citaten zijn in het Engels, de taal waarin ze zijn gepubliceerd. Een vertaald citaat zou niet meer de zin zijn die wij hebben gepubliceerd.
28 augustus 2026
Was:
No release records and no evidence of conformity to acceptance criteria, nor of the person authorising release.
22 augustus 2026
Was:
The machinery is right and the labelling is not: objectives are measurable, monitored and evidenced, but they are stored and presented as security objectives. 9001 6.2.1 asks for quality objectives at relevant functions and levels, and an auditor reads the screen. 6.2.2 also asks what will be done, with what resources, by whom, when, and how results are evaluated, and only the last of those is captured.
Was:
Organizational knowledge is a 9001-only clause with no 27001 counterpart. Documents can hold the knowledge itself, but there is no way to mark a document as organizational knowledge, give it an owner, or review it for currency, so nothing answers 7.1.6 as a clause.
13 augustus 2026
Was:
No calibration records, no equipment identification, no measurement traceability to international or national standards. For a manufacturer this is a routine audit finding and there is nothing here to answer it with. For a pure service company it is often not applicable, but that determination itself has to be recorded and cannot be.
Was:
A 9001-only clause with nothing behind it. It asks the organization to monitor customers' perception of the degree to which their needs have been met, and to determine the methods for obtaining and reviewing that information.
4 augustus 2026
Was:
Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. The assessment event itself is now recorded (8.2).
Was:
Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. 42001 additionally asks that the criteria account for consequences to individuals and to society, not only to the organization, and the register has no field that separates them.
3 augustus 2026
Was:
Issues are captured as text. Nothing links an issue to the risk or objective it drives, and there is no review cadence.
Was:
One free-text field conflates needs with requirements, and there is no field for which requirements the ISMS will address (4.2 c).
Was:
The scope statement is an unversioned, unapproved column outside the document module, and has no field for interfaces and dependencies (4.3 c).
Was:
Versioning and approval are strong. No flag identifies which document is *the* policy, and there is no record of it being communicated or made available (5.2 f, g).
Was:
The SoA renders and hashes server-side. There is no Annex A catalogue in the database, so the 6.1.3 c) check that no necessary control was omitted cannot be performed by the system.
Was:
Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated (6.2 e–i).
Was:
Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.
Was:
Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.
Was:
Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes.
Was:
Assessments are recorded as events with retained results, and the interval is planned rather than inferred. But a change-triggered assessment is one someone remembered to raise, and nothing in the product detects that a significant change occurred.
Was:
Per-risk treatment plan and status. No record of the results of implementation, which 8.3 requires be retained.
Was:
Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom (9.1 b–f).
Was:
Sign-off is immutable and the required inputs are prompted. Two of the 9.3.2 inputs are not prompted for, and inputs are retyped rather than derived from records the product already holds.
Was:
Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting ISMS change.
Was:
Issues are captured as text. 42001 also asks you to determine the organization's role for each AI system (provider, developer, deployer or user) and nothing here records that, so a system you deploy and a system you build carry the same context entry.
Was:
One free-text field conflates needs with requirements, and there is no field for which requirements the management system will address. For AI this omission bites harder: the parties affected by an AI system are frequently not its customers, and nothing distinguishes the two.
Was:
The scope statement is an unversioned, unapproved column outside the document module, with no field for interfaces and dependencies. It also has no place to list the AI systems in scope, which is how a 42001 scope is normally read.
Was:
Versioning and approval are strong. No flag identifies which document is the AI policy, and there is no record of it being communicated or made available. 42001 also expects the AI policy to be reconciled with other organizational policies, and nothing models that relationship.
Was:
The Statement of Applicability renders and hashes server-side, in this standard's own vocabulary. The seeded 42001 pack is a starting set rather than the full Annex A control list, so the check that no necessary control was omitted cannot yet be performed by the system.
Was:
This has no counterpart in ISO 27001 and is the clause 42001 is really about. Impacts can be recorded as risks today, which is where an auditor will look, but there is no dedicated impact assessment holding the affected groups, the intended purpose and reasonably foreseeable misuse per AI system.
Was:
Objectives are captured and measured. Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated.
Was:
Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.
Was:
Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.
Was:
Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes, the last of which matters more for AI, where a model can change behaviour without anyone changing the system.
Was:
Assessments are recorded as events with retained results, and the interval is planned rather than inferred. A change-triggered assessment is still one someone remembered to raise, and nothing in the product detects that a model, its data or its purpose changed.
Was:
Per-risk treatment plan and status. No record of the results of implementation, which this clause requires be retained.
Was:
The operational counterpart of 6.1.4, and it inherits the same gap: the result is retained as a risk record rather than as an impact assessment in its own right, so an auditor asking for the assessment of one named AI system is handed a filtered risk list.
Was:
Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom.
Was:
Sign-off is immutable and the required inputs are prompted. Inputs are retyped rather than derived from records the product already holds, and the prompts are the shared Harmonized Structure ones rather than 42001's own.
Was:
Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting change to the management system.
1 augustus 2026
Was:
No process register and no record of how the processes interact.
Was:
Not modelled.
Was:
No record of what is communicated, when, to whom, or how.
Niet gedicht, geherclassificeerd
2 regels zijn gewijzigd omdat wij besloten dat de leemte een grens van elke software was en geen tekortkoming van ons. Dat als levering tellen zou dezelfde overdrijving in de andere richting zijn, dus staat het hier in plaats van hierboven.
Was:
All eight demonstrations are answered from records held elsewhere in the ISMS, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.
Was:
The demonstrations are answered from records held elsewhere in the management system, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.
Waarom er verder niets op deze pagina staat
Uitgebrachte functies zijn makkelijk op te sommen en bewijzen weinig, omdat het wijzigingslogboek van elke leverancier er vol mee staat. In het openbaar toegegeven en daarna gedichte leemtes zijn de enige regels die iets kosten om te publiceren, omdat ze vereisen dat je hebt gezegd dat iets ontbrak terwijl het ontbrak. Het register is waar de huidige stand leeft, en dat blijft de eerlijke plek om eerst te lezen.