AI management systems for regulated industry

Accountabilityyou can evidence.

AI brings new obligations. Information security, business continuity and validation are the existing ones. I build the management systems for them as one and make them audit-ready, with evidence an auditor accepts.

15 years at Bayer AG

  • ISO/IEC 42001 Lead Implementer
  • ISO/IEC 27001 Lead Auditor
  • BSI BCM Practitioner
Book an initial call

30 minutes, confidential

How I work

Behind it sits the same question

How much is enough, and who signs it off?

Customer evidence, AI in the plant, an emergency plan or a validated system: in the end, a sound classification decides the effort. Five steps, the same in every field.

  1. Step 01

    Define the scope

    What exactly is the subject?

    System boundary, inventory, legal role. The step most often skipped, and the one behind most of the disputes that follow.

    Key questions

    • Which systems, processes and sites are in scope, and which are not?
    • What is the company's role: manufacturer, deployer, provider, service provider?
    • Who is responsible for what, and who decides in the end?

    For example An AI inventory that also captures the AI inside bought-in software.

    Boundary and inventory

  2. Step 02

    Classify

    How critical is it?

    A defensible classification decides the effort for everything that follows. It legitimately removes work instead of treating everything as equally critical.

    Key questions

    • What happens if the system works incorrectly or fails?
    • Which rules apply as a result, and which explicitly do not?
    • Where is a baseline enough, and where is more needed?

    For example Classification per AI system under the EU AI Act, protection needs per process, GAMP category per system.

    Classification with rationale

  3. Step 03

    Derive obligations

    What follows from it, and what explicitly does not?

    The result is a reasoned list, not a copy of the standard.

    Key questions

    • What is mandatory, what is recommended, what is excluded with a rationale?
    • What already exists and can be credited?
    • In what order, by urgency?

    For example A statement of applicability under ISO/IEC 42001 with a rationale for every control.

    Reasoned list of obligations

  4. Step 04

    Produce evidence

    What does an auditor actually hold in their hands?

    Specifications, tests, records, traceability. Only here does the material an auditor reviews come into existence.

    Key questions

    • Which document does the auditor, the customer, the authority need?
    • How do requirement, test and result connect?
    • Who reviews, who approves?

    For example A chain of evidence from the intended purpose of an AI system to the test result.

    Audit-ready documents

  5. Step 05

    Keep it auditable

    How does it stay true?

    Change control, effectiveness measurement, internal audits, action tracking. Without this step, everything before it decays within a year.

    Key questions

    • How are changes assessed before they take effect?
    • How can we tell that controls work?
    • When is the audit internal, when external?

    For example A review cycle that notices when the purpose, data or model of an AI system changes, instead of a rush before the audit.

    Audit cycle

The method in detail

Separate systems, one liability

Risk management is the way of working. The topics are the fields.

What can go wrong, how likely is it, how severe would it be, and what can be done about it? I answer that in a way an auditor can recalculate.

  • ICH Q9(R1)
  • ISO 31000
  • BSI 200-3
  • FMEA
Risk matrixInitial risk → Residual risk after treatment. Illustrative only, no client data.LikelihoodImpact

Hover or tap a dot to see an example.

Initial riskResidual risk after treatmentIllustrative only, no client data.

Getting started

Urgent things first.

I start where the pressure is highest. First comes a clear baseline that shows what matters now and what can wait.

  • AI classification

    When AI is in use but nobody can say whether that is a problem.

    You receive

    • Classification report per AI system
    • Obligations per system
    • Concept for training records

    So that you cantell any customer or auditor in one sentence which AI you use, how, and why that is permissible.

    Discuss this
  • AI maturity check ISO/IEC 42001

    When you want to know how far your handling of AI is from a management system under ISO/IEC 42001.

    You receive

    • Comparison with the requirements of the standard
    • The main gaps in order

    So that you canknow what is missing for audit readiness, and what is not.

    Discuss this
  • NIS2 clarity

    When it is unclear whether and how your company is covered.

    You receive

    • Applicability assessment per legal entity
    • Overview of obligations
    • Registration and reporting route

    So that you canprove whether and how you are covered, and name your obligations as management.

    Discuss this
  • Security baseline

    When customers demand evidence or an audit is coming up.

    You receive

    • Maturity picture against ISO/IEC 27001
    • Draft Statement of Applicability
    • Prioritised treatment plan

    So that you candirect budget to the gaps that actually matter.

    Discuss this
  • Continuity check

    When nobody can say for sure how long production runs without ERP or control systems.

    You receive

    • Downtime tolerances for the critical processes
    • Dependencies between production, IT and ERP
    • List of critical gaps

    So that you candecide which outage is tolerable, and what happens when it occurs.

    Discuss this

Interim leadership

When responsibility has to be filled at short notice.

Independent of any management system: for projects, transformations and ongoing responsibility that nobody in the company can carry right now.

Interim management

Interim project leadership for initiatives that must not fail.

How I bill
Day allowances, agreed for a clearly defined phase.

vCISO and fractional executive mandate

Ongoing part-time leadership for AI governance, information security and business continuity, as a virtual CISO (vCISO) for a defined period.

How I bill
Monthly retainer with a fixed day allowance.

Project and programme mandate

Clearly bounded initiatives with a named result and a date.

How I bill
Fixed price or time and materials, always with a clear scope.
All forms of engagement
Sascha Geeren

Who you will be talking to

The person who actually does the work.

I come from regulated pharmaceutical production: validation, automation and digitalisation where every change has to stand up to an inspector. Today I bring that way of working to AI, information security and business continuity.

  • I will also tell you what is not necessary.
  • You get documents, not slides: reports, plans and evidence an auditor accepts.
  • I value every perspective and am used to talking with production, IT, quality and the works council.
  • Whoever builds a system does not certify it.
Career and approach

Among others · Certificates available on request

  • ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Implementer
  • BSI IT-Grundschutz Practitioner
  • BSI BCM Practitioner
  • Computer validation under GAMP 5

How much is enough?Let us find out in 30 minutes.

Book an initial call

Confidential, with no obligation. You will leave knowing where you stand.