Hardly any first conversation starts with a standard. It starts with a sentence like this: “A customer has sent us a questionnaire, and we do not know what to answer.” Or: “We use AI, and nobody can tell me whether that is a problem.”
Behind both sentences sits the same question. Not: how do we become compliant? But: how much is enough, and who signs it off?
Two mistakes, both expensive
In practice I see two patterns, often in the same company.
Everything equally critical. Every system, every process, every AI application gets the full treatment. That feels safe. But it is expensive, ties up exactly the specialists who are already scarce, and rarely lasts beyond the first audit. What remains is a pile of documents that nobody maintains.
Nothing until it burns. You wait until the situation is clearer, until the customer asks, until the auditor arrives. Then weeks have to make up for what would have taken months at a calm pace, and management carries a risk without knowing it.
Both mistakes have the same cause: there is no justified answer to what is really critical.
Classification decides the effort
Every standard I work with asks the same question at its core: how do we know this system does what it should, and how do we prove it to someone who has no reason to take our word for it? The answer has five steps. Define the subject, classify, derive the obligations, produce the evidence, keep it auditable.
The second step carries the business case. A sound classification sets out what is mandatory and what explicitly is not. That makes it the only step that legitimately removes work.
That holds in every field:
- For artificial intelligence, classification under the EU AI Act decides whether a system is prohibited, high risk or can be operated with manageable obligations.
- In information security, the protection-needs assessment determines where baseline protection is enough and where the truly valuable systems need more.
- In business continuity, the criticality of a process determines how quickly it has to be running again, and therefore which plan is needed.
- In validation, GxP relevance and the GAMP category decide how deeply a system has to be tested. A standard product with little configuration does not need the test scope of a custom development.
A classification is a rationale, not a tick box
A classification is only valuable if it holds up under scrutiny. For that it needs three things.
A clearly defined subject. What exactly is being considered, where does the system end, what is the company’s role in the legal sense? This step is skipped most often and causes most of the disputes later on.
A traceable chain. Every step of the reasoning has to be checkable on its own. An auditor does not accept “uncritical from our point of view”, but will accept a documented assessment.
The courage to give the all-clear. Anyone who can credibly justify that something can be dropped earns more trust than someone who sees action needed everywhere. It is also the more honest way to justify the effort that really is required.
Who signs?
Responsibility stays with management. It cannot be delegated, and rightly so. What can be delegated is the preparation: a decision that is justified, documented and traceable. Management that signs such a classification can answer an auditor’s question without stopping the project.
What follows
Before a management system is built, a tool bought or a project started, there is a baseline assessment with a classification. It takes days, not months. And it answers the question that almost every conversation really starts with: how much is enough?