1. Step 01

    Define the scope

    What exactly is the subject?

    System boundary, inventory, legal role. The step most often skipped, and the one behind most of the disputes that follow.

    Key questions

    • Which systems, processes and sites are in scope, and which are not?
    • What is the company's role: manufacturer, deployer, provider, service provider?
    • Who is responsible for what, and who decides in the end?

    For example An AI inventory that also captures the AI inside bought-in software.

    Boundary and inventory

  2. Step 02

    Classify

    How critical is it?

    A defensible classification decides the effort for everything that follows. It legitimately removes work instead of treating everything as equally critical.

    Key questions

    • What happens if the system works incorrectly or fails?
    • Which rules apply as a result, and which explicitly do not?
    • Where is a baseline enough, and where is more needed?

    For example Classification per AI system under the EU AI Act, protection needs per process, GAMP category per system.

    Classification with rationale

  3. Step 03

    Derive obligations

    What follows from it, and what explicitly does not?

    The result is a reasoned list, not a copy of the standard.

    Key questions

    • What is mandatory, what is recommended, what is excluded with a rationale?
    • What already exists and can be credited?
    • In what order, by urgency?

    For example A statement of applicability under ISO/IEC 42001 with a rationale for every control.

    Reasoned list of obligations

  4. Step 04

    Produce evidence

    What does an auditor actually hold in their hands?

    Specifications, tests, records, traceability. Only here does the material an auditor reviews come into existence.

    Key questions

    • Which document does the auditor, the customer, the authority need?
    • How do requirement, test and result connect?
    • Who reviews, who approves?

    For example A chain of evidence from the intended purpose of an AI system to the test result.

    Audit-ready documents

  5. Step 05

    Keep it auditable

    How does it stay true?

    Change control, effectiveness measurement, internal audits, action tracking. Without this step, everything before it decays within a year.

    Key questions

    • How are changes assessed before they take effect?
    • How can we tell that controls work?
    • When is the audit internal, when external?

    For example A review cycle that notices when the purpose, data or model of an AI system changes, instead of a rush before the audit.

    Audit cycle

Why classification carries the business

Most companies make one of two mistakes. They treat everything as equally critical, which gets expensive and nobody keeps it up. Or they do nothing, which leaves management exposed. A reasoned, documented classification avoids both. It shows what is mandatory and what explicitly is not.

The same test, a different subject

One method, four disciplines.

The five steps across four disciplines
StepArtificial intelligenceInformation securityBusiness continuityValidation in pharmaceutical production
01ScopeAI inventory, role as provider or deployer, intended purposeScope and structure analysis under BSI 200-2Critical processes and their dependenciesGxP relevance and system inventory
02ClassifyProhibited practices (Art. 5), high risk (Art. 6, Annex III)Determination of protection needsDowntime tolerances (MTPD, RTO, RPO)GAMP category and risk class
03ObligationsRequirements and quality management under the EU AI ActStatement of Applicability, treatment planContinuity concept and recovery strategyExtent of qualification
04EvidenceTechnical documentation, logging, human oversightPolicies, records, logsRecovery plans, emergency manual, alerting matrixURS, test cases, traceability matrix
05Keep auditablePost-market monitoring, training recordsEffectiveness measurement, internal audit, management reviewExercise, update of the impact analysisChange control, revalidation

The test stays the same. Only the subject changes.

Proven in regulated environments since 2008

Example

How is an AI system classified under the EU AI Act?

Six questions, in the order I also ask them in an engagement. The result is a possible classification, not legal advice.

  1. Role
  2. Purpose
  3. Prohibited practices
  4. High risk, first route
  5. High risk, second route
  6. Justify an exemption

Question 1 of 6

Do you place the AI system on the market under your own name, or do you use a system you bought in?

This example does not replace an assessment of the individual case or legal advice. Your answers are neither stored nor transmitted.