Method
Five steps, the same in every field.
At their core, all standards ask the same question: how do we know this system does what it should, and how do we prove it to someone who has no reason to believe us? The method answers it in five steps.
Step 01
Define the scope
What exactly is the subject?
System boundary, inventory, legal role. The step most often skipped, and the one behind most of the disputes that follow.
Key questions
- Which systems, processes and sites are in scope, and which are not?
- What is the company's role: manufacturer, deployer, provider, service provider?
- Who is responsible for what, and who decides in the end?
For example An AI inventory that also captures the AI inside bought-in software.
Boundary and inventory
Step 02
Classify
How critical is it?
A defensible classification decides the effort for everything that follows. It legitimately removes work instead of treating everything as equally critical.
Key questions
- What happens if the system works incorrectly or fails?
- Which rules apply as a result, and which explicitly do not?
- Where is a baseline enough, and where is more needed?
For example Classification per AI system under the EU AI Act, protection needs per process, GAMP category per system.
Classification with rationale
Step 03
Derive obligations
What follows from it, and what explicitly does not?
The result is a reasoned list, not a copy of the standard.
Key questions
- What is mandatory, what is recommended, what is excluded with a rationale?
- What already exists and can be credited?
- In what order, by urgency?
For example A statement of applicability under ISO/IEC 42001 with a rationale for every control.
Reasoned list of obligations
Step 04
Produce evidence
What does an auditor actually hold in their hands?
Specifications, tests, records, traceability. Only here does the material an auditor reviews come into existence.
Key questions
- Which document does the auditor, the customer, the authority need?
- How do requirement, test and result connect?
- Who reviews, who approves?
For example A chain of evidence from the intended purpose of an AI system to the test result.
Audit-ready documents
Step 05
Keep it auditable
How does it stay true?
Change control, effectiveness measurement, internal audits, action tracking. Without this step, everything before it decays within a year.
Key questions
- How are changes assessed before they take effect?
- How can we tell that controls work?
- When is the audit internal, when external?
For example A review cycle that notices when the purpose, data or model of an AI system changes, instead of a rush before the audit.
Audit cycle
Why classification carries the business
Most companies make one of two mistakes. They treat everything as equally critical, which gets expensive and nobody keeps it up. Or they do nothing, which leaves management exposed. A reasoned, documented classification avoids both. It shows what is mandatory and what explicitly is not.
The same test, a different subject
One method, four disciplines.
| Step | Artificial intelligence | Information security | Business continuity | Validation in pharmaceutical production |
|---|---|---|---|---|
| 01Scope | AI inventory, role as provider or deployer, intended purpose | Scope and structure analysis under BSI 200-2 | Critical processes and their dependencies | GxP relevance and system inventory |
| 02Classify | Prohibited practices (Art. 5), high risk (Art. 6, Annex III) | Determination of protection needs | Downtime tolerances (MTPD, RTO, RPO) | GAMP category and risk class |
| 03Obligations | Requirements and quality management under the EU AI Act | Statement of Applicability, treatment plan | Continuity concept and recovery strategy | Extent of qualification |
| 04Evidence | Technical documentation, logging, human oversight | Policies, records, logs | Recovery plans, emergency manual, alerting matrix | URS, test cases, traceability matrix |
| 05Keep auditable | Post-market monitoring, training records | Effectiveness measurement, internal audit, management review | Exercise, update of the impact analysis | Change control, revalidation |
The test stays the same. Only the subject changes.
Example
How is an AI system classified under the EU AI Act?
Six questions, in the order I also ask them in an engagement. The result is a possible classification, not legal advice.
- Role
- Purpose
- Prohibited practices
- High risk, first route
- High risk, second route
- Justify an exemption
Question 1 of 6
Do you place the AI system on the market under your own name, or do you use a system you bought in?
This example does not replace an assessment of the individual case or legal advice. Your answers are neither stored nor transmitted.