Topics
Four fields, one liability.
AI, information security, business continuity and validation have different standards but the same question: how do we know the system does what it should, and how do we prove it? That is why I run all four through one shared risk management. AI management comes first because it is the newest obligation and builds on the other three.
Risk management is the way of working. The topics are the fields.
What can go wrong, how likely is it, how severe would it be, and what can be done about it? I answer that in a way an auditor can recalculate.
- ICH Q9(R1)
- ISO 31000
- BSI 200-3
- FMEA
Hover or tap a dot to see an example.
Initial riskAI-supported shift planning without involving the works council (high risk under Art. 6)(Likelihood 3 / Impact 4)
Residual risk after treatmentReasoned classification and a works agreement(Likelihood 1 / Impact 3)
Initial riskAI visual inspection in quality control without a written intended purpose(Likelihood 4 / Impact 4)
Residual risk after treatmentIntended purpose, classification and approval before use(Likelihood 2 / Impact 3)
Initial riskStaff enter company data into freely available AI tools(Likelihood 5 / Impact 3)
Residual risk after treatmentApproved tools, clear rules and AI literacy training(Likelihood 3 / Impact 2)
Initial riskRemote maintenance access without multi-factor sign-in directly at the filling line(Likelihood 4 / Impact 5)
Residual risk after treatmentJump host with zone separation per IEC 62443(Likelihood 2 / Impact 2)
Initial riskRestart after an outage only agreed verbally(Likelihood 2 / Impact 5)
Residual risk after treatmentRestart plan with a target time, rehearsed and kept current(Likelihood 1 / Impact 4)
Initial riskGaps in the audit trail of batch documentation(Likelihood 5 / Impact 2)
Residual risk after treatmentComplete chain of evidence, checked by regular sampling(Likelihood 3 / Impact 1)
AI management
The real questionHow much effort is proportionate, and who is accountable for the decision?
How you notice itYou know which AI runs in the company, who is accountable for it and where the limits are. New applications get approved instead of simply appearing.
NIS2 · ISO/IEC 27001 · IEC 62443 · BSI IT-GrundschutzRisk and information security management
The real questionHow do we, as management, demonstrate that we meet our responsibility?
How you notice itYou see on one page where the company stands and which risks are open. You decide budget and priorities on that basis, not on demand.
ISO 22301 · BSI 200-4Business continuity and crisis readiness
The real questionHow long can a process be down before it becomes expensive or dangerous, and is there a plan someone can actually follow when it happens?
How you notice itYou know which outage is tolerable for how long. When it happens, a rehearsed chain of decisions runs, not the phone list.
GxP · GAMP 5 · MESValidation and interim project leadership
The real questionHow do we prove to the inspector that the system reliably does what it should in our environment?
How you notice itYou steer changes to your systems quickly and under control, because it is clear what needs testing and how deeply.
Under the roof
Four management systems, one logic.
Risk is the common language. Below it, every management system has its own standard, its own evidence and, in the end, its own audit. I build them to fit together instead of growing side by side.
AIMS
ISO/IEC 42001 · EU AI Act
Which AI do we use, and in which risk class?
- Register of AI applications
- Classification with a traceable rationale
- Governance, training and evidence
ISMS
ISO/IEC 27001 · BSI IT-Grundschutz
Which risks do we treat, and how do we prove it?
- Scope and risk assessment
- Statement of applicability
- Internal audits and management review
BCMS
ISO 22301 · BSI Standard 200-4
How long may a process be down, and who decides?
- Impact analysis with the process owners
- Recovery plans for the critical processes
- Exercises that show whether the plan holds
Audit readiness
ISO 19011 · Lead auditor practice
Will the evidence hold up in an audit?
- Organise evidence and name the gaps
- Mock audit with real samples
- Close findings before the audit