Skip to content
Knowledge centreServicesRatesAI ActE-learning sample

Trust & evidence

Trust calls for evidence.

Safe AI use calls for clear responsibilities, appropriate security and checks that are actually performed. Certification can provide independent assessment of that approach. An up-to-date file shows what is in place and what still needs attention.

Discuss your situation
Illustrative file · no customer data

An AI process under control

One application, with agreements that can be found and reviewed.

Process ownerCustomer Service team
  1. Recorded
    Purpose and data useProcess description · version 1.2
  2. For review
    Supplier and accessAssessment by IT
  3. Recorded
    Human oversightWorking instruction · approved
  4. In progress
    Review and improvementAction owner and next review

A status describes the file. It is not a judgement of legal compliance.

What fits your organisation?

Four frameworks. One coherent approach.

We connect requirements to everyday work: who is responsible, which measure fits and how can you show it works? The applicable scope is determined in advance.

ISO 27001

Information security

ISO 27001

A management system for organising information security systematically. Risks, controls and evaluations become part of business operations.

In practice

For example: review access rights, document supplier agreements and test backup recovery.

ISO 42001

Responsible AI management

ISO 42001

A management system for developing and using AI responsibly. It connects policy and ownership to risk assessment and improvement.

In practice

For example: assess an AI process, organise human oversight and follow up on issues.

NEN 7510

Healthcare & health information

NEN 7510

Information security tailored to healthcare. It focuses on the availability, integrity and confidentiality of personal health information.

In practice

For example: determine who may access patient information and how it stays available during an outage.

NIS2

Cyber resilience

NIS2

A European cybersecurity directive addressing risk management and incident reporting. Applicable obligations depend on the organisation and national legislation.

In practice

For example: discuss supplier risks, agree incident roles and prepare for continuity.

Audit Planner

Working together

Connect AI processes with audit preparation.

For NIS2 and NEN 7510, we work with auditplanner.io. This gives the move from understanding to demonstrable working agreements a clear place in our support.

Audit Planner describes an approach based on requirements, owners and evidence for each programme. Together, we discuss which support and documentation fit your organisation.

Meet Audit Planner
Example of building an evidence file
2 of 4 items recorded

From insight to a file ready for review

  1. Recorded
    Purpose and data useProcess description · version 1.2
  2. For review
    Supplier and accessAssessment by IT
  3. Recorded
    Human oversightWorking instruction · approved
  4. In progress
    Review and improvementAction owner and next review
Next stepComplete the supplier assessment

Illustrative progress, not a compliance score or live customer file.

How we make it practical

  1. Define what applies

    We discuss your processes, data, risks and intended scope.

  2. Make agreements workable

    Each action gets an owner, an outcome and an appropriate review point.

  3. Gather relevant evidence

    Decisions, working instructions and checks are linked to the right question.

  4. Review and improve

    Open issues are followed up; the file stays current for assessment.

NIS2 is a directive, not a certification standard. Support or software does not automatically establish compliance. Certification depends on the assessing body, validity period and scope.

Further reading: NEN on information security in healthcare · European Commission on NIS2