ISO/IEC 42001 in Plain English: What It Asks, and What It Costs You to Prove
The explainer that turns a standard into a project plan: what the clauses actually require, and which of your existing SOC 2 evidence already satisfies them.
What ISO/IEC 42001 actually asks for. What the EU AI Act means if you’re a US company with European customers. What carriers now ask about AI at renewal. Written by the people who do the assessments, for the people who have to answer for them.
Underwriters are adding AI questions to renewal submissions faster than most policyholders can answer them. Here’s what they’re asking, why, and what a good answer looks like, from the firm that trains them.
Read the analysis →
The explainer that turns a standard into a project plan: what the clauses actually require, and which of your existing SOC 2 evidence already satisfies them.
A practical sweep you can run in a week, procurement records, browser telemetry, SaaS admin consoles, and the four questions that surface the rest.
Three different problems that buyers and vendors keep merging into one. A taxonomy you can take into a board meeting.
Where the Security Rule already covers you, where it doesn’t, and what belongs in a business associate agreement that mentions AI.
What an AI Systems Program contains, what a market-conduct exam asks for, and the documentation gap most carriers still have.
The index should never look abandoned. Three pieces at launch, three inside six weeks, then monthly.
One email when something is worth reading. No sequences, no drip campaign, no “just circling back.”