Compliance framework guides
What each framework actually requires, how evidence collection works in practice, and how to evaluate software for your program — written by the team that builds one.
SOX compliance for ITGC and §302/§404 readiness
What the Sarbanes-Oxley Act actually requires from IT: how ITGC evidence, control testing, deficiency evaluation, and §302/§404 certification work.
SOC 2 compliance: what it requires and what auditors sample
What SOC 2 actually requires, Type I vs Type II, the evidence auditors sample during an examination, and what a program that scales past spreadsheets looks like.
ISO 27001: the ISMS, Annex A, and the certification cycle
What ISO/IEC 27001:2022 requires of an ISMS — the risk assessment, Statement of Applicability, the four Annex A control themes, and the certification cycle.
The EU AI Act: risk tiers, obligations, and timeline
How the EU AI Act works: risk tiers, prohibited and high-risk obligations, provider vs deployer duties, the phased 2025-2027 timeline, and how to prepare.
ISO/IEC 42001: the AI management system standard
How ISO/IEC 42001 works: the AI management system (AIMS) concept, Annex A controls, the certification cycle, its link to ISO 27001, and how to prepare.
NIST AI Risk Management Framework, explained
How the NIST AI Risk Management Framework works: the Govern, Map, Measure, and Manage functions, the trustworthiness characteristics, profiles, and its voluntary nature.
The Colorado AI Act (SB 24-205), explained
How the Colorado AI Act (SB 24-205) works: high-risk AI and consequential decisions, developer vs deployer duties, the algorithmic-discrimination reasonable-care standard.