Records of Processing: Why the 250-Employee Exemption Fails Governance Docs15th August 2026 GDPR Article 30 records of processing: the exemption almost never applies, controllers and processors keep different records, and… Read More
DPIA: What GDPR Article 35 Actually Requires Governance Docs15th August 2026 A DPIA has four mandatory elements and two of them get skipped. What Article 35 requires, when Article… Read More
TISAX Exchange: The Half of TISAX Suppliers Never Use Governance Docs15th August 2026 TISAX is an exchange mechanism, not a certificate. The four steps, why scope decides what customers receive, and… Read More
SWIFT CSCF: Your Independent Assessment Can Be Internal Governance Docs15th August 2026 The SWIFT CSCF independent assessment can be performed by your own second or third line of defence, not… Read More
SOX 404: Who Needs the Auditor Attestation Governance Docs15th August 2026 SOX 404(a) applies to every issuer; 404(b) only to some. The public float and revenue tests that decide… Read More
PCI DSS Validation: Who Requires It, and What to Do First Governance Docs15th August 2026 PCI SSC does not require PCI DSS validation — your acquirer or payment brand does. How scope really… Read More
NIST AI RMF: The Four Functions, and the Revision Underway Governance Docs15th August 2026 The NIST AI RMF is voluntary, widely referenced, and version 1.0 is being revised under the White House… Read More
ISO 50001: The Standard Held Still, the Family Did Not Governance Docs15th August 2026 ISO 50001:2018 is confirmed and stable, but ISO 50100:2026 and the rebuilt ISO 50002 audit series changed the… Read More
ISO 41001: The Facility Management Standard, and Its Revision Governance Docs15th August 2026 ISO 41001:2018 is current and certifiable, but its replacement has reached DIS stage. What the standard requires, the… Read More
ISO 55001:2024: The Asset Management Standard, Rewritten Governance Docs15th August 2026 ISO 55001:2024 replaced the 2014 edition in July 2024. What the asset management system requires, why the SAMP… Read More
Data Governance and the DMBOK: What It Is, and Is Not Governance Docs15th August 2026 Data governance explained through the DAMA-DMBOK — what the framework covers, the boundaries DAMA sets explicitly, and the… Read More
COSO: Two Frameworks, and the New Generative AI Guidance Governance Docs15th August 2026 COSO explained — the 2013 internal control framework, the 2017 ERM framework, and the supplemental guidance on sustainability… Read More