Reference Implementation PROOF · प्रमाण
Sentinel AI, a complete compliance build, in the open.
Sentinel AI is a fictional mid sized US based B2B AI SaaS company. I built a full compliance implementation for it, from scoping through audit, to demonstrate exactly how I work. This is a public reference architecture, not a past client.
Company profile
Company
Sentinel AI (fictional)
Sector
B2B AI SaaS, enterprise customers
HQ
United States
Size
80 to 150 employees
AI Usage
Foundation model APIs, fine tuned models, RAG pipelines
Customer Verticals
Healthcare adjacent, financial services
Target Markets
US, EU, UK
Framework status
ISO/IEC 27001:2022
Implemented
ISO/IEC 42001:2023
Implemented
EU AI Act
High Risk Classification
SOC 2 Type II
In Progress
GDPR
Mapped
HIPAA
Touch-points Identified
Document groups
ISMS Scope Statement
Defines the boundaries of the information security management system.
Coming soon
AIMS Scope Statement
Defines the boundaries of the AI management system.
Coming soon
Context of the Organisation
Identifies internal and external issues, interested parties, and their requirements.
Coming soon
Information Security Risk Register
Comprehensive risk assessment with likelihood, impact, and treatment plans.
Coming soon
AI Risk Register
AI specific risks including bias, drift, adversarial attack, and supply chain dependencies.
Coming soon
AI System Impact Assessment
Evaluates potential impacts of AI systems on individuals and society.
Coming soon
Risk Treatment Plan
Documented decisions on how each identified risk is addressed.
Coming soon
Information Security Policy
Top level policy establishing management direction and commitment.
Coming soon
AI Policy
Governs the responsible development, deployment, and use of AI systems.
Coming soon
Access Control Policy
Rules for granting, reviewing, and revoking access to information assets.
Coming soon
Data Classification Policy
Framework for categorising information by sensitivity and handling requirements.
Coming soon
Incident Response Policy
Procedures for detecting, reporting, and responding to security incidents.
Coming soon
Supplier Security Policy
Requirements for managing information security risks in supplier relationships.
Coming soon
Acceptable Use Policy
Rules for acceptable use of organisational information and assets.
Coming soon
Cryptography Policy
Standards for the use of cryptographic controls to protect information.
Coming soon
Risk Assessment Procedure
Step by step process for identifying and evaluating risks.
Coming soon
Internal Audit Procedure
Methodology for planning and conducting ISMS and AIMS internal audits.
Coming soon
Management Review Procedure
Agenda, inputs, and outputs for management review meetings.
Coming soon
Change Management Procedure
Controls for managing changes to systems, processes, and services.
Coming soon
AI System Lifecycle Procedure
Governance checkpoints across the AI development and deployment lifecycle.
Coming soon
Statement of Applicability, ISO 27001
Maps all Annex A controls to implementation status with justifications.
Coming soon
Statement of Applicability, ISO 42001
Maps all Annex B and C controls to implementation status.
Coming soon
Control Implementation Notes
Evidence patterns and implementation details for each applied control.
Coming soon
Internal Audit Report
Findings, nonconformities, and observations from the internal audit.
Coming soon
Management Review Minutes
Documented outcomes and decisions from the management review meeting.
Coming soon
Corrective Action Log
Tracks nonconformities through to resolution and effectiveness verification.
Coming soon
12 Month Implementation Roadmap
Phased plan from gap assessment through certification audit.
Coming soon