Reference Implementation
Sentinel AI — a complete compliance build, in the open.
Sentinel AI is a fictional mid-sized US-based B2B AI SaaS company. I built a full compliance implementation for it — from scoping through audit — to demonstrate exactly how I work. This is a public reference architecture, not a past client. Every artifact here follows the same methodology I use on real engagements.
Company
Sentinel AI (fictional)
Sector
B2B AI SaaS — enterprise customers
HQ
United States
Size
80–150 employees
AI usage
Foundation model APIs, fine-tuned models, RAG pipelines
Customer verticals
Healthcare-adjacent, financial services
Target markets
US, EU, UK
Applicable frameworks
ISO/IEC 27001:2022
Implemented
ISO/IEC 42001:2023
Implemented
SOC 2 Type II
In Progress
GDPR
Mapped
EU AI Act
High-Risk Classification
HIPAA
Touch-points Identified
Implementation artifacts
Organised the way an auditor would expect to see them. Click a group to expand.
ISMS Scope Statement
Defines the boundaries of the information security management system.
AIMS Scope Statement
Defines the boundaries of the AI management system.
Context of the Organisation
Identifies internal and external issues, interested parties, and their requirements.
Information Security Risk Register
Comprehensive risk assessment with likelihood, impact, and treatment plans.
AI Risk Register
AI-specific risks including bias, drift, adversarial attack, and supply chain dependencies.
AI System Impact Assessment
Evaluates potential impacts of AI systems on individuals and society.
Risk Treatment Plan
Documented decisions on how each identified risk is addressed.
Information Security Policy
Top-level policy establishing management direction and commitment.
AI Policy
Governs the responsible development, deployment, and use of AI systems.
Access Control Policy
Rules for granting, reviewing, and revoking access to information assets.
Data Classification Policy
Framework for categorising information by sensitivity and handling requirements.
Incident Response Policy
Procedures for detecting, reporting, and responding to security incidents.
Supplier Security Policy
Requirements for managing information security risks in supplier relationships.
Acceptable Use Policy
Rules for acceptable use of organisational information and assets.
Cryptography Policy
Standards for the use of cryptographic controls to protect information.
Risk Assessment Procedure
Step-by-step process for identifying and evaluating risks.
Internal Audit Procedure
Methodology for planning and conducting ISMS/AIMS internal audits.
Management Review Procedure
Agenda, inputs, and outputs for management review meetings.
Change Management Procedure
Controls for managing changes to systems, processes, and services.
AI System Lifecycle Procedure
Governance checkpoints across the AI development and deployment lifecycle.
Statement of Applicability (ISO 27001)
Maps all Annex A controls to implementation status with justifications.
Statement of Applicability (ISO 42001)
Maps all Annex B/C controls to implementation status.
Control Implementation Notes
Evidence patterns and implementation details for each applied control.
Internal Audit Report
Findings, nonconformities, and observations from the internal audit.
Management Review Minutes
Documented outcomes and decisions from the management review meeting.
Corrective Action Log
Tracks nonconformities through to resolution and effectiveness verification.
12-Month Implementation Roadmap
Phased plan from gap assessment through certification audit.
Every artifact here follows the same methodology I use on real engagements. Want to see how I structure an implementation from start to finish?
See the Playbooks