Reference Implementation

Sentinel AI — a complete compliance build, in the open.

Sentinel AI is a fictional mid-sized US-based B2B AI SaaS company. I built a full compliance implementation for it — from scoping through audit — to demonstrate exactly how I work. This is a public reference architecture, not a past client. Every artifact here follows the same methodology I use on real engagements.

Company
Sentinel AI (fictional)
Sector
B2B AI SaaS — enterprise customers
HQ
United States
Size
80–150 employees
AI usage
Foundation model APIs, fine-tuned models, RAG pipelines
Customer verticals
Healthcare-adjacent, financial services
Target markets
US, EU, UK

Applicable frameworks

ISO/IEC 27001:2022 Implemented
ISO/IEC 42001:2023 Implemented
SOC 2 Type II In Progress
GDPR Mapped
EU AI Act High-Risk Classification
HIPAA Touch-points Identified

Implementation artifacts

Organised the way an auditor would expect to see them. Click a group to expand.

ISMS Scope Statement
Defines the boundaries of the information security management system.
Coming soon
AIMS Scope Statement
Defines the boundaries of the AI management system.
Coming soon
Context of the Organisation
Identifies internal and external issues, interested parties, and their requirements.
Coming soon
Information Security Risk Register
Comprehensive risk assessment with likelihood, impact, and treatment plans.
Coming soon
AI Risk Register
AI-specific risks including bias, drift, adversarial attack, and supply chain dependencies.
Coming soon
AI System Impact Assessment
Evaluates potential impacts of AI systems on individuals and society.
Coming soon
Risk Treatment Plan
Documented decisions on how each identified risk is addressed.
Coming soon
Information Security Policy
Top-level policy establishing management direction and commitment.
Coming soon
AI Policy
Governs the responsible development, deployment, and use of AI systems.
Coming soon
Access Control Policy
Rules for granting, reviewing, and revoking access to information assets.
Coming soon
Data Classification Policy
Framework for categorising information by sensitivity and handling requirements.
Coming soon
Incident Response Policy
Procedures for detecting, reporting, and responding to security incidents.
Coming soon
Supplier Security Policy
Requirements for managing information security risks in supplier relationships.
Coming soon
Acceptable Use Policy
Rules for acceptable use of organisational information and assets.
Coming soon
Cryptography Policy
Standards for the use of cryptographic controls to protect information.
Coming soon
Risk Assessment Procedure
Step-by-step process for identifying and evaluating risks.
Coming soon
Internal Audit Procedure
Methodology for planning and conducting ISMS/AIMS internal audits.
Coming soon
Management Review Procedure
Agenda, inputs, and outputs for management review meetings.
Coming soon
Change Management Procedure
Controls for managing changes to systems, processes, and services.
Coming soon
AI System Lifecycle Procedure
Governance checkpoints across the AI development and deployment lifecycle.
Coming soon
Statement of Applicability (ISO 27001)
Maps all Annex A controls to implementation status with justifications.
Coming soon
Statement of Applicability (ISO 42001)
Maps all Annex B/C controls to implementation status.
Coming soon
Control Implementation Notes
Evidence patterns and implementation details for each applied control.
Coming soon
Internal Audit Report
Findings, nonconformities, and observations from the internal audit.
Coming soon
Management Review Minutes
Documented outcomes and decisions from the management review meeting.
Coming soon
Corrective Action Log
Tracks nonconformities through to resolution and effectiveness verification.
Coming soon
12-Month Implementation Roadmap
Phased plan from gap assessment through certification audit.
Coming soon

Every artifact here follows the same methodology I use on real engagements. Want to see how I structure an implementation from start to finish?

See the Playbooks