Clause 4.2, Understanding the needs and expectations of interested parties, is one of the clauses I most often see treated as a tick-box exercise: a register filled in once, filed away, and never looked at again. It is also a piece of string. How far you take it depends entirely on the business, on which […]
Articles
Quality Quote: “Give Your People Better Processes and Get Better Performance From Your People”
“Give your people better processes and get better performance from your people.” Author unknown. Don’t blame the person, blame the process. I’ve lost count of the number of audits I’ve walked into where a manager tells me, in the first ten minutes, that their real problem is “people not doing their job.” Then we go […]
Building Your ISO System with AI? Here’s Where It Goes Wrong
AI tools can draft ISO documentation in minutes, but they routinely miss the mark on context, risk and implementation. Here’s where AI-built ISO systems fail, and how to make yours actually pass certification.
Awareness Is a Behaviour, Not a Slide Deck: Simulated Phishing and Clause 7.3
Ask most businesses how they handle security awareness and you will hear the same answer: an annual slide deck and a quiz nobody remembers by lunchtime. It ticks a box. It changes almost nothing. When a well-crafted phishing email lands three months later, the slide deck is not in the room. The habit is, or […]
ISO 14001:2026 Is Here: What’s Changed and How to Plan Your Transition
ISO 14001:2026 was published on 15 April 2026. Here is what has changed in the environmental management standard and how to plan a smooth transition before April 2029.
NSW Codes of Practice Are Now Enforceable: What the 1 July 2026 Duty Means for You
On 1 July 2026 a quiet but significant change took effect in New South Wales. Codes of practice, which for years sat in the background as “guidance”, became something much closer to law. If you run a business in NSW, the practical question has shifted from “have we had an incident?” to “can we show […]
What Happens When All Your AI Agents Call in Sick?
Claude reliability incidents highlight a new continuity risk: what happens when business-critical AI agents and their underlying providers become unavailable?
From 10 December, Your Privacy Policy Has to Name the Decisions Your Software Makes
From 10 December 2026, new APP 1.7 to 1.9 require your privacy policy to disclose automated decisions about people. The OAIC is reading “computer program” broadly enough to catch spreadsheets, and a human in the loop does not get you out of it.
SafeWork NSW Just Told You What It Will Inspect. Can You Prove It?
SafeWork NSW has published its four regulatory priorities for 2026-27. A regulator that publishes its priorities has effectively written your internal audit programme for you.
Four questions to ask before you let an AI agent loose
Anthropic’s Deputy CISO uses four questions to decide whether an AI agent is safe to deploy. Here they are, and how they map to the controls in ISO 27001 and ISO 42001.
- « Previous Page
- 1
- …
- 5
- 6
- 7
- 8
- 9
- …
- 15
- Next Page »












