
The internal audit that never finds anything
ISO 19011 changed edition in May 2026. The failure mode it exists to prevent did not: the internal audit that has, by drift, stopped disagreeing with management.
Insights on ISO 27001, compliance automation, and information security.

ISO 19011 changed edition in May 2026. The failure mode it exists to prevent did not: the internal audit that has, by drift, stopped disagreeing with management.

Teams read the important label as NIS2-lite and scope their controls down. The security measures in Article 21 are the same either way; the tier changes supervision, some enforcement tools, and the floor on the national fine maximum.

Financial entities keep mapping ISO 27001 controls onto DORA articles and calling the residue paperwork. DORA's real additions are duties that must be performed, to a specification and on a clock, that a certificate was never designed to test.

"ISO 27001 certified" is not a yes-or-no fact about a company. The real claim is the scope statement on the certificate, and it is checkable.

The Cyber Resilience Act's reporting duty applies from 11 September 2026, more than a year before its essential requirements. Teams planning backwards from the 2027 CE mark are sequencing the work in the wrong order.

ISO 27001 never asks for a heat map. What it does ask for (consistent, valid and comparable results) is the test most risk matrices fail.

The EU agreed to push the high-risk deadlines to December 2027 and August 2028. The reason it moved should change how you read it: this is a warning about your scope, not breathing room for your roadmap.

Automate mapping, monitoring, and documentation of EU cross-border data transfers with AI—legal teams retain final decisions.

Centralize controls, map overlapping requirements, and automate evidence to reduce audit time and costs across multiple compliance frameworks.

AI-powered GRC platforms cut manual compliance work with automated evidence, cross-framework mapping, and faster audit reporting.

Consolidate overlapping framework requirements into a single control library to cut audit time and centralize evidence.

A founder note on alignment, distribution, and how the compliance-AI market pays the people doing the recommending