01

Compliant is not yet defensible

Compliance describes the system: the policy, assessment and management process. Defensibility answers for the decision: which requirement applied, what was checked, who intervened and what record remains.

An organisation can hold the right policies and still be unable to answer for a single output produced between two audits.

02

Why AI changes the unit of control

AI systems can produce thousands of consequential outputs between point-in-time reviews. In regulated environments, governance therefore has to reach the output itself, not stop at the programme around it.

The relevant question is not only whether the system was approved. It is whether the organisation can show how this decision was governed at the moment it was used.

03

The operating standard

A defensible deployment applies the relevant control before use, routes judgment to a named Human in the Loop where required, and preserves a tamper-evident record of the result.

Nextvise connects the management system established before deployment with the controls applied while AI is operating.

Basis

EU AI Act Articles 12, 14 and 19 · ISO/IEC 42001 AI management system