Keith Parkman

Senior Advisor, Cybersecurity & Risk

“Strategy is about where you want to go; implementation and audit readiness are about making sure you actually arrive without breaking the business.”

Keith Responds to Key Questions

You've audited against SOX, ISO 27001, PCI DSS, and ISO 42001. How does time in the auditor's chair change the way you get a company ready for one?

Seeing through the auditor’s lens teaches you that compliance is about proving
operational reality, not writing policy books. It shifts audit readiness from a reactive
“checkbox panic” to upfront scope precision, proactive gap remediation, and the design
of workflows that automatically generate clear evidence. Understanding exactly how an
auditor samples, tests controls, and evaluates risk allows you to streamline the entire
process, preventing audit findings before the external team even steps foot in the room.

As a Lead Auditor for ISO 42001, the AI management standard, what do organizations most often miss when they prepare for AIMS certification?

As an ISO 42001 Lead Auditor, the biggest gap I see is organizations prioritizing rapid AI
innovation while failing to dedicate the necessary resources for actual governance.
Companies frequently miss establishing documented processes to monitor their AI
models post-deployment—leaving critical blind spots in model drift, bias, and lifecycle
management. They treat certification as a one-time technical checklist rather than
building the continuous, resource-backed AI Management System (AIMS) the standard
requires.

You've seen companies earn a certification and then stop operating the controls behind it. What should a leader do differently the year after they pass?

A leader should establish a year-round control monitoring plan rather than treating
compliance as an annual scramble. This requires holding control owners directly
accountable for executing their controls in daily operations and for conducting regular,
continuous testing throughout the year. By sampling evidence quarterly and embedding
control checks into everyday workflows, leaders ensure the management system stays
active, effective, and audit-ready.

Clarity over jargon. Substance over spin. Integrity, always.