Version 2.5 · 30 July 2026
A customer found a defect in our toolkit. Here's what we did about it.
He was reading AIMS-06 and noticed it referenced treatment actions by
identifier, TRT-001 through TRT-016, without
ever describing what any of them were. He was right.
So we audited the whole set and found two more defects he hadn't spotted. Four risks
with no treatment action at all, one of them marked "in treatment" with nothing
treating it. And two control back-links in the Statement of Applicability that didn't
reconcile with the treatment plan. An auditor tracing controls would have found both, as a finding against his AI management system, not against our toolkit.
We rebuilt the documents, wrote a new one — AIMS-06a, the Risk
Treatment Action Catalogue — and shipped v2.3 free to every existing customer
with a written explanation of exactly what had been wrong.
In v2.5 we found a second defect of the same class that our own v2.3 audit had missed:
nine risk scores in AIMS-06a did not match the register they cited. That
audit traced every identifier in both directions; it did not trace the values carried
alongside them. Both accounts are public, and so is the automated check that now runs
before every release.
Read the full account, with the control IDs →