Version 2.5 · 30 July 2026 · this post covers 2.3
He was right. We audited the whole set and found two more he hadn't spotted. All three are fixed. Every existing customer received the corrected version free, with a written explanation of what had been wrong.
A customer, a director at a DACH consultancy, was reading AIMS-06,
the Risk Treatment Plan. He noticed it referenced treatment actions by identifier:
TRT-001 through TRT-016. But nowhere did the document say
what any of those actions actually were.
He emailed to tell us. He was right.
We could have patched that one document. Instead we went through the whole set, tracing every identifier in both directions the way an auditor would. We found two further defects he hadn't spotted.
AIMS-05, the AI Risk Register, defines twenty risks:
RISK-001 through RISK-020.
AIMS-06 only treated the first sixteen.
What was missing
| Risk | Description |
|---|---|
RISK-017 | Synthetic media deployed without required labelling |
RISK-018 | Model theft or extraction via API abuse |
RISK-019 | Compute cost disproportionate to delivered value |
RISK-020 | Environmental impact of AI operations |
No treatment action. No owner. No target date.
And RISK-017 was marked IN TREATMENT, with nothing treating it.
An internal contradiction sitting in a document destined for an auditor.
Clause 6.1.3 requires a treatment decision for every risk in the register. Even when that decision is "accept," it has to be recorded, owned, and justified. Four risks had no decision at all.
AIMS-07 is the Statement of Applicability. It maps each of the
38 Annex A controls to the treatment actions that implement it. Two of those
mappings disagreed with AIMS-06.
What didn't reconcile
| Control | Said | Should have said | Because AIMS-06 states |
|---|---|---|---|
A.10.3 |
TRT-010, TRT-015 | TRT-002, TRT-010, TRT-015 | TRT-002 applies A.6.2.6, A.10.2, A.10.3 |
A.5.3 |
, (empty) | TRT-009 | TRT-009 applies A.5.2, A.5.3 |
An auditor tracing controls from the treatment plan into the Statement of Applicability would have found both. As a finding against the customer's AI management system. Not against our toolkit.
The failure mode in compliance documentation is silent. Every identifier cross-references something. It reads beautifully. Then an auditor pulls one thread, three months into a certification, and the chain comes apart.
We wrote a new document, AIMS-06a, the Risk Treatment Action
Catalogue. It describes all twenty treatment actions in full: what each action is,
the verification method, the independent verifier, the completion date, the evidence
references, the risk-score movement from inherent through residual to target, the
acceptance authority, and the audit notes.
Section 3 of that document contains the complete column schema, formatted the same
way Annex A is presented in AIMS-05, so the two reconcile by construction
rather than by hope.
We patched AIMS-06 to treat all twenty risks, and corrected both
back-links in AIMS-07.
Shipped
Version 2.3 went free to every existing customer, with a written note explaining exactly what had been wrong and where. Nobody had to ask for it.
We asked someone to review what we'd written about the fix. They found two counting errors in the file inventory. We corrected those too. That's on this page because leaving it out would be its own kind of dishonesty.
If you're a trainer, a consultancy, or a distributor putting your own brand on someone else's documentation, there's one question worth asking them:
Tell me about a time your templates were wrong.
If they can't answer, they haven't looked. This is our answer. The whole
traceability chain, AIMS-05 → AIMS-06 →
AIMS-06a → AIMS-07, is now reconcilable by identifier
in both directions, and you're welcome to test it. In 2.5 we found that the values carried alongside those identifiers had not been traced, and corrected nine of them. That entry is below.
| Version | Date | Change |
|---|---|---|
| 2.5 | 30 Jul 2026 | Corrected nine risk-score references in AIMS-06a. Each treatment action records the
movement from inherent to residual to target risk and cites AIMS-05 as the source.
Nine of the twenty cited figures did not match the register they pointed at. RISK-006
is 16 → 9 in AIMS-05 and was recorded as 12 → 6;
RISK-011 is 10 → 4 and was recorded as 15 → 8. Seven
others were wrong in the same way. AIMS-05 is authoritative and AIMS-06a now matches
it in all twenty entries.
This is a defect of the same class as the one corrected in 2.3, and it survived that correction because of how we audited. In 2.3 we traced every identifier in both directions — every RISK, TRT and Annex A control reconciles, and still does. We did not trace the values carried alongside those identifiers. Identifier integrity and data integrity are different tests, and we had only run the first. Also in this release: added a Target column to AIMS-05, so the target figures cited by AIMS-06a resolve to a real column rather than an implied one. Replaced literal dates with [DATE] placeholders across all Professional and Audit-Ready artefacts
— left as-is, every document in those tiers would have shown an overdue review
date from April 2027 onward. Renamed Professional and Audit-Ready document IDs so they
no longer carry an AIMS- prefix, which made them look like part of the core
AIMS-01..22 set. Normalised placeholder casing. Corrected the document count in the
Master Guide from 22 to 23; AIMS-06a was added in 2.3 and the guide was never updated.
We now run an automated pre-release check that verifies the shipping archive against every enumeration surface — document counts, identifier coverage, risk-score reconciliation, bidirectional traceability, cross-references, placeholder consistency and document IDs — and fails the release if any of them disagree. |
| 2.4 | 28 Jul 2026 | Regulatory currency: the Digital Omnibus completed passage and is now Regulation (EU) 2026/1744, in force 27 July 2026. Every reference that described it as pending Council adoption now cites the Regulation. No obligation in this toolkit’s control set changed as a result of that update. The Omnibus itself did change obligations — it deferred the high-risk deadlines to 2 December 2027 and 2 August 2028, added two prohibitions, softened the AI literacy duty and introduced Article 4a. Those changes are covered on the EU AI Act page. Added an Article 50 transparency section to the Master Guide (applies 2 August 2026). Fixed a rendering fault that collapsed bulleted lists into run-on text (474 list items recovered across the Professional and Audit-Ready tiers). Repaired AIMS-06a, the only artefact failing OOXML schema validation. Corrected artefact subtitles that labelled guidance and audit-preparation material as "mandatory documented information". |
| 2.3 | 9 Jul 2026 | Added AIMS-06a Risk Treatment Action Catalogue (20 actions, full schema). Patched AIMS-06 to treat RISK-017 through RISK-020. Corrected A.10.3 and A.5.3 back-links in AIMS-07. Updated master index, guide, and first-week checklist. |
| 2.1 | Jun 2026 | EU AI Act Article 73 staged incident-reporting obligations incorporated. Statement of Applicability expanded to all 38 Annex A controls. |
The corrected AIMS-05 → 06 → 06a → 07 traceability chain, and the free FRIA starter.
Get the free FRIA Starter See the toolkits