Version 2.5 · 30 July 2026 · this post covers 2.3

A customer found a defect in our toolkit. Here's what we did about it.

He was right. We audited the whole set and found two more he hadn't spotted. All three are fixed. Every existing customer received the corrected version free, with a written explanation of what had been wrong.

By Akshay Dubey, Founder · Updated 10 July 2026

A customer, a director at a DACH consultancy, was reading AIMS-06, the Risk Treatment Plan. He noticed it referenced treatment actions by identifier: TRT-001 through TRT-016. But nowhere did the document say what any of those actions actually were.

He emailed to tell us. He was right.

We could have patched that one document. Instead we went through the whole set, tracing every identifier in both directions the way an auditor would. We found two further defects he hadn't spotted.

Defect 1, four risks with no treatment action

AIMS-05, the AI Risk Register, defines twenty risks: RISK-001 through RISK-020. AIMS-06 only treated the first sixteen.

What was missing

RiskDescription
RISK-017Synthetic media deployed without required labelling
RISK-018Model theft or extraction via API abuse
RISK-019Compute cost disproportionate to delivered value
RISK-020Environmental impact of AI operations

No treatment action. No owner. No target date. And RISK-017 was marked IN TREATMENT, with nothing treating it. An internal contradiction sitting in a document destined for an auditor.

Clause 6.1.3 requires a treatment decision for every risk in the register. Even when that decision is "accept," it has to be recorded, owned, and justified. Four risks had no decision at all.

Defect 2, two control back-links that didn't reconcile

AIMS-07 is the Statement of Applicability. It maps each of the 38 Annex A controls to the treatment actions that implement it. Two of those mappings disagreed with AIMS-06.

What didn't reconcile

ControlSaidShould have saidBecause AIMS-06 states
A.10.3 TRT-010, TRT-015 TRT-002, TRT-010, TRT-015 TRT-002 applies A.6.2.6, A.10.2, A.10.3
A.5.3 , (empty) TRT-009 TRT-009 applies A.5.2, A.5.3

An auditor tracing controls from the treatment plan into the Statement of Applicability would have found both. As a finding against the customer's AI management system. Not against our toolkit.

The failure mode in compliance documentation is silent. Every identifier cross-references something. It reads beautifully. Then an auditor pulls one thread, three months into a certification, and the chain comes apart.

What we did

We wrote a new document, AIMS-06a, the Risk Treatment Action Catalogue. It describes all twenty treatment actions in full: what each action is, the verification method, the independent verifier, the completion date, the evidence references, the risk-score movement from inherent through residual to target, the acceptance authority, and the audit notes.

Section 3 of that document contains the complete column schema, formatted the same way Annex A is presented in AIMS-05, so the two reconcile by construction rather than by hope.

We patched AIMS-06 to treat all twenty risks, and corrected both back-links in AIMS-07.

Shipped

Version 2.3 went free to every existing customer, with a written note explaining exactly what had been wrong and where. Nobody had to ask for it.

Then we checked our own explanation

We asked someone to review what we'd written about the fix. They found two counting errors in the file inventory. We corrected those too. That's on this page because leaving it out would be its own kind of dishonesty.

Why this is public

If you're a trainer, a consultancy, or a distributor putting your own brand on someone else's documentation, there's one question worth asking them:

Tell me about a time your templates were wrong.

If they can't answer, they haven't looked. This is our answer. The whole traceability chain, AIMS-05AIMS-06AIMS-06aAIMS-07, is now reconcilable by identifier in both directions, and you're welcome to test it. In 2.5 we found that the values carried alongside those identifiers had not been traced, and corrected nine of them. That entry is below.

Version history

VersionDateChange
2.5 30 Jul 2026 Corrected nine risk-score references in AIMS-06a. Each treatment action records the movement from inherent to residual to target risk and cites AIMS-05 as the source. Nine of the twenty cited figures did not match the register they pointed at. RISK-006 is 16 → 9 in AIMS-05 and was recorded as 12 → 6; RISK-011 is 10 → 4 and was recorded as 15 → 8. Seven others were wrong in the same way. AIMS-05 is authoritative and AIMS-06a now matches it in all twenty entries.

This is a defect of the same class as the one corrected in 2.3, and it survived that correction because of how we audited. In 2.3 we traced every identifier in both directions — every RISK, TRT and Annex A control reconciles, and still does. We did not trace the values carried alongside those identifiers. Identifier integrity and data integrity are different tests, and we had only run the first.

Also in this release: added a Target column to AIMS-05, so the target figures cited by AIMS-06a resolve to a real column rather than an implied one. Replaced literal dates with [DATE] placeholders across all Professional and Audit-Ready artefacts — left as-is, every document in those tiers would have shown an overdue review date from April 2027 onward. Renamed Professional and Audit-Ready document IDs so they no longer carry an AIMS- prefix, which made them look like part of the core AIMS-01..22 set. Normalised placeholder casing. Corrected the document count in the Master Guide from 22 to 23; AIMS-06a was added in 2.3 and the guide was never updated.

We now run an automated pre-release check that verifies the shipping archive against every enumeration surface — document counts, identifier coverage, risk-score reconciliation, bidirectional traceability, cross-references, placeholder consistency and document IDs — and fails the release if any of them disagree.
2.4 28 Jul 2026 Regulatory currency: the Digital Omnibus completed passage and is now Regulation (EU) 2026/1744, in force 27 July 2026. Every reference that described it as pending Council adoption now cites the Regulation. No obligation in this toolkit’s control set changed as a result of that update. The Omnibus itself did change obligations — it deferred the high-risk deadlines to 2 December 2027 and 2 August 2028, added two prohibitions, softened the AI literacy duty and introduced Article 4a. Those changes are covered on the EU AI Act page. Added an Article 50 transparency section to the Master Guide (applies 2 August 2026). Fixed a rendering fault that collapsed bulleted lists into run-on text (474 list items recovered across the Professional and Audit-Ready tiers). Repaired AIMS-06a, the only artefact failing OOXML schema validation. Corrected artefact subtitles that labelled guidance and audit-preparation material as "mandatory documented information".
2.3 9 Jul 2026 Added AIMS-06a Risk Treatment Action Catalogue (20 actions, full schema). Patched AIMS-06 to treat RISK-017 through RISK-020. Corrected A.10.3 and A.5.3 back-links in AIMS-07. Updated master index, guide, and first-week checklist.
2.1 Jun 2026 EU AI Act Article 73 staged incident-reporting obligations incorporated. Statement of Applicability expanded to all 38 Annex A controls.

Want to see the chain for yourself?

The corrected AIMS-05 → 06 → 06a → 07 traceability chain, and the free FRIA starter.

Get the free FRIA Starter See the toolkits