AI Security & Governance series · Annual update

Annual Update Methodology by Kai London

AI regulation, standards and threats move faster than most governance cycles. This volume gives you a repeatable annual method — what to re-scan, what to re-test, what to retire, and how to show the board the programme has genuinely been refreshed rather than reprinted.

Available on Amazon.

What is inside

Regulatory horizon scanning

Tracking change across jurisdictions and deciding which developments actually require action.

Standards refresh

Absorbing revisions to the standards you rely on without restarting the control mapping each time.

Threat and incident review

Feeding the year's threat developments and your own incidents back into the control set.

Control reassessment

Re-testing whether controls still fit the systems in place, and retiring what no longer earns its keep.

Assurance cycle

Planning the year's testing, internal audit coverage and external assessment so they reinforce each other.

Board reporting and evidence

An annual report that shows movement — what changed, what it cost, and what remains open.

Who it is for: AI governance leads running an established programme, compliance and assurance teams, internal audit, and risk committee secretaries who own the annual cycle.

EU AI ActISO/IEC 42001NIST AI RMFISO/IEC 27001DORA

A governance programme that has not changed in a year has not been maintained. It has been filed.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.