Annual Update Methodology by Kai London
AI regulation, standards and threats move faster than most governance cycles. This volume gives you a repeatable annual method — what to re-scan, what to re-test, what to retire, and how to show the board the programme has genuinely been refreshed rather than reprinted.
Available on Amazon.
What is inside
Regulatory horizon scanning
Tracking change across jurisdictions and deciding which developments actually require action.
Standards refresh
Absorbing revisions to the standards you rely on without restarting the control mapping each time.
Threat and incident review
Feeding the year's threat developments and your own incidents back into the control set.
Control reassessment
Re-testing whether controls still fit the systems in place, and retiring what no longer earns its keep.
Assurance cycle
Planning the year's testing, internal audit coverage and external assessment so they reinforce each other.
Board reporting and evidence
An annual report that shows movement — what changed, what it cost, and what remains open.
Who it is for: AI governance leads running an established programme, compliance and assurance teams, internal audit, and risk committee secretaries who own the annual cycle.
A governance programme that has not changed in a year has not been maintained. It has been filed.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.