The organizational wrapper around the controls.
Cortex runs one management system across quality, information security and AI. The controls are enforced in code: a hash-chained audit log, a capability policy, and approval gates an agent cannot resolve for itself. These twelve documents are the organisational half of the same system, published in full: each names the code path behind every claim it makes, and each names its own open items rather than omitting them.itting them.
An auditor reads both halves.
A control that works but is undocumented is a finding, and so is a policy that is documented but never executed. These documents close the first problem. Only operating them closes the second, which is why every status below is the honest one rather than the flattering one.
Management system
One system across quality, security and AI, and the corrective action loop that closes what it finds.
2 documentsCortex integrated management system
One management system covering quality, information security and AI management across the Cortex platform, defining its scope, accountable roles, objectives, review cycle and improvement path.
Corrective and preventive action register
The organisation's record of what went wrong, why, what was changed so it stops going wrong, and the evidence that the change worked.
Information security
The ISO/IEC 27001 core: scope and applicability, risk, access, incidents, continuity, suppliers, vulnerabilities.
7 documentsISMS scope and Statement of Applicability
The boundary of the information security management system, and a control by control statement of which Annex A controls apply to Cortex, where each one stands and what evidence proves it.
Risk register
The information security and AI risks Cortex actually carries, scored with a stated method, treated with controls that point at code, and left with a residual level that somebody owns.
Access review procedure
The periodic review that confirms the human, agent and machine authority a Cortex stack currently grants is still the authority it should grant.
Incident response and breach notification
How an event on a Cortex stack is classified, contained, recovered and reviewed, and what the GDPR and the EU AI Act require once personal data or a high-risk AI system is involved.
Business continuity and disaster recovery
What a Cortex stack must be able to recover from, in what dependency order, how fast and with how much data loss accepted, together with the two coverage findings that no target in it can hide.
Supplier and sub-processor register
The single list of every third party a Cortex stack depends on, what each one can see, which of them are GDPR sub-processors, and what happens when one of them fails.
Vulnerability management
How technical vulnerabilities in the five layers a Cortex stack depends on are found, ranked, fixed and excepted, and where that coverage is currently advisory rather than enforced.
AI management
ISO/IEC 42001: the policy, the register of what is actually running, and the method for assessing its impact.
3 documentsAI policy
What the organisation that builds and operates Cortex commits to when it uses and ships autonomous agents, which principle is enforced by which code path, what is prohibited outright, and how it reads its own role under the EU AI Act.
AI system inventory
The register of every system in the portfolio that uses AI, recording for each one how autonomously it runs, which models it reaches, what data it touches, who watches it and how it is classified under the EU AI Act.
AI system impact assessment method and template
When an AI system's impact on people must be assessed, the nine-step method for doing it, and a completed worked assessment of the most autonomous system in the portfolio.
Conformity-ready, not certified. Every control ISO 9001, ISO/IEC 27001 and ISO/IEC 42001 require is implemented in code or documented as procedure, and the evidence they ask for falls out of normal operation rather than being assembled before an audit. What separates readiness from a certificate is a completed management cycle with its records, an internal audit pass and an accredited certification body: operating work, not engineering work.
Start with the gaps.
The fastest way to judge a management system is to read what it admits. The risk register and the vulnerability procedure are the two documents that say the most about how this one is run.