VeritomeHelp Centre
/
Browse documentation
Programmes

Phases and gates: why the next step is locked

Each programme runs in phases; a phase is locked until the one before it is complete. The same rule the EU AI Act journey uses, applied to the standards — plus the GDPR bucket that sits outside the path.

Updated Veritome documentation

Every programme runs in phases, and a phase is locked until every counted step in the phases before it is complete. This is the rule the EU AI Act journey already applies (Classify → Scope → Implement → Assess → Register → Monitor); the programmes borrow it verbatim.

The phases, by programme

ProgrammePhases
ISO/IEC 42001Establish · Plan · Support · Operate · Evaluate & improve · Certification audit
ISO/IEC 27001Establish · Plan · Support · Operate · Evaluate & improve · Certification audit
GDPREstablish · Map · Protect · Operate — plus Conditional / specialist, outside the path
NIST AI RMFGovern · Map · Measure · Manage

The two ISO programmes share the Annex SL spine every ISO management-system standard is built on, which is why their phases match. The GDPR is an accountability regime, not a management system, so its phases follow the order data-protection work happens in. NIST AI RMF 1.0 is its four functions and ends in a profile document, not a readiness gate.

Why gates

Because the standards are built that way. You cannot treat risks you have not assessed; you cannot audit a management system whose scope is not written; a management review with nothing to review is a meeting, not a record. The gate stops the programme producing records in an order an auditor would reject.

Reading the card

On Frameworks → Programme each card shows the phase strip with the gate visible, the steps evidenced over the steps that count, and the next step — the first open step in the first unfinished phase, in plan order. A locked phase says which phase must finish first. A step counts as complete when it is Evidenced (approved) or Done by overlap; a step marked Not applicable is outside every count.

Empty phases

A phase with no applicable steps counts as complete, so a programme never stalls on work it does not have.

GDPR's four phases, and the bucket outside them

The GDPR programme runs on Establish · Map · Protect · Operate: appoint and scope, map the processing, protect it, then run the clocks — breach notification, data-subject requests, the periodic review.

Under the strip sits Conditional / specialist — consent, the EU representative, international transfers, supervisory-authority cooperation, codes of conduct and certification. It is outside the path: never locked, never a gate. Three of its steps apply only when something is true of you:

  • Consent — when processing relies on consent, including children's online services.
  • International transfers — when personal data leaves the EU/EEA.
  • Codes and certification — when you join an approved code of conduct or certification scheme.

They start Not applicable. The transfers step switches itself on when a system on your register is flagged for cross-border transfer; the other two have no register fact behind them, so you switch them on by setting the status to Not started. A step you do not need stays Not applicable and is outside every count. The plan never overrides a status a person set, in either direction.

Coverage says "Workflow assigned"

On Frameworks → Coverage a requirement with a step behind it reads Workflow assigned — not "covered", not "implemented". A workflow existing for a clause is not the clause being done; that comes only from the step's record being approved.