VeritomeHelp Centre
/
Browse documentation
Programmes

Programmes: a standard as a path, not a list

Switch a framework on and it becomes a programme — ordered steps in gated phases, each producing a record. The standards stop being a checklist you tick and become work you do once.

Updated Veritome documentation

A programme is what a framework becomes when you switch it on under Frameworks. There is one programme per enabled framework — ISO/IEC 42001, ISO/IEC 27001, NIST AI RMF or the GDPR — made of steps generated from record templates and arranged in phases with gates between them. The EU AI Act never has a programme: its journey is the obligation engine's six phases per system, and the programmes borrow that model rather than replace it.

Why a path

A standard read as a list is 38 or 93 controls to populate, in no order, all at once. Read as a path it is what to do this week: the steps that are open, the record each one produces, the gate that opens the next phase. That is also how a certification body reads it — a Stage 1 audit asks whether the management system exists on paper, Stage 2 whether it runs.

What a step is

A step is a record template placed in a programme: guidance that paraphrases what the clause requires (never the standard's licensed text), the questions the record answers, and the evidence an auditor would accept. Every template was generated from the owner's verified framework matrix and carries a named reviewer's stamp; the guidance is regenerated from that matrix, never edited by hand.

Each step names three kinds of reference, and the distinction matters:

  • Closes — the clauses the step's record answers. These are what the Coverage matrix maps and what the drawer shows as the step's own requirements.
  • Satisfies — the seeded requirement rows the approved record is credited against. Credit, evidence fan-out and the Statement of Applicability read only these.
  • Related — supporting links to neighbouring duties in other frameworks. They are shown in the drawer so you can find the adjacent requirement, and they are never credited: a related link files no evidence and covers nothing.

Some records are genuinely shared. The ISO/IEC 42001 and ISO/IEC 27001 programmes share one record for the clause 4–10 work both standards ask for — context, roles, risk, objectives, competence, internal audit, management review and the rest. Complete it once and it is complete in both.

Where things live

  • Frameworks — five tabs: Frameworks (enable a framework, set its scope and target date), Programme (one card per programme: phase strip, steps evidenced, the next step, target date, and the certification body, certificate reference and next surveillance audit an admin records by hand), Coverage (the requirement-by-requirement matrix and its CSV), Requirements (the catalogue) and Changes (regulatory watch).
  • Obligations — programme steps appear as organisation-scope rows beside the per-system obligations, with a Programme · Phase column and a "Scope: organisation" filter.
  • Controls — the controls your approved steps produced.
  • Policies — the organisation-scope records (the AI policy, the ISMS scope, the literacy programme, the privacy governance policy).
  • Documents — every record a programme produces is a row in the document register while that programme is active, and opens in the same step drawer.

Re-plan on a programme card regenerates it — after a template update, say. Regenerating never overwrites a step status a person set.

What a programme costs, and what is live

Programmes are not plan tiers. ISO/IEC 42001 and the NIST AI RMF crosswalk are included from the Govern plan up — no per-framework fee; ISO/IEC 27001 is the one programme sold separately, €199 a month on Govern and already part of Manage and Enterprise — there is no bundle. The GDPR programme comes with the Govern plan and above, because personal data through an AI system is a Govern-level duty rather than a certification project.

One honest note on timing: the three certifiable programmes — ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF — are not going out with the launch. While the cross-mapping is switched off, Controls and Frameworks are absent from the rail and the pricing page states the date the mapping lands. The GDPR programme and the EU AI Act journey are live regardless.