Book an Appointment

Governance, Risk & Compliance

ISO 27001, BSI IT-Grundschutz, NIS2, DORA, CRA and the EU AI Act: how to bring management systems, risk management and regulatory obligations into one audit-ready, integrated structure — without duplicating work.

Good governance is not paperwork — it is the operating system of your security: an integrated management system translates standards and regulation into clear responsibilities, measurable controls and evidence that holds up in an audit. These knowledge pages bundle our methodology on standards, EU regulation and day-to-day operations — from gap analysis and certification to vCISO and GRC as a Service.

Topics & knowledge pages

Each topic leads to a dedicated knowledge page with deep dives, practical guides and the matching services.

Deep Dives

In-depth knowledge pages on the topics that currently raise the most questions — with verified sources and concrete measures.

Supply Chain Security

How to systematically assess and manage the security of your IT, cloud, and AI supply chain – from supplier selection through to continuous monitoring.

View knowledge page

ISO/IEC 42001 in Practice

With ISO/IEC 42001:2023, an international, certifiable standard for an Artificial Intelligence Management System (AIMS) exists for the first time. What the standard requires, what the documentation landscape looks like — and how you can efficiently integrate an AIMS into your existing ISMS.

View knowledge page

AI Act Transparency Obligations

From August 2, 2026, the transparency obligations of Art. 50 AI Act apply to interactive AI systems, generative content, emotion recognition and deepfakes. The European Commission's draft guidelines of May 8, 2026 specify how providers and deployers are expected to implement these obligations.

View knowledge page

NIST AI RMF & Cyber AI Profile

Risk management for AI the NIST way: the AI Risk Management Framework and the new Cyber AI Profile (NIST IR 8596) give organizations a structured, prioritized framework for securing AI systems, using AI for defense and thwarting AI-enabled attacks.

View knowledge page

ISO/IEC 27001

What the standard requires, how the path to certification works and why an ISMS based on ISO/IEC 27001 holds up as evidence towards customers, partners and supervisory authorities.

View knowledge page

IT-Grundschutz

How the BSI standards, the IT-Grundschutz Compendium and the safeguarding approaches interact – and what the ongoing modernisation towards Grundschutz++ means for your ISMS.

View knowledge page

Latest news on this topic area

All news
GRC & Compliance12 August 2026Up to €15,000 in grants: GRC consulting via MID-Digitale Prozesse (NRW)The NRW state programme “Mittelstand Innovativ & Digital” funds external consulting for digitalising your GRC processes — from NIS2, CRA, EU AI Act and ISO 27001 gap analyses to roadmap, tool selection and VamiGRC implementation. At a €500 net day rate: €0 own contribution for the consulting. 2026 call: applications from 7 Sep to 1 Dec 2026 via NRW.BANK — we guide you through the entire funding process.GRC & ComplianceJune 30, 2026VamiSec is an accredited PECB Training Partner — 300+ official certifications (ISO 27001, NIS 2, EU AI Act & more)VamiSec GmbH is an accredited PECB Training Partner, delivering 300+ internationally recognized certifications — from ISO 27001 and NIS 2 to the EU AI Act — taught by active Lead Auditors who live these standards in client projects every day.GRC & ComplianceApril 2026Grundschutz++ now available as a consulting serviceWe now offer Grundschutz++ as an integrated consulting service — the combination of BSI IT-Grundschutz and ISO 27001, delivered within the Vami IMS framework. One management system, two certification goals, no duplicate effort.GRC & ComplianceSeptember 20, 2025VamiSec officially certified to ISO/IEC 27001:2022VamiSec is now officially certified to ISO/IEC 27001:2022 — issued by Proks Certification GmbH. Scope: information security consulting services, digital products, and the processing of client data. Information security and compliance as the foundation of trust.

Compliance as a system, not a binder

In an initial consultation, we show you how your standards and regulatory requirements converge into one integrated, audit-ready management system.