Advisory
AI governance & ISO/IEC 42001
Organizations need to know where AI and personal data sit in their operations, who makes decisions, and what evidence supports those decisions. We help turn that understanding into repeatable governance.
The mandate
Give AI decisions a durable management system.
Implement an ISO/IEC 42001 AI management system with clear ownership, risk assessment, lifecycle controls, and evidence.
Discuss this workHow we help
- AI system and use-case inventory
- ISO/IEC 42001 scope and management system design
- AI risk and impact assessment
- Lifecycle controls, monitoring, and records
- Privacy and data protection alignment
What the work produces
- An accountable AI and privacy operating model
- Documented decisions and control ownership
- A governance roadmap grounded in risk
Common questions
Clarify the mandate before delivery.
Does ISO/IEC 42001 apply only to AI developers?
No. The standard is intended for organizations providing or using AI systems. The appropriate management-system scope should reflect the organization’s role and the AI systems it controls.
Does ISO/IEC 42001 certification prove EU AI Act compliance?
No. ISO/IEC 42001 concerns an AI management system. EU AI Act duties depend on the organization’s role and individual system; they require a separate legal and product assessment.
How does privacy fit into an AI governance program?
Map personal data, purposes, processing roles, retention, supplier flows, and affected people for each use case. Then connect privacy decisions to AI risk, impact, and lifecycle reviews.
Primary references
Work with Normstone
Let’s build what stands up to scrutiny.
Tell us what you need to achieve. We’ll help define the right first step.