AI governance readiness
An assessment of how your company uses AI, based on ISO/IEC 42001, the international standard for AI management systems, and the AI Risk Management Framework of the US National Institute of Standards and Technology (NIST AI RMF). If you decide to go further, we then implement your AI management system.
Your enterprise customers are asking how you govern AI
Your enterprise customers send you questionnaires about AI: which tools and models you use, what customer data they see and who decides on each use.
The answers are spread across engineering, product, legal and security, and nobody has the full list yet.
The assessment brings those answers together in one piece of work: which AI your company uses, what data it touches, how each use is classified by risk and which Annex A controls of ISO/IEC 42001 you need for those risks.
The risk classification includes the categories of the EU AI Act (Regulation (EU) 2024/1689): prohibited practices, high-risk systems or systems with transparency obligations.
We also read the result through the four functions of NIST AI RMF: Govern, Map, Measure and Manage.
With that base, you answer your customers with evidence and decide which uses to approve and with which controls.
What you receive
- AI use inventoryEvery AI tool and system in your company: who uses it and for what.
- Risk classificationEach AI use classified by risk, including whether it falls into one of the EU AI Act categories.
- Data mapWhat data each AI use reads or receives, including personal data and your customers' data.
- Risk matrixThe risks of each AI use, assessed and ranked by priority.
- Gap against ISO/IEC 42001 (Annex A)Which Annex A controls your company needs for its risks, which ones you already have and which are missing.
- Cross-walk to NIST AI RMFThe same gap, read through the functions, categories and subcategories of NIST AI RMF.
- Prioritized action planWhat to close first, in what order and who owns each item, within the first 90 days.
- Executive presentationThe results, presented to your leadership with the decisions that are theirs to make.
- AI management system (optional)After the assessment, the implementation of ISO/IEC 42001: from zero to prepared for certification with an accredited body, with the first internal audit and the first management review done.
How it works
-
We agree on the scope with you: which AI uses and systems the assessment covers.
-
We interview the teams that use AI and build the inventory and the data map.
-
We classify and assess the risks, check them against the Annex A controls of ISO/IEC 42001 and cross-walk the result to the functions of NIST AI RMF.
-
We deliver the prioritized action plan and present it to your leadership.
-
If you decide to go further, we implement the AI management system with your team until it is ready for certification with an accredited body, with the first internal audit and the first management review already done.
What defines the scope
- How many AI uses and systems are in scope.
- How many teams in your company use AI.
- Whether the implementation of the AI management system is added.
- The size of the organization, when the system is implemented.
How to engage
The assessment and the implementation are contracted separately, each at a fixed fee.
References
- ISO/IEC 42001:2023
- ISO/IEC 42001 · Annex A
- NIST AI RMF 1.0
- EU AI Act · Regulation (EU) 2024/1689
Related services
Governance, risk and compliance
What data your company has, who is accountable for each data set and how its quality is measured.
Data governance for AI
Governance, risk and compliance
ISO/IEC 27001, ISO/IEC 42001 and ISO 22301: from zero to prepared for certification with an accredited body.
ISO readiness
Governance, risk and compliance
Chief information security officer (CISO), data protection officer (DPO) and governance, risk and compliance (GRC).
Fractional compliance
Let's talk about the AI questions your customers are asking.
In 30 minutes we review where you stand and suggest where to start.