Cybersecurity governance and leadership

AI governance (ISO/IEC 42001 and AI Act)

Inventory, risks, evidence and maturity to use artificial intelligence with control and compliance.

What it involves

What we do

Adopting AI demands governance: which systems are in use, with what data, what risks they create and how compliance with the European AI Regulation is demonstrated. We build your AI management system aligned with ISO/IEC 42001.

What's included

  • Inventory of AI systems and use cases
  • Risk classification under the AI Act
  • AI and generative AI usage policies
  • Risk and impact assessment of AI systems
  • AI governance register and ISO/IEC 42001 evidence
  • Maturity assessment and adaptation plan

Who it's for

  • Organisations deploying AI in business processes
  • Providers and developers of AI systems
  • Regulated entities that must demonstrate control over AI

Deliverables

  • AI inventory and register
  • AI usage policy
  • AI risk assessment
  • ISO/IEC 42001 maturity report

Reference frameworks and standards

ISO/IEC 42001AI ActISO/IEC 23894GDPRNIST AI RMF

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does AI governance (ISO/IEC 42001 and AI Act) fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.