Confidence
is built.
Normstone builds the governance, controls, and evidence behind credible assurance. We turn demanding AI and cyber requirements into practices that hold up in the real world.
The work behind trust
Risk is real. Readiness should be, too.
Normstone works where customer assurance, AI governance, and operational security meet. We help teams define the right scope, implement controls, and show evidence of what actually works.
What we do
From obligation to operation.
Focused implementation and advisory for organizations facing consequential trust decisions.
Where we focus
AI governance first. Assurance close behind.
ISO/IEC 42001 gives AI decisions a management system. SOC 2 answers a service assurance question. ISO/IEC 27001 provides a security foundation. NIS2 brings cyber risk and incident duties for covered EU entities under national law.
Explore all standardsAssurance follows the buyer. Governance follows the risk.
For a European or Asia Pacific technology company, a SOC 2 request may begin with international procurement. AI governance questions arise across product and internal operations. We connect those buyer and risk questions to practical delivery, while keeping local duties distinct.
Market perspectives
Designed for the questions buyers ask.
Each market page connects global assurance frameworks to distinct local context.
How we work
Built to hold up in practice.
Our work moves from decisions to sustained operation, with ownership and evidence at every stage.
Understand
Define scope, obligations, current state, and material risk.
Design
Set priorities, owners, controls, and a practical roadmap.
Implement
Embed processes, build evidence, and resolve gaps with teams.
Sustain
Review effectiveness and adapt as the organization changes.
Resources
Guidance for the next decision.
Practical answers on AI management, SOC 2, and shared control design.
ISO/IEC 42001
ISO/IEC 42001 implementation roadmap: from AI inventory to management review
A usable sequence for building an AI management system that governs both AI products and internal use.
ISO/IEC 42001
AI impact assessment for ISO/IEC 42001: make the decision traceable
A practical review of purpose, affected people, foreseeable harm, mitigations, and approval for each material AI use.
SOC 2
SOC 2 for European SaaS companies: when it helps and how to prepare
A buyer-led guide to SOC 2 in Europe: the right trigger, a defensible scope, and how it sits beside ISO 27001 and GDPR.
Work with Normstone
Let’s build what stands up to scrutiny.
Tell us what you need to achieve. We’ll help define the right first step.