Confidence
is built.

Normstone builds the governance, controls, and evidence behind credible assurance. We turn demanding AI and cyber requirements into practices that hold up in the real world.

The work behind trust

Risk is real. Readiness should be, too.

Normstone works where customer assurance, AI governance, and operational security meet. We help teams define the right scope, implement controls, and show evidence of what actually works.

Where we focus

AI governance first. Assurance close behind.

ISO/IEC 42001 gives AI decisions a management system. SOC 2 answers a service assurance question. ISO/IEC 27001 provides a security foundation. NIS2 brings cyber risk and incident duties for covered EU entities under national law.

Explore all standards

Assurance follows the buyer. Governance follows the risk.

For a European or Asia Pacific technology company, a SOC 2 request may begin with international procurement. AI governance questions arise across product and internal operations. We connect those buyer and risk questions to practical delivery, while keeping local duties distinct.

How we work

Built to hold up in practice.

Our work moves from decisions to sustained operation, with ownership and evidence at every stage.

01

Understand

Define scope, obligations, current state, and material risk.

02

Design

Set priorities, owners, controls, and a practical roadmap.

03

Implement

Embed processes, build evidence, and resolve gaps with teams.

04

Sustain

Review effectiveness and adapt as the organization changes.

Work with Normstone

Let’s build what stands up to scrutiny.

Tell us what you need to achieve. We’ll help define the right first step.

Start a conversation