About Normstone

Practical by design. Accountable by default.

Normstone advises on the work that sits between ambition and proof.

Our point of view

Trust is an operating discipline.

Organizations are asked to demonstrate more than intent. Customers want assurance. Leaders need to know where exposure sits and whether controls work. AI systems add decisions that require clear ownership.

Normstone exists to make those demands manageable. Our advisory focus joins strategy with implementation, so governance is visible in decisions, processes, and evidence—not only in presentation slides.

Our principles

The standard we set for the work.

Start with the real risk.

Understand the business, its dependencies, and its exposure before selecting a framework response.

Make ownership explicit.

Controls only endure when the people who operate them know what good looks like.

Build evidence naturally.

Useful records emerge from sound operations; they should not require an annual scramble.

Respect independence.

Advisory and implementation are separate from independent certification and attestation decisions.

Market focus

Regional context. Globally recognized frameworks.

Our published guidance focuses on Europe, Australia, and Singapore, with ISO/IEC 42001 and SOC 2 at the center and ISO/IEC 27001 as a security foundation.

Explore market guidance
“The measure of a program is how it performs when the environment changes.”

Work with Normstone

Let’s build what stands up to scrutiny.

Tell us what you need to achieve. We’ll help define the right first step.

Start a conversation