Advisory

AI governance & ISO/IEC 42001

Organizations need to know where AI and personal data sit in their operations, who makes decisions, and what evidence supports those decisions. We help turn that understanding into repeatable governance.

The mandate

Give AI decisions a durable management system.

Implement an ISO/IEC 42001 AI management system with clear ownership, risk assessment, lifecycle controls, and evidence.

Discuss this work

How we help

  • AI system and use-case inventory
  • ISO/IEC 42001 scope and management system design
  • AI risk and impact assessment
  • Lifecycle controls, monitoring, and records
  • Privacy and data protection alignment

What the work produces

  • An accountable AI and privacy operating model
  • Documented decisions and control ownership
  • A governance roadmap grounded in risk

Common questions

Clarify the mandate before delivery.

Does ISO/IEC 42001 apply only to AI developers?

No. The standard is intended for organizations providing or using AI systems. The appropriate management-system scope should reflect the organization’s role and the AI systems it controls.

Does ISO/IEC 42001 certification prove EU AI Act compliance?

No. ISO/IEC 42001 concerns an AI management system. EU AI Act duties depend on the organization’s role and individual system; they require a separate legal and product assessment.

How does privacy fit into an AI governance program?

Map personal data, purposes, processing roles, retention, supplier flows, and affected people for each use case. Then connect privacy decisions to AI risk, impact, and lifecycle reviews.

Work with Normstone

Let’s build what stands up to scrutiny.

Tell us what you need to achieve. We’ll help define the right first step.

Start a conversation