Resources
Questions worth answering well.
Implementation guides for ISO/IEC 42001, SOC 2, ISO/IEC 27001, NIS2, ESG, and the markets where each matters.
Start with the decision in front of you.
Follow a focused reading path, then explore the full library below.
Resource library
Search by framework, market, or the question you need to answer.
ISO/IEC 42001
ISO/IEC 42001 implementation roadmap: from AI inventory to management review
A usable sequence for building an AI management system that governs both AI products and internal use.
ISO/IEC 42001
ISO/IEC 42001 in Europe: AI governance alongside the EU AI Act
Where an AI management system can support European governance work, and where AI Act analysis must remain separate.
ISO/IEC 42001
ISO/IEC 42001 in Australia: building an AI governance system
How Australian organisations can use ISO/IEC 42001 alongside the National AI Centre’s six essential AI practices.
ISO/IEC 42001
ISO/IEC 42001 in Singapore: using AI Verify within an AI management system
A practical way to combine an organisation-wide AI management system with Singapore’s AI governance guidance and testing tools.
ISO/IEC 42001
How to build an AI inventory for ISO/IEC 42001
The fields, ownership decisions, and review triggers that make an AI inventory useful beyond an initial assessment.
ISO/IEC 42001
Third-party AI procurement: questions to ask before deployment
A risk-based intake and oversight method for bought models, AI-enabled software, and outsourced AI services.
ISO/IEC 42001
AI impact assessment for ISO/IEC 42001: make the decision traceable
A practical review of purpose, affected people, foreseeable harm, mitigations, and approval for each material AI use.
ISO/IEC 42001
Generative AI release controls: from evaluation to monitoring
How to turn AI governance into evidence at each change to a generative AI product or workflow.
ISO/IEC 42001
ISO/IEC 42001 internal audit and management review: what to test
An audit and review cycle that tests how AI decisions operate, not just whether templates exist.
ISO/IEC 42001
ISO/IEC 42001 and the NIST AI RMF: how to use both
Use the management system and voluntary risk framework for their different strengths without turning either into a checklist.
ISO/IEC 42001
EU AI Act role mapping before an ISO/IEC 42001 program
Identify provider, deployer, and other roles for each AI system, then connect applicable duties to the AI management system.
AI governance
AI governance starts with an inventory
Before a policy or certification target, establish what AI is used, who owns it, and what decisions it shapes.
SOC 2
SOC 2 for European SaaS companies: when it helps and how to prepare
A buyer-led guide to SOC 2 in Europe: the right trigger, a defensible scope, and how it sits beside ISO 27001 and GDPR.
SOC 2
SOC 2 in Australia: a practical path for technology providers
How Australian technology firms can use SOC 2 for customer assurance while keeping local privacy and sector obligations in view.
SOC 2
SOC 2 in Singapore: preparing for cross-border customer assurance
A practical SOC 2 plan for Singapore-based service providers, with clear boundaries around PDPA and financial-sector requests.
SOC 2
SOC 2 Type 1 vs Type 2: choose the report your buyers can use
A practical choice between design at a date and operating effectiveness over a period, with buyer, timing, and evidence questions to settle first.
SOC 2
SOC 2 system description: define the service before the controls
How to describe the service, dependencies, customer responsibilities, and boundaries that make a SOC 2 report useful in procurement.
SOC 2
The SOC 2 evidence calendar: build records into everyday work
A control-owner plan for producing complete, traceable evidence through a Type 2 reporting period, without inventing work at the end.
SOC 2
How to review a SOC 2 report for a cross-border SaaS purchase
A report-reading checklist for European, Australian, and Singapore buyers: opinion, scope, period, exceptions, and local obligations.
SOC 2
SOC 2 and subservice organizations: draw the real control boundary
Account for cloud and outsourced providers, user responsibilities, and evidence handoffs in the system description.
SOC 2
Which SOC 2 Trust Services Criteria should a provider include?
Choose reporting criteria based on the service and buyer concern rather than adding categories for appearance.
SOC 2
Answering a SOC 2 request from a US buyer when your team is in Europe or APAC
Turn a cross-border procurement request into a scoped assurance plan without claiming SOC 2 is a local legal requirement.
SOC 2
SOC 2 readiness beyond the checklist
How to define the system, operate controls, and prepare evidence before the reporting period becomes a scramble.
ISO/IEC 27001
ISO/IEC 27001 Statement of Applicability: make every control decision explainable
Connect risk treatment, Annex A control selection, ownership, implementation, and evidence in one working record.
ISO/IEC 27001
ISO/IEC 27017 and 27018: cloud security and PII controls in practice
Use current cloud guidance to divide customer and provider responsibilities and protect personal information processed in public cloud services.
ISO 27001
ISO 27001: from scope to evidence
A practical sequence for building an ISMS that can withstand independent assessment and remain useful afterward.
NIS2
NIS2 supplier security and incident readiness: build the operating record
A practical route from NIS2 applicability to supplier oversight, incident decisions, and evidence across an EU operating footprint.
NIST CSF 2.0
NIST CSF 2.0 Profiles: turn cybersecurity outcomes into a roadmap
Use a Current and Target Profile to connect business priorities, risk gaps, control ownership, and measurable improvement.
NIS2
NIS2: the first decisions that matter
A clear starting point for applicability, governance, incident processes, and supplier security.
Cross-framework
ISO 27001, SOC 2, and ISO 42001: what to share and what to keep distinct
Three different assurance questions, one disciplined control operation. A guide to sequencing and reusing evidence responsibly.
Cross-framework
One control system, many frameworks
How to reduce duplicated effort across ISO 27001, SOC 2, ISO 42001, and regulatory obligations without flattening their differences.
ESG & sustainability
ESG reporting readiness: build disclosure controls before drafting
A practical way to define reporting scope, materiality, data ownership, and review evidence across sustainability disclosures.
ESG & sustainability
ISO 14064-1 GHG inventory: from boundaries to verification readiness
Define an organizational emissions inventory with controlled activity data, documented calculations, and a clear independent handoff.
ESG & sustainability
ISO 14001:2026 implementation: turn environmental aspects into operations
Scope an environmental management system, assign action owners, monitor performance, and prepare for independent assessment.
ESG & sustainability
ISO 50001 energy management: baseline, indicators, and improvement
Build an energy review, performance indicators, operating actions, and evidence that survives the reporting cycle.
ISO/IEC 27701
ISO/IEC 27701:2025 privacy management: a new implementation starting point
How to scope a privacy information management system under the current standalone edition and connect it with security controls.
ISO 22301
ISO 22301 business continuity: build from critical service decisions
Translate business impact, dependencies, recovery choices, exercises, and review into a workable continuity management system.
ISO/IEC 20000-1
ISO/IEC 20000-1 service management: make delivery measurable
Scope the services, build a service management system, and connect incidents, changes, suppliers, and improvement to customer outcomes.
TISAX
TISAX readiness for automotive suppliers: scope, ISA, and evidence
Prepare an automotive information security assessment around partner requirements, assessment scope, and an operational ISMS.
DORA
DORA is an operating model, not a document set
Where ICT risk, incidents, testing, and third-party oversight meet in day-to-day operations.
No resources match that search. Try another topic or keyword.
Work with Normstone
Let’s build what stands up to scrutiny.
Tell us what you need to achieve. We’ll help define the right first step.