Resources

Questions worth answering well.

Implementation guides for ISO/IEC 42001, SOC 2, ISO/IEC 27001, NIS2, ESG, and the markets where each matters.

Start with the decision in front of you.

Follow a focused reading path, then explore the full library below.

AI management

Build governance around real uses.

Create an AI inventory Assess third-party AI
SOC 2 reporting

Define the report buyers need.

Type 1 or Type 2 Plan the evidence period
Information security

Make an ISMS operational.

Scope to evidence Statement of Applicability
NIS2

Turn EU cyber duties into practice.

Decide applicability first Build the operating record
ESG & sustainability

Put evidence behind the claim.

Build disclosure controls Prepare a GHG inventory
Regional context

Apply standards across markets.

ISO 42001 in Australia ISO 42001 in Singapore

Resource library

Search by framework, market, or the question you need to answer.

Implementation guide4 min read

ISO/IEC 42001

ISO/IEC 42001 implementation roadmap: from AI inventory to management review

A usable sequence for building an AI management system that governs both AI products and internal use.

Read resource
Market guide4 min read

ISO/IEC 42001

ISO/IEC 42001 in Europe: AI governance alongside the EU AI Act

Where an AI management system can support European governance work, and where AI Act analysis must remain separate.

Read resource
Market guide5 min read

ISO/IEC 42001

ISO/IEC 42001 in Australia: building an AI governance system

How Australian organisations can use ISO/IEC 42001 alongside the National AI Centre’s six essential AI practices.

Read resource
Market guide5 min read

ISO/IEC 42001

ISO/IEC 42001 in Singapore: using AI Verify within an AI management system

A practical way to combine an organisation-wide AI management system with Singapore’s AI governance guidance and testing tools.

Read resource
Implementation guide5 min read

ISO/IEC 42001

How to build an AI inventory for ISO/IEC 42001

The fields, ownership decisions, and review triggers that make an AI inventory useful beyond an initial assessment.

Read resource
Implementation guide5 min read

ISO/IEC 42001

Third-party AI procurement: questions to ask before deployment

A risk-based intake and oversight method for bought models, AI-enabled software, and outsourced AI services.

Read resource
Implementation guide5 min read

ISO/IEC 42001

AI impact assessment for ISO/IEC 42001: make the decision traceable

A practical review of purpose, affected people, foreseeable harm, mitigations, and approval for each material AI use.

Read resource
Implementation guide5 min read

ISO/IEC 42001

Generative AI release controls: from evaluation to monitoring

How to turn AI governance into evidence at each change to a generative AI product or workflow.

Read resource
Assurance readiness5 min read

ISO/IEC 42001

ISO/IEC 42001 internal audit and management review: what to test

An audit and review cycle that tests how AI decisions operate, not just whether templates exist.

Read resource
Framework comparison5 min read

ISO/IEC 42001

ISO/IEC 42001 and the NIST AI RMF: how to use both

Use the management system and voluntary risk framework for their different strengths without turning either into a checklist.

Read resource
Market guide5 min read

ISO/IEC 42001

EU AI Act role mapping before an ISO/IEC 42001 program

Identify provider, deployer, and other roles for each AI system, then connect applicable duties to the AI management system.

Read resource
Implementation guide3 min read

AI governance

AI governance starts with an inventory

Before a policy or certification target, establish what AI is used, who owns it, and what decisions it shapes.

Read resource
Market guide4 min read

SOC 2

SOC 2 for European SaaS companies: when it helps and how to prepare

A buyer-led guide to SOC 2 in Europe: the right trigger, a defensible scope, and how it sits beside ISO 27001 and GDPR.

Read resource
Market guide4 min read

SOC 2

SOC 2 in Australia: a practical path for technology providers

How Australian technology firms can use SOC 2 for customer assurance while keeping local privacy and sector obligations in view.

Read resource
Market guide4 min read

SOC 2

SOC 2 in Singapore: preparing for cross-border customer assurance

A practical SOC 2 plan for Singapore-based service providers, with clear boundaries around PDPA and financial-sector requests.

Read resource
Decision guide5 min read

SOC 2

SOC 2 Type 1 vs Type 2: choose the report your buyers can use

A practical choice between design at a date and operating effectiveness over a period, with buyer, timing, and evidence questions to settle first.

Read resource
Implementation guide5 min read

SOC 2

SOC 2 system description: define the service before the controls

How to describe the service, dependencies, customer responsibilities, and boundaries that make a SOC 2 report useful in procurement.

Read resource
Implementation guide5 min read

SOC 2

The SOC 2 evidence calendar: build records into everyday work

A control-owner plan for producing complete, traceable evidence through a Type 2 reporting period, without inventing work at the end.

Read resource
Buyer guide5 min read

SOC 2

How to review a SOC 2 report for a cross-border SaaS purchase

A report-reading checklist for European, Australian, and Singapore buyers: opinion, scope, period, exceptions, and local obligations.

Read resource
Implementation guide5 min read

SOC 2

SOC 2 and subservice organizations: draw the real control boundary

Account for cloud and outsourced providers, user responsibilities, and evidence handoffs in the system description.

Read resource
Buyer question4 min read

SOC 2

Which SOC 2 Trust Services Criteria should a provider include?

Choose reporting criteria based on the service and buyer concern rather than adding categories for appearance.

Read resource
Market guide5 min read

SOC 2

Answering a SOC 2 request from a US buyer when your team is in Europe or APAC

Turn a cross-border procurement request into a scoped assurance plan without claiming SOC 2 is a local legal requirement.

Read resource
Implementation guide4 min read

SOC 2

SOC 2 readiness beyond the checklist

How to define the system, operate controls, and prepare evidence before the reporting period becomes a scramble.

Read resource
Implementation guide5 min read

ISO/IEC 27001

ISO/IEC 27001 Statement of Applicability: make every control decision explainable

Connect risk treatment, Annex A control selection, ownership, implementation, and evidence in one working record.

Read resource
Standard guide5 min read

ISO/IEC 27001

ISO/IEC 27017 and 27018: cloud security and PII controls in practice

Use current cloud guidance to divide customer and provider responsibilities and protect personal information processed in public cloud services.

Read resource
Implementation guide4 min read

ISO 27001

ISO 27001: from scope to evidence

A practical sequence for building an ISMS that can withstand independent assessment and remain useful afterward.

Read resource
Executive briefing5 min read

NIS2

NIS2 supplier security and incident readiness: build the operating record

A practical route from NIS2 applicability to supplier oversight, incident decisions, and evidence across an EU operating footprint.

Read resource
Implementation guide5 min read

NIST CSF 2.0

NIST CSF 2.0 Profiles: turn cybersecurity outcomes into a roadmap

Use a Current and Target Profile to connect business priorities, risk gaps, control ownership, and measurable improvement.

Read resource
Executive briefing3 min read

NIS2

NIS2: the first decisions that matter

A clear starting point for applicability, governance, incident processes, and supplier security.

Read resource
Framework comparison4 min read

Cross-framework

ISO 27001, SOC 2, and ISO 42001: what to share and what to keep distinct

Three different assurance questions, one disciplined control operation. A guide to sequencing and reusing evidence responsibly.

Read resource
Perspective3 min read

Cross-framework

One control system, many frameworks

How to reduce duplicated effort across ISO 27001, SOC 2, ISO 42001, and regulatory obligations without flattening their differences.

Read resource
Implementation guide6 min read

ESG & sustainability

ESG reporting readiness: build disclosure controls before drafting

A practical way to define reporting scope, materiality, data ownership, and review evidence across sustainability disclosures.

Read resource
Implementation guide5 min read

ESG & sustainability

ISO 14064-1 GHG inventory: from boundaries to verification readiness

Define an organizational emissions inventory with controlled activity data, documented calculations, and a clear independent handoff.

Read resource
Implementation guide5 min read

ESG & sustainability

ISO 14001:2026 implementation: turn environmental aspects into operations

Scope an environmental management system, assign action owners, monitor performance, and prepare for independent assessment.

Read resource
Implementation guide5 min read

ESG & sustainability

ISO 50001 energy management: baseline, indicators, and improvement

Build an energy review, performance indicators, operating actions, and evidence that survives the reporting cycle.

Read resource
Standard guide5 min read

ISO/IEC 27701

ISO/IEC 27701:2025 privacy management: a new implementation starting point

How to scope a privacy information management system under the current standalone edition and connect it with security controls.

Read resource
Implementation guide5 min read

ISO 22301

ISO 22301 business continuity: build from critical service decisions

Translate business impact, dependencies, recovery choices, exercises, and review into a workable continuity management system.

Read resource
Implementation guide5 min read

ISO/IEC 20000-1

ISO/IEC 20000-1 service management: make delivery measurable

Scope the services, build a service management system, and connect incidents, changes, suppliers, and improvement to customer outcomes.

Read resource
Sector guide5 min read

TISAX

TISAX readiness for automotive suppliers: scope, ISA, and evidence

Prepare an automotive information security assessment around partner requirements, assessment scope, and an operational ISMS.

Read resource
Executive briefing3 min read

DORA

DORA is an operating model, not a document set

Where ICT risk, incidents, testing, and third-party oversight meet in day-to-day operations.

Read resource

Work with Normstone

Let’s build what stands up to scrutiny.

Tell us what you need to achieve. We’ll help define the right first step.

Start a conversation