Site map
Explore Normstone.
A complete index of advisory services, standards, market perspectives, and practical resources.
Advisory
Standards, schemes & obligations
Markets
Resources
- ISO/IEC 42001 implementation roadmap: from AI inventory to management review
- ISO/IEC 42001 in Europe: AI governance alongside the EU AI Act
- ISO/IEC 42001 in Australia: building an AI governance system
- ISO/IEC 42001 in Singapore: using AI Verify within an AI management system
- How to build an AI inventory for ISO/IEC 42001
- Third-party AI procurement: questions to ask before deployment
- AI impact assessment for ISO/IEC 42001: make the decision traceable
- Generative AI release controls: from evaluation to monitoring
- ISO/IEC 42001 internal audit and management review: what to test
- ISO/IEC 42001 and the NIST AI RMF: how to use both
- EU AI Act role mapping before an ISO/IEC 42001 program
- AI governance starts with an inventory
- SOC 2 for European SaaS companies: when it helps and how to prepare
- SOC 2 in Australia: a practical path for technology providers
- SOC 2 in Singapore: preparing for cross-border customer assurance
- SOC 2 Type 1 vs Type 2: choose the report your buyers can use
- SOC 2 system description: define the service before the controls
- The SOC 2 evidence calendar: build records into everyday work
- How to review a SOC 2 report for a cross-border SaaS purchase
- SOC 2 and subservice organizations: draw the real control boundary
- Which SOC 2 Trust Services Criteria should a provider include?
- Answering a SOC 2 request from a US buyer when your team is in Europe or APAC
- SOC 2 readiness beyond the checklist
- ISO/IEC 27001 Statement of Applicability: make every control decision explainable
- ISO/IEC 27017 and 27018: cloud security and PII controls in practice
- ISO 27001: from scope to evidence
- NIS2 supplier security and incident readiness: build the operating record
- NIST CSF 2.0 Profiles: turn cybersecurity outcomes into a roadmap
- NIS2: the first decisions that matter
- ISO 27001, SOC 2, and ISO 42001: what to share and what to keep distinct
- One control system, many frameworks
- ESG reporting readiness: build disclosure controls before drafting
- ISO 14064-1 GHG inventory: from boundaries to verification readiness
- ISO 14001:2026 implementation: turn environmental aspects into operations
- ISO 50001 energy management: baseline, indicators, and improvement
- ISO/IEC 27701:2025 privacy management: a new implementation starting point
- ISO 22301 business continuity: build from critical service decisions
- ISO/IEC 20000-1 service management: make delivery measurable
- TISAX readiness for automotive suppliers: scope, ISA, and evidence
- DORA is an operating model, not a document set