The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
AI governance
The governance that proves your artificial intelligence is under control.
ISO 42001 is to artificial intelligence what ISO 27001 is to information security: a certifiable management system with a defined scope, roles, risk analysis, controls, and audits. We build that system inside your company and prepare you for certification, which is conducted by an independent body. Companies that already hold 27001 reuse much of the structure, because the two standards were written to work together.
In practice, the work starts by putting the scope in writing and mapping every AI in use, including what came embedded in systems you already licensed. We then compare what exists against what the standard requires and rank the gaps by risk and effort. From that baseline come the AI use policy, with the criteria for approving new systems, and the statement of applicability, which justifies each control.
On your side, we need access to the teams that procure and operate AI, to the documents you already have, and to someone with the authority to approve policy. The management system belongs to the company, not the consultant: we write it together with the people who will run it and train them, with records.
You choose how deep to go. You can stop at the diagnostic with an action plan and execute with your own team, continue through full implementation with organized evidence, or go all the way to the audit rehearsal and support during the certifier's fieldwork, with a corrective action plan for whatever they flag.
The stages and deliverables below describe the Full compliance work modality. The other modalities appear when you request the proposal.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
AI system inventory
We map what exists, including what arrived embedded in a system already under contract and what a department signed up for without telling anyone.
Evidence gathering
We collect what already exists: documents, configurations and logs. We start from what the company has, rather than from a blank form.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Implementation
We stand the controls up together with your team, write down what needs to exist on paper and train the people who will operate them. Nothing counts as implemented until it works in practice and someone on your side can sustain it.
Evidence routine
We set out how each control proves it worked, with an owner and a frequency, so the audit does not turn into a scramble.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.