Skip to content

Frameworks

AI governance you can show somebody

Your customers have started asking how your AI systems are governed, and the EU AI Act has started to apply. We assess you against ISO/IEC 42001 or the NIST AI Risk Management Framework and give you something to answer with.

Who this is for

Building it, embedding it, or answering for it

The question arrives from three directions, and they want different evidence.

  • Companies building AI systems

    Where the model or the product is yours, governance is about the lifecycle: data quality, validation, deployment, monitoring, and who decides that a system is fit to ship.

  • Companies embedding somebody else’s

    Using a third-party model does not transfer the accountability. Your customers will ask you what it does with their data, how it fails, and who checked — and the vendor’s documentation will not answer all three.

  • Companies being asked by customers

    Increasingly the question is a procurement one. An AI section in a security questionnaire is now as routine as an encryption section, and it is answered far more cheaply from an assessment than from scratch.

What is assessed

Two frameworks, and the regulation behind the question

Which one fits depends on whether you need something certifiable, something practical, or something that maps to a European obligation.

  1. 01

    ISO/IEC 42001:2023

    The AI management system standard — and the one you can be certified against by an accredited body. It has the same management-system shape as ISO 27001: scope, policy, risk assessment, objectives, controls, internal audit, management review. If you already hold ISO 27001, most of the surrounding machinery is reusable.

  2. 02

    NIST AI Risk Management Framework

    Voluntary, practical, and organised into four functions — Govern, Map, Measure and Manage. There is no certificate at the end, which makes it the lighter starting point when what you need is a defensible internal position rather than a badge.

  3. 03

    The EU AI Act

    A regulation, applying in phases since 2024, with obligations that depend on the risk class of the system rather than on your size. Neither framework above is a compliance route to it, but both put you in a materially better position to work out which class you are in and to evidence what you do about it.

Related

If the question is really about how you build software

AI governance questions often turn out to be development-practice questions wearing a newer word.

  1. 01

    NIST Secure Software Development Framework

    Four practice groups — prepare the organization, protect the software, produce well-secured software, and respond to vulnerabilities. Where the concern is your pipeline rather than your model, this is the more useful assessment.

How it runs

Four steps, and a few hours of your time

Short, and deliberately not an audit. The output is a position you can defend and a plan you can work through.

  1. 01

    Scoping call

    About an hour. Which systems are in scope, whether you build or embed, and who is already asking you the question.

  2. 02

    Assessment

    A structured questionnaire against the chosen framework, run with the people who own the systems and the data rather than with whoever answers the security mailbox.

  3. 03

    Gap report and plan

    A few business days. Findings mapped to the framework’s functions or controls, a remediation plan with effort and priority, and a posture report for management.

  4. 04

    Debrief

    A working session on what to fix first, and on how to answer the questionnaire that prompted this in the first place.

What this is not

Readiness, not certification — and not legal advice

ISO/IEC 42001 certification is issued by an accredited certification body, and a firm that helped build your management system cannot be the one that certifies it. We take you up to that point and prepare you for it.

We do not classify your systems under the EU AI Act for you. Whether something is a high-risk system within the meaning of the regulation is a legal determination, and we will tell you when a question has crossed into one rather than answering it anyway.

And we do not evaluate your models. Bias testing, red-teaming and model evaluation are their own discipline; what we assess is whether you have the governance to commission that work, act on it and evidence it.

An AI section in a customer questionnaire?

Tell us what you build or embed, and who is asking. We will tell you which framework answers it and where you stand.