Know what you run
A register of every AI system and the records behind it.
AI governance services
We start with a register of every AI system you run: who owns it, what data it sees and what it may decide alone. Policy and impact assessments build on it.
What we help you put in place
Pick the group you need, or book a call and we'll suggest where to start.
A register of every AI system and the records behind it.
A customer wants a certificate, you serve the EU, or your board wants a baseline.
Model risk your regulator asks about, AI inside your vendors' products, and testing the systems themselves.
AI governance is part of our governance, risk and compliance services.
Where governance starts
Governance asks who approved a system, what it may decide alone, who answers when it's wrong, and whether you can explain a disputed decision months later.
AI security asks whether someone can attack it: through prompt injection (instructions hidden in text it reads), poisoned training data or an agent holding a credential it shouldn't have. Our AI security services test and harden AI systems against the OWASP LLM Top 10 and MITRE ATLAS threat lists, and set up the logging and alerts your team runs. Both stall on the same missing document: a list of the AI systems you run.
Models you trained are easy to name. The rest is harder to find: an AI feature switched on inside a subscription (SaaS) tool, an outside AI service called from one corner of your code, a copilot bought on a company card. ISO/IEC 42001 pulls all of it in through its resource and third-party controls, and auditors ask for the AI system inventory first. Scoping narrowly on purpose is fine; doing it because nobody looked earns a nonconformity (an audit finding).
Each answers a question an auditor or board will ask. Put the system's register ID on every record, vendor review and piece of audit evidence, or they drift apart within a quarter and nobody notices until an auditor lines them up.
An impact assessment looks outward, at consequences for individuals, groups of individuals and societies; a risk assessment looks inward, at your objectives. ISO/IEC 42001 requires both, and merging them is a common major nonconformity. We follow the ISO/IEC 42005:2025 structure; your accountable owner signs. Clauses 6.1.4 and 8.4, control group A.5.
A roles and authorities matrix names one accountable person per system, and dated approval records show who approved it and when. We draft it; one of your executives signs. Clause 5.3, control A.3.2.
A statement of intended and out-of-scope use, with an escalation path for cases the system wasn't built for. It makes human oversight testable. Controls A.9.2 to A.9.4.
Event logs, a technical documentation pack and change records tying each output to a model version and dataset, kept past your complaint window. Your engineers build them; we specify what to log and review what you kept. If they can't, narrow what the system may decide. Controls A.6.2.7 and A.6.2.8.
How an engagement runs
Policy has to fit the AI you actually run, so we list it first.
We interview your teams and review software subscriptions, company-card spend, outgoing network traffic, calls to outside AI services and procurement records. The result is a draft register with an owner, a role and a data-sensitivity rating for each system. Discovery takes three to four weeks; with classification and scoping, four to eight. It often runs long, because shadow AI (tools nobody approved) surfaces here.
Each system gets a role, a criticality band and a written statement of what it may decide with no person involved. Systems touching personal data are flagged against duties under India's Digital Personal Data Protection (DPDP) Act in the same pass.
Only high-impact systems need a full assessment. We'd rather write six assessments with evidence behind them than thirty templated ones; auditors spot templates quickly.
Where a system is sold or used decides what governs it. Lenders and non-banking financial companies (NBFCs) also answer to their regulator for model risk. We build the register, impact assessments and decision-rights records once; only the signature changes.
Who signs what
It's ISO/IEC 42001. The rest give you guidance, a report, a statement your executive signs or legal duties.
| Framework | What you get | Who issues it |
|---|---|---|
| ISO/IEC 42001:2023 | An accredited certificate that your AI management system, within a stated scope, conforms and operates. It lasts three years, with annual surveillance audits, and says nothing about whether a model is safe, accurate or unbiased. | A certification body accredited for ISO/IEC 42001 specifically; 27001 accreditation doesn't carry over. |
| NIST AI RMF 1.0 | A current profile scored across all 72 subcategories, a target profile and a prioritized gap roadmap. | Nobody. We produce the assessment and evidence index; your executive signs the statement of alignment. |
| NIST AI 600-1, the Generative AI Profile | Twelve named generative-AI risks and 212 suggested actions keyed by Action ID, covering 49 of the 72 subcategories; the other 23 get none. | Nobody, as with the AI RMF. |
| EU AI Act (Regulation (EU) 2024/1689) | Legal obligations, no certificate. Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk dates (see the FAQ). | The provider signs the declaration of conformity; its advisors don't. |
| ISO/IEC 42005:2025 and ISO/IEC 23894:2023 | Guidance. 42005 structures an AI system impact assessment; 23894 covers AI risk management on an ISO 31000 base. | No one. Neither is certifiable. |
| SOC 2 | An attestation report under AICPA standards, often mislabeled a certificate. AI controls can sit in its scope as additional subject matter, but it isn't evidence of conformance to the AI RMF or ISO/IEC 42001. | A CPA firm. |
| India DPDP Act 2023 and DPDP Rules 2025 | Law commencing in tranches (see the FAQ). | Nobody issues a DPDP certificate. You answer to the Data Protection Board of India. |
What this work does not include. We provide AI governance consulting and implementation; we are not a certification body or a CPA firm. Certificates, SOC 2 reports and EU declarations of conformity are signed by an accredited certification body, a CPA firm or the provider.
FAQ
Certificates, deadlines, scope and where to start. For anything else, ask us directly.
No jurisdiction requires it; procurement drives it. It's the only international AI management system standard that accredited certification bodies audit against, so buyers' third-party risk teams score RFPs against it. India has no AI statute, and MeitY's India AI Governance Guidelines, released on 5 November 2025 under the IndiaAI Mission, are voluntary.
No. EN ISO/IEC 42001:2026, adopted unchanged by CEN-CENELEC in March 2026, isn't cited as a harmonized standard in the Official Journal, so Article 40(1) gives it no presumption of conformity. The Article 17 quality management system duty has its own standard, EN 18286:2026 (approved 12 July 2026, available 22 July 2026), which isn't cited either. Budget the Article 17 work separately.
No one can, including us. NIST runs no certification scheme, accredits no assessors and calls the framework voluntary. You can get a third-party assessment report, a management self-attestation or a gap report against a target profile. If a customer needs something to file, the route is ISO/IEC 42001, with the AI RMF work feeding it. A SOC 2 report doesn't substitute.
It was, until the Digital Omnibus amendment, Regulation (EU) 2026/1744, moved it. The amendment left the Article 50 transparency duty for AI-generated and AI-interacting content alone, and it has applied since 2 August 2026. Chapter III high-risk obligations now apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. Our EU AI Act page has the calendar tier by tier.
No. We're an implementation and assessment firm and hold neither certificate. Certificates come from certification bodies accredited for that specific standard by an IAF-recognized accreditation body; ISO itself certifies nobody. To check any certificate, ask which accreditation body holds that scope and look it up in its register.
Start with whichever one someone is already asking you for. Deals stalled on a security questionnaire need a certificate, and ISO/IEC 42001 is the AI answer. EU users bring in the AI Act, which nothing else discharges. Otherwise, start with a NIST AI RMF profile: it costs less, commits you to nothing and produces most of what the other two need later.
Yes. ISO/IEC 42001 covers deployers as well as builders, so a company with no data science team can certify. Your Statement of Applicability looks different: most of A.6.2 (design, development and validation) is excluded with justification, but A.5 (impact assessment) and A.10 (third parties and customers) can't be. If your only AI exposure is staff using a public chatbot, an acceptable-use policy and a vendor review is the proportionate answer, and we'll say so.
The DPDP Act 2023 and DPDP Rules 2025 commence in tranches: institutional provisions in November 2025, Consent Manager registration in November 2026, and the duties you owe a Data Principal in May 2027. For AI work the overlap is data acquisition, quality and provenance, which ISO/IEC 42001 controls A.7.3 to A.7.6 also cover, so both efforts share evidence. As of September 2026 no change to those dates has been gazetted. Our DPDP page sets out each tranche.
Last updated 25 September 2026.
Let's talk
Tell us roughly how many AI systems you think you run. We'll tell you what a discovery pass usually finds and how long it takes. We reply within one working day.