AI governance and ISO/IEC 42001 consultancy

Corporate AI governance with method, controls and evidence.

VGrid helps organisations structure AI management systems, define responsibilities, treat risks and keep evidence for audit and executive decision-making.

The initial conversation is used to understand context, priority and fit. Scope, timeline and investment are defined afterwards.

Structure
Management system, roles and decision criteria.
Control
Risks, policies, processes and records.
Evidence
Indicators, internal audit and documentary trails.

How VGrid works

AI governance handled as a management system.

The work combines documentary structuring, risk assessment, definition of responsibilities and internal verification, so that corporate AI use can be described, justified and audited.

  • 01Scope defined before the work

    Every project starts with context, AI systems in use, roles involved and decision criteria on record.

  • 02Integration across functions

    Legal, security, privacy, technology and business work from the same inventory and the same risk matrix.

  • 03Verifiable documentation

    System inventory, policies, risk matrix, indicators and internal audit records.

  • 04Standards as design criteria

    ISO/IEC 42001 and NIST AI RMF applied as structuring requirements, with a declared regulatory cut-off date.

  • 05Assessment of actual use

    Mapping of systems, agents, vendors and data processed, plus self-assessment questionnaires.

  • 06Continuous operation

    Periodic review, treatment of nonconformities and continual improvement of the management system.

Scope

From diagnosis to continuous operation

Scope may include gap analysis against ISO/IEC 42001, maturity diagnosis, AI use policies, implementation of the AI management system (AIMS), integration with ISO/IEC 27001, ISO/IEC 27701 and data protection law, survey of applicable regulatory requirements, treatment of ungoverned AI use, internal audit and continuous operation. Implementation and internal audit are conducted with formal separation of roles; certification is issued by an accredited certification body.

01

Diagnose

ISO/IEC 42001 gap analysis, maturity diagnosis, AI inventory and mapping of ungoverned AI use.

02

Structure

Responsible AI policies, AI committee, RACI, risk matrix (NIST AI RMF and ISO/IEC 23894) and Annex A controls.

03

Implement

Practical AIMS implementation led by an ISO/IEC 42001 Lead Implementer, integrated with ISO/IEC 27001, ISO/IEC 27701 and data protection law.

04

Align

Preventive alignment with the EU AI Act and pre-compliance with the Brazilian AI bill (PL 2338), with documentation and evidence.

05

Audit

Internal audit, control assessment and readiness assessment led by an ISO/IEC 42001 Lead Auditor, ahead of certification.

06

Operate

Governance operated continuously: indicators, AI incidents, AI literacy, vendor due diligence and regulatory change.

The VGrid method

Five stages, from context to continual improvement.

The same method organises AI governance, ISO/IEC 42001, AI security and AI compliance projects, from the initial survey to periodic review.

See the method in detail
  • 01

    Read

    Diagnosis of real AI use, data, vendors, risks and regulatory exposure.

  • 02

    Prioritise

    Risk, criticality and impact matrix: where to govern first, with clear criteria.

  • 03

    Implement

    Policies, controls, roles, committee, inventory and evidence in operation.

  • 04

    Govern

    Oversight routine, indicators, internal audit and continuous risk management.

  • 05

    Evolve

    Growing maturity aligned with ISO 42001, NIST AI RMF and regulatory change.

FAQ

Frequently asked questions

Practice areas, ISO/IEC 42001, applicable regulatory requirements and ways to start.

Organisations we have worked with

  • Travel Inn
  • Ibracem
  • Tial

Testimonials

Accounts from organisations we have worked with.

Real testimonials published anonymously, as an editorial decision and out of respect for confidentiality agreements. Identification by function and sector only.

  • “The structuring gave us an inventory of AI systems, a use policy and a risk matrix that the board is able to read and discuss.”

    Technology Directorate · Hospitality

  • “The most useful point was separating what was a normative requirement from what was an internal decision. That reduced discussion and accelerated approval.”

    Legal and Compliance · Corporate education

  • “We now have a record of who approves each AI use, with evidence for internal audit and for clients that request such proof.”

    Information Security Management · Technology services

  • “The assessment identified AI uses that had not been mapped and defined clear criteria to authorise or block each tool.”

    Executive Directorate · Industry and distribution

There is no correspondence between the logos displayed and the accounts published. Logos and testimonials are presented independently.

Talk to VGrid

Tell us the context of your organisation

Describe the objective, the current stage and the main urgency. VGrid uses this information to assess fit and suggest the next step.

We reply after an initial review of the context
Data used only to assess fit
No automatic mailing list subscription

Your data is processed according to our privacy policy.