AI governance · ISO/IEC 42001 consultancy

Bespoke AI governance, with method and evidence.

VGrid structures AI governance projects that connect ISO/IEC 42001, risk management with the NIST AI RMF and the assessment of EU AI Act requirements, according to each organisation's context. Security, privacy and data protection are part of the work, with controls and evidence.

The initial conversation is used to understand context, priority and fit. Scope, timeline and investment are defined afterwards.

Structure
Management system, roles and decision criteria.
Control
Risks, policies, processes and records.
Evidence
Indicators, internal audit and documentary trails.

Working references

Four references, different natures, integrated work.

A management system standard, AI risk management guidance, a voluntary framework and a regulation with specific applicability. Each answers a different question and enters the project according to scope.

  • ISO/IEC 42001

    Management system standard

    AI management system: policies, responsibilities, processes and continual improvement. Certification is issued by an accredited body.

    About ISO/IEC 42001
  • ISO/IEC 23894

    AI risk management guidance

    AI risk management integrated into the organisation's activities: criteria, risk register, treatment and review. It is guidance, not a certifiable set of requirements.

    ISO/IEC 23894 implementation (page in Portuguese)
  • NIST AI RMF

    Voluntary framework

    AI risk management: applying the GOVERN, MAP, MEASURE and MANAGE functions to each organisation's context. There is no NIST certification.

    NIST AI RMF implementation
  • EU AI Act

    European Union regulation

    Applicability and regulatory requirements: assessment of roles, risks, obligations and evidence according to how each system is classified.

    EU AI Act readiness

ISO/IEC 42001 does not by itself guarantee compliance with legal requirements. ISO/IEC 23894 is guidance and grants no certification, and the NIST AI RMF is voluntary and grants none either. The EU AI Act applies according to the legal scope of each case.

Scope may include gap analysis against ISO/IEC 42001, maturity diagnosis, AI use policies, implementation of the AI management system (AIMS), integration with ISO/IEC 27001, ISO/IEC 27701 and data protection law, survey of applicable regulatory requirements, treatment of ungoverned AI use, internal audit and continuous operation. Implementation and internal audit are conducted with formal separation of roles; certification is issued by an accredited certification body.

See the full scope of work

Organisations we have worked with

  • Travel Inn
  • Ibracem
  • Tial
  • Luby
  • Rofe
  • The Four Beauty
  • K2 Web
  • Imdepa

Testimonials

Accounts from organisations we have worked with.

Real testimonials published anonymously, as an editorial decision and out of respect for confidentiality agreements. Identification by function and sector only.

  • “The structuring gave us an inventory of AI systems, a use policy and a risk matrix that the board is able to read and discuss.”

    Technology Directorate · Hospitality

  • “The most useful point was separating what was a normative requirement from what was an internal decision. That reduced discussion and accelerated approval.”

    Legal and Compliance · Corporate education

  • “We now have a record of who approves each AI use, with evidence for internal audit and for clients that request such proof.”

    Information Security Management · Technology services

  • “The assessment identified AI uses that had not been mapped and defined clear criteria to authorise or block each tool.”

    Executive Directorate · Industry and distribution

There is no correspondence between the logos displayed and the accounts published. Logos and testimonials are presented independently.

The VGrid method

Five stages, from context to continual improvement.

The same method organises AI governance, ISO/IEC 42001, AI security and AI compliance projects, from the initial survey to periodic review.

See the method in detail
  1. 01

    Read

    Diagnosis of real AI use, data, vendors, risks and regulatory exposure.

  2. 02

    Prioritise

    Risk, criticality and impact matrix: where to govern first, with clear criteria.

  3. 03

    Implement

    Policies, controls, roles, committee, inventory and evidence in operation.

  4. 04

    Govern

    Oversight routine, indicators, internal audit and continuous risk management.

  5. 05

    Evolve

    Growing maturity aligned with ISO 42001, NIST AI RMF and regulatory change.

VGrid.ai | AI governance platform

From strategy to continuous AI management.

Meet VGrid.ai, VGrid's AI governance platform. We are developing an environment to support companies, consultants and teams in organising responsibilities, risks, controls and evidence.

  1. 01Responsibilities
  2. 02Risks
  3. 03Controls
  4. 04Evidence
Clear responsibilities, assessed risks, applied controls and organised evidence.
FAQ

Frequently asked questions

Practice areas, ISO/IEC 42001, applicable regulatory requirements and ways to start.

Talk to VGrid

Tell us the context of your organisation

Describe the objective, the current stage and the main urgency. VGrid uses this information to assess fit and suggest the next step.

We reply after an initial review of the context
Data used only to assess fit
No automatic mailing list subscription

Your data is processed according to our privacy policy.