AI governance · ISO/IEC 42001 consultancy
Bespoke AI governance, with method and evidence.
VGrid structures AI governance projects that connect ISO/IEC 42001, risk management with the NIST AI RMF and the assessment of EU AI Act requirements, according to each organisation's context. Security, privacy and data protection are part of the work, with controls and evidence.
The initial conversation is used to understand context, priority and fit. Scope, timeline and investment are defined afterwards.
- Structure
- Management system, roles and decision criteria.
- Control
- Risks, policies, processes and records.
- Evidence
- Indicators, internal audit and documentary trails.
Working references
Four references, different natures, integrated work.
A management system standard, AI risk management guidance, a voluntary framework and a regulation with specific applicability. Each answers a different question and enters the project according to scope.
ISO/IEC 42001
Management system standard
AI management system: policies, responsibilities, processes and continual improvement. Certification is issued by an accredited body.
About ISO/IEC 42001ISO/IEC 23894
AI risk management guidance
AI risk management integrated into the organisation's activities: criteria, risk register, treatment and review. It is guidance, not a certifiable set of requirements.
ISO/IEC 23894 implementation (page in Portuguese)NIST AI RMF
Voluntary framework
AI risk management: applying the GOVERN, MAP, MEASURE and MANAGE functions to each organisation's context. There is no NIST certification.
NIST AI RMF implementationEU AI Act
European Union regulation
Applicability and regulatory requirements: assessment of roles, risks, obligations and evidence according to how each system is classified.
EU AI Act readiness
ISO/IEC 42001 does not by itself guarantee compliance with legal requirements. ISO/IEC 23894 is guidance and grants no certification, and the NIST AI RMF is voluntary and grants none either. The EU AI Act applies according to the legal scope of each case.
Practice areas
Four practice areas, with defined scope and deliverables.
Each area can be engaged on its own or in an integrated way. The starting point is always reading the context and the organisation's current stage.
Scope may include gap analysis against ISO/IEC 42001, maturity diagnosis, AI use policies, implementation of the AI management system (AIMS), integration with ISO/IEC 27001, ISO/IEC 27701 and data protection law, survey of applicable regulatory requirements, treatment of ungoverned AI use, internal audit and continuous operation. Implementation and internal audit are conducted with formal separation of roles; certification is issued by an accredited certification body.
See the full scope of workOrganisations we have worked with
Testimonials
Accounts from organisations we have worked with.
Real testimonials published anonymously, as an editorial decision and out of respect for confidentiality agreements. Identification by function and sector only.
“The structuring gave us an inventory of AI systems, a use policy and a risk matrix that the board is able to read and discuss.”
Technology Directorate · Hospitality
“The most useful point was separating what was a normative requirement from what was an internal decision. That reduced discussion and accelerated approval.”
Legal and Compliance · Corporate education
“We now have a record of who approves each AI use, with evidence for internal audit and for clients that request such proof.”
Information Security Management · Technology services
“The assessment identified AI uses that had not been mapped and defined clear criteria to authorise or block each tool.”
Executive Directorate · Industry and distribution
There is no correspondence between the logos displayed and the accounts published. Logos and testimonials are presented independently.
The VGrid method
Five stages, from context to continual improvement.
The same method organises AI governance, ISO/IEC 42001, AI security and AI compliance projects, from the initial survey to periodic review.
See the method in detail- 01
Read
Diagnosis of real AI use, data, vendors, risks and regulatory exposure.
- 02
Prioritise
Risk, criticality and impact matrix: where to govern first, with clear criteria.
- 03
Implement
Policies, controls, roles, committee, inventory and evidence in operation.
- 04
Govern
Oversight routine, indicators, internal audit and continuous risk management.
- 05
Evolve
Growing maturity aligned with ISO 42001, NIST AI RMF and regulatory change.
VGrid.ai | AI governance platform
From strategy to continuous AI management.
Meet VGrid.ai, VGrid's AI governance platform. We are developing an environment to support companies, consultants and teams in organising responsibilities, risks, controls and evidence.
- 01Responsibilities
- 02Risks
- 03Controls
- 04Evidence
Frequently asked questions
Practice areas, ISO/IEC 42001, applicable regulatory requirements and ways to start.
Tell us the context of your organisation
Describe the objective, the current stage and the main urgency. VGrid uses this information to assess fit and suggest the next step.