
Mandate III · Comply
One program. Two certificates: ISO 42001 and ISO 27001.
And European law in order.
We take you step by step to ISO 42001 certification, ISO 27001, or both. Each program can run on its own. Together, they become one. Same flexibility for compliance with European law. High risk arrives in December 2027, and part of it already applies: sixteen months to do it properly, not to defer it.
ISO 42001 & 27001 certification
Both standards share the same management system frame. Each can run alone, at its own pace. Together they become one program inside the way you already operate, and two certificates at the end. Policies, risk registers, controls, internal audit. All of it built to withstand the scrutiny of an accredited body.
AI Act · Diagnostic & Triage
Five days, fixed price. The risk classification of your AI systems, your exposure map against obligations already in force and those of December 2027, and a written action plan for your board.
How it runs
Four steps. No surprises.
Inventory
Your AI and information systems, their risk classification, the gap between what you do and what the standards require.
Close
Policies, registers, controls, built inside your existing tools and committees. Never in a parallel binder.
Prove
Internal audit, management review, correction of the last gaps. The system is ready when it no longer fears questions.
Certify
The certification audit is run by an independent accredited body. We prepare you for it, and we are beside you on the day.
A SaaS vendor whose European pipeline was stuck on the certificate.
European enterprise buyers would not sign without recognized AI governance. We took the organization from gap analysis to a certification-ready ISO/IEC 42001 management system, built inside the way the product team already ships. Then all the way to the audit.
Straight questions
What we get asked before signing.
Does the move to December 2027 give us time?
Sixteen months to do properly what takes twelve, if you start now. And part of the law already applies: AI literacy, transparency, prohibited practices. The delay moved the high-risk deadline. It did not suspend the law.
Why run ISO 42001 and 27001 together?
Because they share the same frame: policies, risk management, internal audit, management review. Running them together costs considerably less than running them in sequence, and your clients increasingly ask for both. One program, two certificates.
Do you issue the certificate yourselves?
No, and be wary of anyone who implies otherwise. The certificate is issued by an accredited, independent certification body. Our role: build your management system, audit it internally, and take you to that audit in the best possible shape. Our founder is also a registered auditor: we know what the auditor will look at, because we have sat on the other side of the table.
What happens during the five day Triage?
Days one and two: inventory of your AI systems and risk classification. Days three and four: exposure map against obligations, in force and upcoming. Day five: a prioritized 90 day action plan and a memo for your board. Fixed price, known before we start.
Sixteen months. That is comfortable for whoever starts now.