AI inventory
A structured register of AI systems, tools and use cases — including shadow AI.
AI
Most organizations already use AI — often more than management knows. We help you get an overview, set sensible rules, assess risks and prepare for the EU AI Act and ISO/IEC 42001, building on the governance structures you already have.
AI governance starts with simple questions. The problem is that nobody owns the answers.
A structured register of AI systems, tools and use cases — including shadow AI.
Clear, practical rules for employees: which tools, which data, which approvals.
A method to assess AI risks — integrated with your existing risk management.
A structured assessment of your role (provider/deployer) and the risk category of your use cases.
Who approves, who monitors, who intervenes — and how that is documented.
From idea and approval to operation, monitoring and retirement of AI systems.
Rules for training data, input data and outputs, aligned with information security and data protection.
An AI management system according to ISO/IEC 42001 — ideally integrated into your ISMS or QMS.
Find out where and how AI is used today — through interviews, tool reviews and existing inventories.
Assess use cases by risk and by the requirements that apply to them.
Policies, approval processes and responsibilities that people can follow.
Connect AI governance to your existing ISMS, QMS, risk management and documentation.
Train employees and decision-makers on responsible and secure AI use.
Keep the inventory, risks and rules current as AI use evolves.
AI governance should not become another silo
Risk management, document control, roles, audits and reviews already exist in your ISMS or QMS. AI governance works best as an extension of these structures — ISO/IEC 42001 is built for exactly that.
Where legal advice is needed
We translate AI requirements into governance structures, processes and controls. Binding legal interpretations of the EU AI Act for your specific case should be confirmed by legal counsel.
No new silo
AI governance uses the structures you already have — and only adds what is specific to AI.
AI governance is the set of rules, responsibilities and processes an organization uses to control how AI is selected, developed, used and monitored — so that AI use is secure, lawful, transparent and aligned with the organization’s goals.
The EU AI Act sorts AI uses by risk. Certain practices are prohibited; providers and deployers must support AI literacy of their staff; transparency obligations apply to certain AI systems; and high-risk AI systems face extensive requirements. Following the 2026 “Digital Omnibus” amendment, most high-risk obligations now apply from December 2027 (stand-alone systems) and August 2028 (AI in regulated products). Which obligations apply to you depends on your role and use cases.
ISO/IEC 42001 is the international standard for AI management systems (AIMS). It describes how an organization establishes policies, objectives, risk assessment, roles and controls for the responsible development and use of AI — and can be certified.
Both use the same management system structure. ISO/IEC 27001 protects information; ISO/IEC 42001 governs AI systems, including issues like transparency, bias and human oversight. Organizations with an ISMS can reuse much of their management framework and add AI-specific elements.
No. ISO/IEC 42001 is voluntary. It can, however, provide a structured way to implement and evidence many governance requirements that the EU AI Act and customers expect.
Plan and secure private or self-hosted AI: local models, controlled knowledge access and data sovereignty — governed like any other critical system.
Combine quality, information security and AI governance in one integrated management system with shared processes.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
What AI governance means, what ISO/IEC 42001 is, what the EU AI Act requires after the 2026 Digital Omnibus amendment, and how both connect to an existing ISMS.
NIS2, the Cyber Resilience Act and the EU AI Act explained: who is affected, which 2026 deadlines apply and how one ISMS covers shared requirements.
Let us start with an overview of your AI use. The next steps usually become clear quickly.