Skip to content
ISO 42001 · NIST AI RMF · EU AI Act

Governance that scales
with your AI adoption

ISO 42001, NIST AI RMF, EU AI Act, and PL 2338 (BR). We implement the right framework for your sector, integrated into your existing risk program — without becoming yet another blocking layer.

4Frameworks supported
2026EU AI Act enforceable
BRPL 2338 in progress
Ago 2026EU AI Act high-risk enforceable
NIST AI RMF 1.0AI management system
PL 2338 / 2023 (BR)US voluntary framework
PL 2338BR regulatory framework
The four frameworks

One governance program
Multiple regulatory regimes

We map controls once and each framework gets its evidence package automatically. No rework, no duplication.

FW-01 · INTERNATIONAL

ISO/IEC 42001 — AIMS

First international standard for an AI management system. Plan-Do-Check-Act, with specific clauses for risk, transparency, and continuous improvement. Third-party certifiable.

42001
FW-02 · UNITED STATES

NIST AI RMF 1.0

Voluntary framework organized in four functions — Govern, Map, Measure, Manage. Adopted by US federal agencies and increasingly as a baseline for B2B contracts.

FW-03 · EUROPEAN UNION

EU AI Act

Mandatory regulation with a risk pyramid. High-risk systems require conformity assessment, technical documentation, human oversight, and post-market monitoring. Fines up to €35M or 7% of revenue.

conformity assessment
technical documentation
post-market monitoring
FW-04 · BRASIL

PL 2338 / 2023 (BR)

Brazilian regulatory framework in progress. Risk-based categorization, rights of the affected person, and ANPD oversight. We track the text in real time and adjust your program.

2024PLSenate approved
2025PLChamber under review
2026·expected sanction
We build with you

A complete program across 5 fronts

G1

Policy & strategy

AI acceptable-use policy, ethical principles, risk appetite definition, and regulatory roadmap aligned with the business plan.

C-levelBoard
G2

Organizational structure

AI committee, RACI per system, AI Officer role, integration with Risk, Compliance, Privacy, and Information Security.

RACICommittee
G3

Processes & controls

Algorithmic impact assessment, approval gate for new systems, change process, retraining, and controlled decommissioning.

AIA / DPIAChange mgmt
G4

Documentation & evidence

Model cards, system cards, decision logs, audit trail, and automatic evidence package per regulatory framework.

AuditablePer framework
G5

Training & culture

Executive enablement, hands-on engineering training, leadership incident simulations, and communication to employees and customers.

Learning tracksTabletop
Cross-mapping

One control
Multiple evidences

Each control maps simultaneously to ISO 42001, NIST AI RMF, and EU AI Act — implement once, satisfy all three.

CTRL · DATA

Data governance

Lineage, quality, bias, LGPD/GDPR compliance, PII redaction, and validation of training/RAG data.

ISO 42001 · 8.3
NIST · MAP 2.3
EU AI Act · Art 10
CTRL · OVERSIGHT

Human oversight

Intervention points, override controls, mandatory review for high-impact decisions, and adherence metrics.

ISO 42001 · 9.2
NIST · MANAGE 4.1
EU AI Act · Art 14
CTRL · TRANSPARENCY

Transparency & explanation

User disclosure, public model cards, per-decision explanations, and appeal channels for affected individuals.

ISO 42001 · 7.4
NIST · GOVERN 5.1
EU AI Act · Art 52
CTRL · RISK

Continuous risk management

Per-system risk assessment, post-deploy monitoring, drift metrics, and periodic review process.

ISO 42001 · 6.1
NIST · MAP 1.1
EU AI Act · Art 9
CTRL · INCIDENT

Incident management

Definition of what an AI incident is, notification process to authorities, communication to affected parties, and lessons learned.

ISO 42001 · 10.2
NIST · MANAGE 4.3
EU AI Act · Art 73
CTRL · VENDOR

Vendor management

Due diligence, AI contractual clauses, multi-tenant isolation, and documented shared responsibility.

ISO 42001 · 7.5
NIST · GOVERN 6.1
EU AI Act · Art 25

Is your AI governance ready for 2026?

Start with a regulatory-readiness assessment — leave with gap analysis, prioritization, and an implementation plan for the frameworks that matter to your business.

Assess readiness