Governance that scales
with your AI adoption
ISO 42001, NIST AI RMF, EU AI Act, and PL 2338 (BR). We implement the right framework for your sector, integrated into your existing risk program — without becoming yet another blocking layer.
One governance program
Multiple regulatory regimes
We map controls once and each framework gets its evidence package automatically. No rework, no duplication.
ISO/IEC 42001 — AIMS
First international standard for an AI management system. Plan-Do-Check-Act, with specific clauses for risk, transparency, and continuous improvement. Third-party certifiable.
NIST AI RMF 1.0
Voluntary framework organized in four functions — Govern, Map, Measure, Manage. Adopted by US federal agencies and increasingly as a baseline for B2B contracts.
EU AI Act
Mandatory regulation with a risk pyramid. High-risk systems require conformity assessment, technical documentation, human oversight, and post-market monitoring. Fines up to €35M or 7% of revenue.
PL 2338 / 2023 (BR)
Brazilian regulatory framework in progress. Risk-based categorization, rights of the affected person, and ANPD oversight. We track the text in real time and adjust your program.
A complete program across 5 fronts
Policy & strategy
AI acceptable-use policy, ethical principles, risk appetite definition, and regulatory roadmap aligned with the business plan.
Organizational structure
AI committee, RACI per system, AI Officer role, integration with Risk, Compliance, Privacy, and Information Security.
Processes & controls
Algorithmic impact assessment, approval gate for new systems, change process, retraining, and controlled decommissioning.
Documentation & evidence
Model cards, system cards, decision logs, audit trail, and automatic evidence package per regulatory framework.
Training & culture
Executive enablement, hands-on engineering training, leadership incident simulations, and communication to employees and customers.
One control
Multiple evidences
Each control maps simultaneously to ISO 42001, NIST AI RMF, and EU AI Act — implement once, satisfy all three.
Data governance
Lineage, quality, bias, LGPD/GDPR compliance, PII redaction, and validation of training/RAG data.
Human oversight
Intervention points, override controls, mandatory review for high-impact decisions, and adherence metrics.
Transparency & explanation
User disclosure, public model cards, per-decision explanations, and appeal channels for affected individuals.
Continuous risk management
Per-system risk assessment, post-deploy monitoring, drift metrics, and periodic review process.
Incident management
Definition of what an AI incident is, notification process to authorities, communication to affected parties, and lessons learned.
Vendor management
Due diligence, AI contractual clauses, multi-tenant isolation, and documented shared responsibility.
Is your AI governance ready for 2026?
Start with a regulatory-readiness assessment — leave with gap analysis, prioritization, and an implementation plan for the frameworks that matter to your business.
Assess readiness