Our services

AI Governance and ISO/IEC 42001 Readiness

Apexagen helps you establish practical governance for the AI tools, applications and automated decisions used across your organisation. We identify where AI is being used, assess the associated risks and put responsibilities, policies and controls in place.

Who this service is for

  • SMEs adopting generative AI without formal policies or assigned responsibilities.
  • Enterprises that need a consistent governance model across departments.
  • Organisations responding to customer, tender or regulatory questions about AI.
  • Teams developing AI applications or autonomous agents.
  • Organisations preparing for ISO/IEC 42001 certification.
  • Businesses extending existing risk, privacy or information security programmes to cover AI.

What the service covers

AI inventory and ownership

Identify approved AI tools, applications, models, agents and business use cases. Record who owns each system and who is responsible for its risks.

Risk classification

Classify AI use based on the data involved, the decisions being supported, the level of autonomy and the possible impact on customers, employees and operations.

Policies and operating procedures

Develop practical rules for acceptable AI use, data handling, human review, procurement, development, monitoring and incident reporting.

Roles and accountability

Define responsibilities for executives, business owners, risk teams, technology teams, developers and users.

Third-party AI governance

Assess how external AI providers process data, manage security, retain information and communicate material service changes.

AI lifecycle controls

Establish approval, testing, deployment, monitoring, change-management and retirement requirements for AI systems.

ISO/IEC 42001 readiness

Conduct a gap assessment, establish an AI management system and organise the policies, records and evidence required for independent certification.

What you receive

  • AI system and use-case inventory.
  • AI governance framework.
  • Acceptable-use and AI management policies.
  • AI risk classification method and risk register.
  • Roles and responsibility matrix.
  • Third-party AI assessment checklist.
  • AI system approval and review process.
  • Incident and escalation procedure.
  • ISO/IEC 42001 gap assessment.
  • Prioritised implementation roadmap and certification-readiness evidence plan.

How we deliver it

We begin by interviewing the people responsible for AI adoption, technology, risk, privacy and business operations. We review existing policies and identify how AI is currently used.

We then assess the gaps, design controls that match your organisation’s size and risk profile, and work with your team to put the agreed processes into operation. Where ISO/IEC 42001 readiness is required, we support implementation and preparation for the independent certification assessment.

Explore all AI security, governance and automation services.

FAQ

Do smaller organisations need an AI governance programme?

Yes, but it should be proportionate. An SME may begin with an AI inventory, an acceptable-use policy, clear data-handling rules and an approval process for higher-risk use cases.

Does Apexagen issue ISO/IEC 42001 certification?

No. Certification is performed by an independent certification body. Apexagen helps establish the management system, address gaps and prepare the organisation for assessment.

Can this build on our existing ISO/IEC 27001 programme?

Yes. Existing risk management, supplier management, access control, incident response and audit processes can often be extended to cover AI.

Deployed to Deliver

Assess your AI governance readiness

Tell us how your organisation uses AI and what requirements you need to meet. We will help identify the practical next steps.

Assess your AI governance readiness