Our services
AI Governance and ISO/IEC 42001 Readiness
Apexagen helps you establish practical governance for the AI tools, applications and automated decisions used across your organisation. We identify where AI is being used, assess the associated risks and put responsibilities, policies and controls in place.
Who this service is for
- SMEs adopting generative AI without formal policies or assigned responsibilities.
- Enterprises that need a consistent governance model across departments.
- Organisations responding to customer, tender or regulatory questions about AI.
- Teams developing AI applications or autonomous agents.
- Organisations preparing for ISO/IEC 42001 certification.
- Businesses extending existing risk, privacy or information security programmes to cover AI.
What the service covers
AI inventory and ownership
Identify approved AI tools, applications, models, agents and business use cases. Record who owns each system and who is responsible for its risks.
Risk classification
Classify AI use based on the data involved, the decisions being supported, the level of autonomy and the possible impact on customers, employees and operations.
Policies and operating procedures
Develop practical rules for acceptable AI use, data handling, human review, procurement, development, monitoring and incident reporting.
Roles and accountability
Define responsibilities for executives, business owners, risk teams, technology teams, developers and users.
Third-party AI governance
Assess how external AI providers process data, manage security, retain information and communicate material service changes.
AI lifecycle controls
Establish approval, testing, deployment, monitoring, change-management and retirement requirements for AI systems.
ISO/IEC 42001 readiness
Conduct a gap assessment, establish an AI management system and organise the policies, records and evidence required for independent certification.
What you receive
- AI system and use-case inventory.
- AI governance framework.
- Acceptable-use and AI management policies.
- AI risk classification method and risk register.
- Roles and responsibility matrix.
- Third-party AI assessment checklist.
- AI system approval and review process.
- Incident and escalation procedure.
- ISO/IEC 42001 gap assessment.
- Prioritised implementation roadmap and certification-readiness evidence plan.
How we deliver it
We begin by interviewing the people responsible for AI adoption, technology, risk, privacy and business operations. We review existing policies and identify how AI is currently used.
We then assess the gaps, design controls that match your organisation’s size and risk profile, and work with your team to put the agreed processes into operation. Where ISO/IEC 42001 readiness is required, we support implementation and preparation for the independent certification assessment.
Explore all AI security, governance and automation services.
FAQ
Do smaller organisations need an AI governance programme?
Yes, but it should be proportionate. An SME may begin with an AI inventory, an acceptable-use policy, clear data-handling rules and an approval process for higher-risk use cases.
Does Apexagen issue ISO/IEC 42001 certification?
No. Certification is performed by an independent certification body. Apexagen helps establish the management system, address gaps and prepare the organisation for assessment.
Can this build on our existing ISO/IEC 27001 programme?
Yes. Existing risk management, supplier management, access control, incident response and audit processes can often be extended to cover AI.
Deployed to Deliver
Assess your AI governance readiness
Tell us how your organisation uses AI and what requirements you need to meet. We will help identify the practical next steps.
Assess your AI governance readiness