AI governance
you can demonstrate.
Your clients, regulator and board no longer ask only whether you use AI. They want to know how you control it. ISO/IEC 42001 is an international certifiable standard dedicated to AI management systems. We support you from the first assessment through certification-audit preparation. The Neural ICE founders deliver the work directly.
"We take AI seriously" is not evidence. A certified management system is.
Four forces are converging on the same requirement: show, with evidence, that your AI is under control.
Evidence is becoming a commercial criterion
Tenders, vendor questionnaires and due-diligence processes increasingly ask how AI is governed. A policy alone is less convincing than a structured, auditable system. ISO/IEC 42001 provides a recognised framework for answering with evidence.
AI Act · December 2027
From 2 December 2027, rules for certain Annex III high-risk AI systems apply, including risk management, traceability and human oversight requirements. An AI management system provides a structured framework for implementing those obligations.
Unauthorised AI use escapes governance
AI is already present in many organisations, adopted tool by tool without clear accountability. Governance starts with an honest inventory: which tools are used, on what data and under whose responsibility?
The board owns the risk
AI failures are becoming a management-accountability issue. A certified AI management system supports a documented, auditable answer to an essential question: who controls the organisation's use of AI?
Start with the essentials. Prepare certification at the right time. Stay on course.
Four engagements form a progressive path. Each can stand alone and, where needed, prepare the next. You own every deliverable and can use it with or without us.
AI Governance Health Check
A fixed-scope assessment: an inventory of the AI tools actually in use, including unauthorised use; gap analysis against clauses 4–10 and all 38 Annex A controls; maturity assessment; and an AI Act exposure map. You receive a prioritised roadmap that you can implement with us or another partner.
ISO/IEC 42001 Implementation
We build the complete system with you: scope, AI policy, risk assessment and treatment, AI system impact assessments under ISO/IEC 42005, Statement of Applicability, responsibilities and maintained evidence. We then run a full internal-audit and management-review cycle and support you during the certification audit.
EU AI Act preparation
We classify your AI systems against the regulation's risk tiers, identify the obligations that apply and prepare the necessary measures. This engagement uses the same management system to avoid creating a separate compliance project.
Ongoing AI management system governance
An AI management system must operate day to day, and certification follows a three-year cycle. We organise internal audits, management reviews, regulatory monitoring, updates for new AI Act guidance and recertification preparation. Your governance stays current without immediately creating a dedicated role.
Certification is issued by an independent accredited body. Our role is to build a robust system with you, prepare the expected evidence and support you through the audit.
Controls embedded in your practices, not only in documents.
Our approach mirrors the AI device: controls must exist in the way you work, not only in a binder. Five phases follow the standard's Plan–Do–Check–Act logic, and each produces deliverables you own.
Already ISO 27001 certified? The two standards share a harmonised structure. Your ISMS and AI management system can share policies, a risk method, internal audits and management reviews: one integrated system rather than two parallel programmes. Integrating ISO 27001 and ISO/IEC 42001 is part of Marie's expertise.
You work directly with the founders.
The engagement is not delegated to a junior team. The people designing Neural ICE also lead your workshops and deliver the work. Thomas brings security engineering and technical controls; Marie brings data protection, governance and audit discipline. ISO/IEC 42001 needs both dimensions.
Thomas Kristner
Co-founder · Security & technical controlsThomas has more than fifteen years of experience securing critical systems. He leads the technical dimension of your AI management system: robustness, security controls, logging and traceability designed to withstand an auditor's review.
CISSP · CEH
LinkedIn ↗Marie G. Mansour
Co-founder · Governance, data protection & auditMarie specialises in data protection and works as a Data Protection Officer. She leads the governance dimension: policy, impact assessments, audit methodology and the documentary discipline that prepares the organisation for stage 2.
ISO 27001 Lead Auditor · CIPP/E
LinkedIn ↗Advisory and the AI device share the same standards but remain independent. No advisory engagement requires a hardware purchase. If your roadmap identifies a need for sovereign on-premises AI, advisory clients may receive priority access to the Neural ICE AC:1 founding-customer programme.
Advice independent of hardware salesA 30-minute scoping call. No slides, no pitch.
Tell us where you are. We will explain honestly what appears necessary and what does not. If an ISO/IEC 42001 assessment is not the right next step, we will say so.
- A direct conversation with the founders who will also deliver the engagement
- A first assessment with a fixed scope and price
- Expertise for the Swiss and European context: Swiss FADP, GDPR, FINMA and the AI Act
Request received.
Your request has been recorded. We will contact you as soon as possible.