Member of NVIDIA InceptionNVIDIA Inception
Neural ICE
EN · FR · DE · IT Book a scoping call
Consulting · AI Governance · ISO/IEC 42001

AI governance
you can demonstrate.

Your clients, regulator and board no longer ask only whether you use AI. They want to know how you control it. ISO/IEC 42001 is an international certifiable standard dedicated to AI management systems. We support you from the first assessment through certification-audit preparation. The Neural ICE founders deliver the work directly.

ISO/IEC 42001 · AI management systems AI Act · first Annex III high-risk deadlines in December 2027 GDPR · Swiss FADP · FINMA context
Why now

"We take AI seriously" is not evidence. A certified management system is.

Four forces are converging on the same requirement: show, with evidence, that your AI is under control.

Your clients

Evidence is becoming a commercial criterion

Tenders, vendor questionnaires and due-diligence processes increasingly ask how AI is governed. A policy alone is less convincing than a structured, auditable system. ISO/IEC 42001 provides a recognised framework for answering with evidence.

Regulation

AI Act · December 2027

From 2 December 2027, rules for certain Annex III high-risk AI systems apply, including risk management, traceability and human oversight requirements. An AI management system provides a structured framework for implementing those obligations.

Exposure

Unauthorised AI use escapes governance

AI is already present in many organisations, adopted tool by tool without clear accountability. Governance starts with an honest inventory: which tools are used, on what data and under whose responsibility?

Accountability

The board owns the risk

AI failures are becoming a management-accountability issue. A certified AI management system supports a documented, auditable answer to an essential question: who controls the organisation's use of AI?

The offers

Start with the essentials. Prepare certification at the right time. Stay on course.

Four engagements form a progressive path. Each can stand alone and, where needed, prepare the next. You own every deliverable and can use it with or without us.

01 · Assess

AI Governance Health Check

A fixed-scope assessment: an inventory of the AI tools actually in use, including unauthorised use; gap analysis against clauses 4–10 and all 38 Annex A controls; maturity assessment; and an AI Act exposure map. You receive a prioritised roadmap that you can implement with us or another partner.

3–5 days · fixed fee · remote or on-site

02 · Implement · flagship

ISO/IEC 42001 Implementation

We build the complete system with you: scope, AI policy, risk assessment and treatment, AI system impact assessments under ISO/IEC 42005, Statement of Applicability, responsibilities and maintained evidence. We then run a full internal-audit and management-review cycle and support you during the certification audit.

3–6 months · scope defined after the assessment

03 · Align

EU AI Act preparation

We classify your AI systems against the regulation's risk tiers, identify the obligations that apply and prepare the necessary measures. This engagement uses the same management system to avoid creating a separate compliance project.

2–4 weeks · standalone or combined with engagement 02

04 · Sustain

Ongoing AI management system governance

An AI management system must operate day to day, and certification follows a three-year cycle. We organise internal audits, management reviews, regulatory monitoring, updates for new AI Act guidance and recertification preparation. Your governance stays current without immediately creating a dedicated role.

Ongoing · quarterly rhythm · annual terms

Certification is issued by an independent accredited body. Our role is to build a robust system with you, prepare the expected evidence and support you through the audit.

Method

Controls embedded in your practices, not only in documents.

Our approach mirrors the AI device: controls must exist in the way you work, not only in a binder. Five phases follow the standard's Plan–Do–Check–Act logic, and each produces deliverables you own.

01 · Frame
We involve leadership, analyse the context and define the scope under clauses 4 and 5. We identify your role under the standard, interested parties, their expectations, and the organisational, information-system and physical boundaries. This definition forms the basis of the scope shown on the certificate.
02 · Assess gaps
We assess the current state against clauses 4–10 and all 38 Annex A controls. Each requirement receives a maturity level and target. The report distinguishes what is in place, what needs completing and what is not applicable. It orders priorities and supports planning for the next phase.
03 · Design
We draft the AI policy, risk assessment and treatment method, impact assessments and Statement of Applicability linking controls to identified risks. The documents fit your organisation's language and practices rather than a generic template library.
04 · Implement
Controls selected in the Statement of Applicability are implemented with named owners: competence and awareness backed by evidence, maintained documented information, operational control, and reassessment after significant changes such as a new model, data source or use case.
05 · Prove & certify
We define indicators, run a complete internal-audit and management-review cycle, and close findings after analysing their causes. This produces evidence a stage 2 auditor is likely to examine. During certification, stage 1 reviews the documentation and stage 2 tests the system in practice; we support you through both.

Already ISO 27001 certified? The two standards share a harmonised structure. Your ISMS and AI management system can share policies, a risk method, internal audits and management reviews: one integrated system rather than two parallel programmes. Integrating ISO 27001 and ISO/IEC 42001 is part of Marie's expertise.

Who you'll work with

You work directly with the founders.

The engagement is not delegated to a junior team. The people designing Neural ICE also lead your workshops and deliver the work. Thomas brings security engineering and technical controls; Marie brings data protection, governance and audit discipline. ISO/IEC 42001 needs both dimensions.

TK

Thomas Kristner

Co-founder · Security & technical controls

Thomas has more than fifteen years of experience securing critical systems. He leads the technical dimension of your AI management system: robustness, security controls, logging and traceability designed to withstand an auditor's review.

CISSP · CEH

LinkedIn ↗
MM

Marie G. Mansour

Co-founder · Governance, data protection & audit

Marie specialises in data protection and works as a Data Protection Officer. She leads the governance dimension: policy, impact assessments, audit methodology and the documentary discipline that prepares the organisation for stage 2.

ISO 27001 Lead Auditor · CIPP/E

LinkedIn ↗

Advisory and the AI device share the same standards but remain independent. No advisory engagement requires a hardware purchase. If your roadmap identifies a need for sovereign on-premises AI, advisory clients may receive priority access to the Neural ICE AC:1 founding-customer programme.

Advice independent of hardware sales
First step

A 30-minute scoping call. No slides, no pitch.

Tell us where you are. We will explain honestly what appears necessary and what does not. If an ISO/IEC 42001 assessment is not the right next step, we will say so.

  • A direct conversation with the founders who will also deliver the engagement
  • A first assessment with a fixed scope and price
  • Expertise for the Swiss and European context: Swiss FADP, GDPR, FINMA and the AI Act
We use the information you provide only to contact you. We do not sell it or share it for commercial purposes, and this site uses no advertising trackers. Full privacy notice →

Request received.

Your request has been recorded. We will contact you as soon as possible.

From open weights to real work AI infrastructure under your control Prepared for AI Act governance Data protection by design Incubated at Trust Village · unlimitrust campus 🇨🇭