Skip to content

Practice area

AI Governance

ROZSUD helps businesses design and implement AI governance frameworks that allow AI adoption to scale without losing control of regulatory, security, privacy and operational risk.

Discuss your matter

Typical deliverables

  • AI system inventory and risk classification
  • AI governance framework and policy set
  • AI impact and risk assessments
  • EU AI Act readiness plan
  • ISO/IEC 42001 gap analysis and AIMS documentation
  • AI vendor due diligence reports
A cross-jurisdiction capability, supported across the jurisdictions in our directory. See jurisdictions

Overview

Why it matters

AI is reaching products, operations and decisions faster than most governance frameworks can adapt. The EU AI Act sets obligations according to the risk of each system and the role of each business; customers and investors ask how AI is controlled; and the same systems raise questions of data protection, security, intellectual property and liability.

We help businesses put that governance in place: an inventory of the AI in use, a risk classification that reflects the AI Act and the business's own risk appetite, clear roles and human oversight, and the policies, assessments and documentation that let AI adoption scale. Where certification is the goal, we implement an AI management system to ISO/IEC 42001 and support the business through the audit.

AI governance is joined up with our Privacy & Data Protection, Information Security & Cybersecurity, Commercial & Technology Contracts and Legal Opinions practices, because the same AI system can raise data protection, security, contractual and regulatory questions at once.

This is governance, compliance and assurance work. ROZSUD does not develop, train or technically test AI models. Certification to ISO/IEC 42001 is granted by independent, accredited certification bodies, not by ROZSUD.

Key services

From the first gap analysis to the external audit

We identify the gaps, design the programme, help implement it and support you through external scrutiny — by auditors, customers and regulators.

Certification & External Audit Support

Support through the whole readiness and audit process — for ISO/IEC 27001, ISO/IEC 27701 and ISO/IEC 42001 certification, SOC 2 examinations and other external audits — from the first gap analysis to closing the findings.

  • Building or refining the framework the audit will test
  • Gap analysis against the standard or criteria
  • Policies, procedures, registers and evidence prepared for review
  • Teams prepared for auditor interviews
  • Evidence gathering coordinated across the business
  • Acting as your coordination point with the external auditor, including in audit sessions
  • Remediation of audit findings

Certification and attestation decisions remain with the independent certification or audit body. ROZSUD does not issue certifications and is not a certification body.

Enterprise Sales & Customer Assurance

Security, privacy and, increasingly, AI reviews are a routine step in enterprise procurement, and an unanswered questionnaire can hold up a deal. We help you respond accurately and quickly — removing security and privacy blockers without overstating the controls behind the answers.

  • Customer security and privacy questionnaires
  • RFIs and the security sections of RFPs
  • Vendor due diligence and security reviews
  • Enterprise procurement and contractual security requirements
  • Customer audit requests
  • A reusable assurance pack of policies, summaries and evidence

Scope

What we do

Programme & governance

  • AI Governance Programme Design

    A governance framework sized to how the business builds, buys and uses AI: principles, ownership, decision rights and a roadmap.

  • AI Policies & Governance Procedures

    Acceptable-use, development and procurement policies, and the procedures that put them into practice.

  • Roles, Responsibilities & Oversight

    Accountability for AI across the business, from the board and an AI governance forum to the owner of each system.

  • Human Oversight Frameworks

    Where and how people review, override or stop AI outputs, designed around the risk of each use case.

  • AI Governance Documentation

    The records regulators, auditors and customers expect: inventories, assessments, technical documentation and decision logs.

  • Fractional AI-Governance Support

    An experienced AI-governance lead on an agreed monthly scope, while the internal function is built.

Regulation & risk

  • EU AI Act Readiness

    Whether and how the AI Act applies, the business's role as provider or deployer of each system, and a plan to meet the obligations that follow.

  • AI System Inventory

    A register of the AI systems and models in use or in development, including AI embedded in suppliers' products.

  • AI Risk Classification

    Each system classified against the AI Act's risk categories and the business's own risk appetite.

  • AI Impact & Risk Assessments

    Assessments of the effects of AI systems on people, the business and third parties, including fundamental rights impact assessments where the AI Act requires them.

Security, privacy & third parties

  • AI Security Governance

    Security requirements for AI systems and models — data, access, supply chain and misuse — built into the wider security programme.

  • AI Privacy Alignment

    Lawful basis, transparency, data minimisation and DPIAs for AI systems that process personal data.

  • AI Vendor & Third-Party Risk

    Due diligence on AI providers and models, and oversight of the AI embedded in suppliers' products and services.

  • AI Procurement & Contractual Governance

    Contract terms for buying and supplying AI: data use, intellectual property, performance, transparency and allocation of liability.

Assurance & capability

  • ISO/IEC 42001 Implementation & Readiness

    An artificial intelligence management system (AIMS) built to ISO/IEC 42001, and support through the certification audit.

  • AI Audit & Customer Assurance Readiness

    Evidence and answers for customer AI questionnaires, due diligence and audits of how AI is governed.

  • AI Literacy & Training

    AI literacy programmes for staff and management, aligned with the AI Act, and role-based training for teams that build or use AI.

Frameworks

Frameworks, standards & regulations

Standards and frameworks are chosen — to certify against, to report on or to give a programme its structure. Regulations and legislation apply by law, according to where the business operates and what it does. We work with both, and map one set of controls to the requirements that apply.

Standards

ISO/IEC 42001
Artificial intelligence management systems (AIMS): the requirements, and the basis for certification.
ISO/IEC 27001 and ISO/IEC 27701
Information security and privacy management systems, which an AI management system often builds on.

Frameworks

NIST AI Risk Management Framework
NIST AI RMF 1.0 and its Generative AI Profile, used to structure how AI risks are identified and managed.
NIST Cybersecurity Framework
Used for the security of AI systems and the infrastructure around them.

Regulations & legislation

EU AI Act
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, applying in stages.
GDPR
Where AI systems process personal data: lawful basis, transparency, automated decision-making and DPIAs.

Working with us

Engagement formats

Every engagement is scoped in writing before work begins, in one of these formats or a combination of them.

  • Focused advisory session

    A prepared consultation on a defined security, privacy or AI-governance question, followed by practical action points.

  • Scoped deliverable

    Preparation, review or improvement of a specific policy, procedure, assessment, register, methodology or other governance deliverable.

  • Fractional support

    Ongoing senior security, privacy or AI-governance support under an agreed monthly scope.

  • Programme build or remediation

    Building or improving an ISMS, PIMS, AIMS or broader compliance programme against an agreed framework.

  • Audit & customer assurance support

    Preparation for certification audits, customer audits and enterprise security or privacy reviews, and the remediation that follows.

  • Third-party assurance

    Independent security and privacy assessment of a vendor, partner, investee, acquisition target or other third party, with findings and recommendations.

Timing depends on the size of the organisation, its current maturity, its product and geography, the framework selected and the scope of any audit. We set it out when we scope the work, and we do not promise certification dates.

Questions

Frequently asked

Does the EU AI Act apply to businesses outside the EU?

It can. The AI Act applies to providers that place AI systems on the EU market or put them into service there, and to providers and deployers outside the EU where the output of an AI system is used in the EU. We establish whether it applies, and in which role, before designing anything.

Do we need ISO/IEC 42001 certification?

Certification is voluntary. Some businesses pursue it to answer customer and investor questions with one recognised standard; others use ISO/IEC 42001 as a framework without certifying. We help you decide, and the certification decision itself rests with an independent certification body.

We only use AI tools from other providers. Does this apply to us?

Usually, yes. Businesses that deploy third-party AI have obligations of their own, and much of the AI risk in a typical business sits in tools that were bought rather than built. We start with an inventory of the AI in use, including AI embedded in suppliers' products.

Related

  • Fractional DPO support, privacy programmes, GDPR and global privacy compliance, DPIAs, data mapping, transfers and ISO/IEC 27701.

  • Regulatory, business model, perimeter, payment, gaming, crypto-asset and cross-border opinions for banks, partners and investors.

All practice areas

Discuss your matter with a senior advisor.

Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.