Discipline

Artificial Intelligence

Learn to govern the AI you operate, get help building the system, and have it audited

ISO/IEC 420017 modules · 2 tracks

AI you can account for, not only describe

Accountability for AI is owed to people outside the organisation, and it cannot be assembled after the fact. ISO/IEC 42001 is one frame for building it while the systems are still being chosen.

Overview

AI governance starts with what is already running

Organisations are often further into AI than their inventory says. Models arrive inside purchased software, teams adopt assistants without a procurement step, and a use that was a pilot last quarter is load-bearing this one. The first honest question is not which controls to apply but what is actually running, who owns it, and what it decides.

Closing that gap is mostly bookkeeping, and it is the part that gets skipped: an inventory that is maintained rather than compiled once, impact assessment that looks at the people affected and not only at risk to the organisation, and controls that survive a change of model or supplier. Most of it is governance rather than data science, which is why it usually lands on people who do not build models.

Professional tracks

Build role-specific expertise

All tracks →

Halderstone tracks follow a modular structure. They first establish a strong, role-specific foundation across disciplines, which is then applied to the chosen discipline.

Training modules

Deepen your expertise

All modules →

Each module can be taken on its own and trains the calls a practitioner has to make without being prompted. These are the modules that teach this discipline; the cross-discipline core that every track shares is in the catalogue.

Advisory

Build and improve your AI governance

Learn more →

We help organisations establish practical governance for artificial intelligence across strategy, risk, control, accountability and assurance. This includes structuring AI management systems, embedding oversight into the AI lifecycle, and creating documentation and evidence that support responsible use, internal governance and external scrutiny.

The four phases below are the life of a management system, and an engagement can begin at any one of them.

  1. 01

    Design

    Establishing clear structures and accountability

    AI governance framework and policy design, including AI Management Systems (AIMS) aligned with ISO/IEC 42001

    Definition of roles, responsibilities and decision rights

    AI system classification and risk categories

    Integration into existing management systems (e.g. ISMS, QMS)

    Design of documentation and evidence structures

  2. 02

    Operate

    Making AI governance work in daily practice

    AI risk and system impact assessments

    Operational processes for AI lifecycle management

    Controls for data quality, model changes and human oversight

    Incident and issue handling for AI-related risks

    Enablement of key roles (management, product owners, compliance)

  3. 03

    Assure

    Providing confidence and audit readiness

    Independent reviews of AI governance and AIMS structures

    Control effectiveness and implementation checks

    Outsourced internal audit based on ISO/IEC 42001

    Certification readiness assessments

    Supplier and third-party AI reviews

    Preparation for internal and external audits

  4. 04

    Evolve

    Keeping governance effective as technology and regulation change

    Monitoring regulatory and technological developments

    Scenario analysis for future AI use cases

    Maturity assessments and improvement roadmaps for AIMS

    Executive sparring on strategic AI decisions

    Integration of new requirements into existing systems

Audit

Assess your AI governance

Learn more →

An AI governance audit asks whether the oversight bites: whether the risks identified are the ones the deployed systems actually create, whether the controls hold across a change of model or supplier, and whether anyone would notice if they stopped working.

Supported frameworks

ISO/IEC 42001

EU AI Act

NIST AI RMF

OECD AI Principles

Internal AI governance frameworks

Free · no obligation

Thirty minutes to understand your situation and what you are trying to achieve. No preparation needed on your side.

Length
30 minutes
Where
Video call · link sent by email
Afterwards
Possible next steps, in writing

Prefer to write instead?

Pick a timeYour details

Times shown in
Zurich

The calendar cannot be reached just now. Please send a written brief instead.

Nothing suitable?