Hael
Sign inBook a call

AI GOVERNANCE AND COMPLIANCE ADVISORY

The advisory firm for AI governance and compliance.

We take companies through ISO/IEC 42001, SOC 2, ISO 27001 and the EU AI Act, answer the security reviews their buyers send, and keep the evidence current afterwards.

WHY HAEL

Most failed reviews are not failures of security. They are failures of evidence.

The standards are public. Anyone can read the SOC 2 criteria or download ISO/IEC 42001. What separates a certificate from a rejected report is whether the evidence holds together when someone examines it, and whether it still describes what you do six months later.

Practice

Every engagement is led by someone who has taken organisations through authorisation and supervision. That judgement is what stops a scope being drawn wrong in week one and found in month six.

Method

Fixed scope, fixed price, and a schedule you can see from the start. You know what happens each week, what we need from you, and what you hold at the end.

Record

Your systems, controls, evidence and approvals live in one place. It is included in every engagement, and it stays yours when we finish.

WHAT WE DO

The part nobody else does.

Compliance platforms show you which controls are missing. Certification bodies tell you whether you passed. Neither one writes the policy, gathers the evidence, runs the project, or sits with your engineers to close the gap. That is the work. We run it from first scope through to certificate, and we manage the platform, the timetable and the certification body along the way.

We work inside Vanta, Drata, Secureframe or whichever platform you already pay for, and on our own record where you have none. Your systems, controls, evidence and approvals live in one place, included in every engagement, and yours to keep afterwards. The tool is not the point. What sits behind the evidence is.

FRAMEWORKS

One partner for every framework

Without adding vendors, handoffs, or advice that contradicts itself.

ISO/IEC 42001
The AI management standard now appearing in enterprise procurement, and already mandatory for some suppliers using AI in sensitive contexts. Read the guide
EU AI Act
Article-by-article classification, technical documentation, and the obligations phasing in through 2027. Read the guide
SOC 2
The report enterprise buyers ask for first, and the one most reviews still begin with.
ISO 27001
The international security standard, usually run alongside SOC 2 so one evidence set serves both.
NIST AI RMF
The framework US buyers ask about, mapped to work you are already doing. Read the guide
GDPR for AI
Where data protection and AI governance overlap, handled once rather than twice. Read the guide

THE DIFFERENCE

A certificate is a moment. Your buyers are asking about now.

Enterprise buyers no longer accept a policy document as proof. They ask who approved the claim, what evidence sits behind it, and when it was last reviewed. Most compliance work produces a document and stops there. We keep the record live, so the answer you give in month nine is as good as the one you gave at audit.

SERVICES

However far along you are

Gap analysis

Where you stand against the standard you are being measured on, and what it will take. Days, not weeks.

Implementation

The management system, controls, documentation and evidence, built to survive examination. We run the project, configure your compliance platform, and prepare you for the certification body.

Internal audit

Required every year, and it cannot be performed by the body that certifies you. We run it independently.

Certification support

Scoping, evidence, and sitting beside you through Stage 1 and Stage 2.

Security reviews and questionnaires

The CAIQ, the SIG, a DDQ, or a buyer's own spreadsheet. Answered from your approved evidence base.

Continuous assurance

Systems change, vendors change, rules change. We keep the record current so the next cycle is a review, not a rebuild.

WHO THIS IS FOR

Three situations we are usually called into

The first enterprise review

A buyer's security or AI questionnaire has arrived, and the answer decides the deal.

Scaling AI across the business

More systems than anyone can track by hand, and no single position that holds across them.

Already certified, now adding AI

SOC 2 or ISO 27001 is in place, and AI governance has to be added without starting over.

HOW WE WORK

Three stages, and you know what happens in each

01

Scope

We review your systems, your target buyers and the standards you are being measured against, and agree a scope, a price and a schedule before any work starts.

02

Build

We stand up the management system, the controls and the evidence, and draft the artefacts against the standard you will be examined on.

03

Assure

After certification we keep the record current, answer buyer reviews from it, and track the regulatory changes that affect you.

ABOUT HAEL

A specialist advisory firm for AI governance and compliance.

Hael is a compliance advisory firm. We work with companies that build, deploy or sell AI, and we take them through the standards their buyers, boards and regulators care about: ISO/IEC 42001, SOC 2, ISO/IEC 27001 and the EU AI Act.

Every engagement is led by a practitioner. We agree scope, price and schedule before any work starts, deliver the management system and the evidence behind it, and stay engaged afterwards so the record remains current as products, controls and rules change.

We do not resell software, and we do not sit examinations. Certification is issued by an accredited certification body. Our work is to get the organisation to the point where that certification is defensible, and to keep it that way.

Advisory practitioner at work in a professional office.

INSIGHTS

Written for the people who have to operationalise it.

Guides and briefings on the standards, the regulations, and the reviews that decide enterprise deals.

View all insights

Tell us the framework and the deadline.

We will tell you what the work actually involves, and what it will cost. Thirty minutes, no obligation.

Book a call

Hael. AI governance and compliance advisory. Engagements are governed by our terms of business. Nothing on this site constitutes legal advice.