Trustworthy AI.
Independently assured.

AI governance and ISO/IEC 42001 implementation for Australian government and enterprise, with independent testing to prove the controls work.

03 / The problem

AI is already inside your organisation. The question is whether you can stand behind it.

  • Staff paste organisational data into public AI tools.
  • Vendors switch on AI features inside systems you already run.
  • Models shape decisions without a named owner or evidence they work.

04 / Services

Governance first. Implementation that holds. Testing that proves it.

Governance that stands up to scrutiny.

Know where AI is used, what could go wrong and who is accountable, with a defensible record of how every system was assessed and approved.

What you get

  • AI inventory and use-case register
  • Risk and impact assessments, including Australian Government AI impact assessments
  • Compliance mapping to the government AI policy, the Guidance for AI Adoption and the Privacy Act
  • Policies, roles, accountability and board reporting
Explore governance

Management systems that run, not just exist.

We implement AI management systems the way our founder has run management systems on $2B+ infrastructure projects: obligations into plans, plans into controls, controls into records an auditor can follow.

What you get

  • ISO/IEC 42001 gap assessment and implementation plan
  • AI policy, procedures and Annex A control set
  • Documented information: registers, impact assessments and records
  • Training, internal audit readiness and corrective action process
Explore implementation

Testing that proves the controls work.

Targeted technical testing for the systems that carry the most risk, as part of a governance or implementation engagement or on its own. A sample assessment and test report is available on request.

What you get

  • Chatbot and conversational AI evaluation: accuracy, escalation and failure modes
  • Prompt injection and data-leakage testing
  • Bias and robustness checks
  • Retesting and evidence for sign-off
Explore testing

05 / Why Meriam

Governance and implementation, through every layer of the system.

  1. Application The interface people actually use.
  2. Model The model, its version and configuration.
  3. Data Training, retrieval and input data.
  4. Tools / agents What the system can call and do.
  5. Controls Guardrails, filters and permissions.
  6. Human oversight Who can intervene, and when.
  7. Logging What is recorded, and kept.
  8. Evidence Proof the controls actually work.

AI assurance starts beneath the interface.

We don't assume controls work. We test them.

06 / Verification

What we test when the risk warrants it

  1. Accuracy Does it get the answer right, consistently?
  2. Robustness Does it hold up under noise, edge cases and drift?
  3. Bias Does it treat people and groups fairly?
  4. Prompt injection Can hidden instructions take control?
  5. Data leakage Can it be made to reveal what it shouldn't?
  6. Tool misuse Can it be steered into harmful actions?
  7. Unsafe autonomy Does it act beyond its mandate?
  8. Human escalation Does it hand off when it should?

Flagship engagement

07 / Start here

AI Governance Readiness Assessment

A fixed-scope, fixed-price assessment of where you stand against your obligations and ISO/IEC 42001, and what to fix first.

Duration
2–3 weeks
Investment
From A$20,000 ex GST
Format
Fixed scope
  • Inventory of AI systems and use cases
  • Risk and impact assessment against your obligations
  • ISO/IEC 42001 gap analysis and control map
  • Starter documentation: AI policy, register and impact assessment templates
  • Prioritised roadmap and executive briefing

Every finding traceable.
Every control evidenced.

08 / How we work

A clear path from first look to signed off.

  1. Step 01

    Map

    Find where AI is actually used, by whom, and on what data.

    OutputAI inventory and use-case register

  2. Step 02

    Assess

    Rank the risks against your obligations and appetite.

    OutputRisk-ranked findings

  3. Step 03

    Test

    Probe models and systems for the failures that matter.

    OutputTest results and evidence

  4. Step 04

    Assure

    Document controls and evidence your executives can sign.

    OutputAssurance report and sign-off pack

09 / Frameworks & obligations

Mapped to the standards you are measured against.

ISO/IEC 42001
AI management systems
NIST AI RMF
AI risk management framework
Responsible use of AI in government
Australian Government policy and AI impact assessments
Guidance for AI Adoption
Six essential practices, evolving the Voluntary AI Safety Standard
National AI assurance framework
Shared approach for Australian, state and territory governments
NSW AI Assessment Framework
NSW Government AI use cases
Queensland FAIRA
Queensland Government AI risk assessment
Privacy Act 1988
Australian Privacy Principles
EU AI Act
For organisations serving EU markets
Governance control mapIllustrative
Governance control map: ISO/IEC 42001, NIST AI RMF, AI in Government Policy, the Voluntary AI Safety Standard and the Privacy Act 1988 mapped to seven control domains: accountability, risk assessment, data governance, testing and evaluation, transparency, human oversight, and monitoring and logging.

10 / Expertise

Led by Isaiah Dau.

Meriam is new. The experience behind it isn't.

Isaiah has spent nine years implementing and operating management systems on state and federal infrastructure, energy and mining projects worth $100M to $2B+: turning regulatory obligations into plans, running risk and impact assessments, hosting audits, investigating incidents and closing out corrective actions under regulator scrutiny. For the past two years he has built, deployed, tested and governed AI systems hands-on.

That is what an AI management system needs: someone who has made management systems work in the field, and who knows how AI systems actually behave.

  • IAPP AIGP
  • PECB ISO/IEC 42001 Provisional Implementer
  • ISTQB CTFL
  • ISTQB CT-AI
  • 100% Indigenous-owned

Where the experience comes from

  • Project EnergyConnect Elecnor Australia · 900km SA–NSW–VIC transmission line, $2B+ Senior Environmental Advisor
  • Rio Tinto Gove Operating bauxite mine, Northern Territory Environmental Engineer
  • Major Road and Rail Upgrades Fulton Hogan · alliance delivering for VicRoads Environmental Advisor
  • Mordialloc Freeway & Lathams Road Decmil Group · $300M+ Environmental Engineer
  • Stormwater, Wastewater and Contaminated Land Projects Arup · Melbourne Environmental Engineer
  • Major Rail and Road Infrastructure Projects Lendlease Engineering · CPB Contractors Graduate Environmental Engineer
  • AI systems, 2024 to present Built, deployed, tested and governed AI systems end to end, with a time-stamped development history available as evidence Independent

Regulators worked withSA EPA · NSW EPA · EPA Victoria · NT EPA · DCCEEW

How it maps to ISO/IEC 42001

4 Context and obligations
Applied state and federal legislation, approval conditions and client requirements to define what each project's plans had to control.
5 Leadership and roles
Advised project leadership on compliance obligations; supervised junior staff across a 900km, multi-state programme.
6.1 Risk and impact assessment
Ran risk workshops and impact controls planning, including noise modelling of community impact before night works.
7 Support and documented information
Delivered inductions and training; kept permit and compliance registers, monitoring records and regulator reporting.
8 Operational planning and control
Developed and implemented construction environmental management plans and sub-plans within ISO 14001-aligned systems.
9 Performance evaluation
Designed and ran monitoring programmes, carried out compliance inspections, and hosted internal and external audits.
10 Improvement
Investigated incidents and complaints, raised nonconformance reports, and implemented and verified corrective actions.

Ready to stand behind your AI?

Start with a 20-minute conversation about the system you need to stand behind.

Or email isaiah@meriamconsulting.com.au