Skip to main content

Elevate

CASE STUDY | TEALIUM

ISO 42001 Readiness Case Study: How Tealium Scoped Its AI Management System and Completed a Website Privacy Review

Tealium, a global customer data platform, built the foundation of a certifiable AI Management System and completed an independent website privacy and cookie compliance review with Elevate Consult, inside one coherent governance program.

C A S E   S T U D Y

Scaling AI Governance with Confidence

C L I E N T

Tealium, Inc. San Diego, CA

INDUSTRY

Customer Data Platform (CDP) / MarTech

SERVICES PROVIDE

AI Governance (ISO 42001 readiness), Website Privacy and Cookie Compliance Review

ENGAGEMENT
November 2025 to present
“Over the past two years, Elevate has provided consistent, responsive service over time and completed all delivered at a high level of quality and on time. This is seemingly simple but rarely accomplished. Elevate has provided internal audit, risk assessment and professional services support for a wide variety of global regulations and compliance frameworks. The Elevate team has been a great partner for Tealium.”
Julie Bennett-Hudel, Tealium

Client Profile

Tealium is a global customer data platform headquartered in San Diego, California, serving enterprise clients across regulated industries. As a CDP operator, Tealium processes personal data at scale and is subject to overlapping privacy frameworks including GDPR, CPRA/CCPA, and emerging AI-specific regulation. 

In late 2025, Tealium committed to strengthening its AI governance posture by pursuing ISO/IEC 42001:2023 certification, the first international management-system standard for Artificial Intelligence Management Systems (AIMS). In parallel, the company sought an independent review of its public-facing website to validate cookie, privacy, and tracking practices against GDPR and CPRA/CCPA requirements. 

The Challenge

Tealium needed two outcomes from a single advisory partner:

A defensible path to ISO 42001 certification.

The company had AI-related practices in place but no formalized AIMS scope, no Statement of Applicability (SoA), and no documented gap analysis against the standard. Without this foundation, a Stage 1 certification audit would surface design-level nonconformities.

 Independent validation of website     privacy practices.

Cookie banners, tracking pixels, and privacy notices had been deployed over multiple years and across multiple regulatory updates. Tealium needed an outside assessment to identify gaps under GDPR, the ePrivacy Directive, and CPRA/CCPA, and to feed corrective actions into the same governance program supporting the ISO 42001 effort.

The two workstreams were related: website-facing data practices intersect directly with AI system data handling, and both needed to be addressed inside one coherent compliance program. 

The Solution

Elevate Consult delivered a combined engagement covering AI governance readiness and website privacy compliance, sequenced so that findings from each workstream informed the other. 

AI GOVERNANCE

ISO 42001 Readiness 

Elevate’s GRC team, led by an ISO 42001 Lead Auditor, executed the foundational activities required to bring Tealium to a certifiable state: 

Defined the AIMS scope statement and prepared the Statement of Applicability (SoA) 

Performed a gap analysis of Tealium’s current AI governance state against ISO 42001: 2023 requirements 

Documented and assisted in producing the AIMS mandatory artifacts, including: 

AIMS Manual

AIMS Policy

AIMS Corrective Action Plan

AIMS Steering Committee Charter & Agenda
 

Drafted supporting AIMS policies covering

Responsible Use

Model Management

Responsible AI Development

Website Privacy and Cookie Compliance Review 

In parallel, Elevate performed a structured review of Tealium’s website across the four review dimensions: 

Cookie compliance

First-party and third-party cookie inventory, consent management platform configuration, tracking and pixel review, and opt-in/opt-out validation against GDPR and CPRA/CCPA 

Privacy and cookie policy review

Assessment of Privacy Policy, Cookie Policy, and Terms of Service against required disclosures, legal basis documentation, data subject rights language, and “Do Not Sell” mechanisms

Copyright image compliance

Review of image licensing and attribution practices 

Section 508 / WCAG 2.0 Level AA accessibility

Trusted Tester testing on the main page and associated compliance pages 

Findings were delivered in two formats: a detailed compliance report for the technical and legal teams, and an executive summary for privacy leadership.

A completed website privacy review and a certification-track AIMS foundation

The Outcome

The Website Privacy and Cookie Compliance Review was completed in June 2026. It produced a prioritized list of remediation items that Tealium incorporated directly into its corrective action plan, ensuring that website-facing data practices align with the AIMS controls being implemented across the organization. 

 

On the AI governance workstream, Elevate delivered the foundation required for certification: the AIMS scope, Statement of Applicability, gap analysis, and mandatory documentation are in place. Tealium is now progressing through its internal audit ahead of a planned ISO 42001 certification assessment. 

AIMS scope and Statement of Applicability formalized 

Mandatory ISO 42001 documentation produced and approved by Tealium’s AIMS Steering Committee 

Website privacy and cookie compliance gaps documented across GDPR, ePrivacy Directive, and CPRA/CCPA 

Corrective actions integrated into a single governance program covering both AI and website privacy 

Services Provided

ISO 42001 AIMS Scoping and Statement of Applicability 

ISO 42001 Gap Analysis against the 2023 standard 

AIMS Documentation (Manual, Policy, Corrective Action Plan, Steering Committee Charter) 

Responsible AI Policies (Responsible Use, Model Management, Responsible AI Development) 

Website Privacy and Cookie Compliance Review (GDPR · ePrivacy · CPRA/CCPA) 

Section 508 / WCAG 2.0 Level AA Trusted Tester Assessment 

Why Elevate Consult

Elevate Consult is a B2B advisory firm specialized in cybersecurity and AI governance, with ISO 42001 Lead Auditors, CMMC Certified Assessors, and SWIFT CSP Certified Assessors on staff. Our engagements are designed to integrate cleanly with adjacent compliance programs, so that AI governance, information security, and privacy work as one system rather than three.

Frameworks we support: ISO 42001 · ISO 27001 · NIST AI RMF · EU AI Act readiness · GDPR · CPRA/CCPA · CMMC · FedRAMP · SOC 2 · SWIFT CSP · CMS EDE

ISO 42001 / AI Governance Services

Free AI Governance Training

SOVOS SOC 2 Case Study

All Case Studies

FAQ

How did Tealium prepare for ISO 42001 certification?

Tealium engaged Elevate Consult to scope its AI Management System (AIMS), perform a gap analysis against ISO 42001: 2023, prepare the Statement of Applicability, and produce mandatory AIMS documentation including the AIMS Manual, Policy, Corrective Action Plan, and Steering Committee Charter.

What does a website privacy and cookie compliance review include?

For Tealium, Elevate Consult reviewed cookie configurations and tracking against GDPR and CPRA/CCPA, audited privacy and cookie policies for required disclosures, assessed copyright image practices, and performed Section 508 Trusted Tester testing for WCAG 2.0 Level AA accessibility.

Can ISO 42001 and website privacy work be done in one engagement?

Yes. Tealium combined ISO 42001 AIMS readiness and a website privacy and cookie review into a single program with Elevate Consult, so that AI governance controls and website-facing data practices were aligned through one corrective action plan.

Ready to scope your AI Management System?

Audits don’t reward good intentions. They reward evidence.

Prefer to start on your own? Get the Free AI Governance Training