CASE STUDY | TEALIUM
ISO 42001 Readiness Case Study: How Tealium Scoped Its AI Management System and Completed a Website Privacy Review
Tealium, a global customer data platform, built the foundation of a certifiable AI Management System and completed an independent website privacy and cookie compliance review with Elevate Consult, inside one coherent governance program.
Scaling AI Governance with Confidence
C L I E N T
Tealium, Inc. San Diego, CA
INDUSTRY
Customer Data Platform (CDP) / MarTech
SERVICES PROVIDE
AI Governance (ISO 42001 readiness), Website Privacy and Cookie Compliance Review
Client Profile
Tealium is a global customer data platform headquartered in San Diego, California, serving enterprise clients across regulated industries. As a CDP operator, Tealium processes personal data at scale and is subject to overlapping privacy frameworks including GDPR, CPRA/CCPA, and emerging AI-specific regulation.
In late 2025, Tealium committed to strengthening its AI governance posture by pursuing ISO/IEC 42001:2023 certification, the first international management-system standard for Artificial Intelligence Management Systems (AIMS). In parallel, the company sought an independent review of its public-facing website to validate cookie, privacy, and tracking practices against GDPR and CPRA/CCPA requirements.
The Challenge
Tealium needed two outcomes from a single advisory partner:
A defensible path to ISO 42001 certification.
The company had AI-related practices in place but no formalized AIMS scope, no Statement of Applicability (SoA), and no documented gap analysis against the standard. Without this foundation, a Stage 1 certification audit would surface design-level nonconformities.
Independent validation of website privacy practices.
Cookie banners, tracking pixels, and privacy notices had been deployed over multiple years and across multiple regulatory updates. Tealium needed an outside assessment to identify gaps under GDPR, the ePrivacy Directive, and CPRA/CCPA, and to feed corrective actions into the same governance program supporting the ISO 42001 effort.
The two workstreams were related: website-facing data practices intersect directly with AI system data handling, and both needed to be addressed inside one coherent compliance program.
The Solution
Elevate Consult delivered a combined engagement covering AI governance readiness and website privacy compliance, sequenced so that findings from each workstream informed the other.
AI GOVERNANCE
ISO 42001 Readiness
Elevate’s GRC team, led by an ISO 42001 Lead Auditor, executed the foundational activities required to bring Tealium to a certifiable state:
Defined the AIMS scope statement and prepared the Statement of Applicability (SoA)
Performed a gap analysis of Tealium’s current AI governance state against ISO 42001: 2023 requirements
Documented and assisted in producing the AIMS mandatory artifacts, including:
AIMS Manual
AIMS Policy
AIMS Corrective Action Plan
Drafted supporting AIMS policies covering
Responsible Use
Model Management
Responsible AI Development
Website Privacy and Cookie Compliance Review
In parallel, Elevate performed a structured review of Tealium’s website across the four review dimensions:
Cookie compliance
First-party and third-party cookie inventory, consent management platform configuration, tracking and pixel review, and opt-in/opt-out validation against GDPR and CPRA/CCPA
Privacy and cookie policy review
Assessment of Privacy Policy, Cookie Policy, and Terms of Service against required disclosures, legal basis documentation, data subject rights language, and “Do Not Sell” mechanisms
Copyright image compliance
Review of image licensing and attribution practices
Section 508 / WCAG 2.0 Level AA accessibility
Trusted Tester testing on the main page and associated compliance pages
Findings were delivered in two formats: a detailed compliance report for the technical and legal teams, and an executive summary for privacy leadership.
A completed website privacy review and a certification-track AIMS foundation
The Outcome
The Website Privacy and Cookie Compliance Review was completed in June 2026. It produced a prioritized list of remediation items that Tealium incorporated directly into its corrective action plan, ensuring that website-facing data practices align with the AIMS controls being implemented across the organization.
On the AI governance workstream, Elevate delivered the foundation required for certification: the AIMS scope, Statement of Applicability, gap analysis, and mandatory documentation are in place. Tealium is now progressing through its internal audit ahead of a planned ISO 42001 certification assessment.
Key results
AIMS scope and Statement of Applicability formalized
Mandatory ISO 42001 documentation produced and approved by Tealium’s AIMS Steering Committee
Website privacy and cookie compliance gaps documented across GDPR, ePrivacy Directive, and CPRA/CCPA
Corrective actions integrated into a single governance program covering both AI and website privacy
Services Provided
ISO 42001 AIMS Scoping and Statement of Applicability
ISO 42001 Gap Analysis against the 2023 standard
AIMS Documentation (Manual, Policy, Corrective Action Plan, Steering Committee Charter)
Responsible AI Policies (Responsible Use, Model Management, Responsible AI Development)
Website Privacy and Cookie Compliance Review (GDPR · ePrivacy · CPRA/CCPA)
Section 508 / WCAG 2.0 Level AA Trusted Tester Assessment
Why Elevate Consult
Elevate Consult is a B2B advisory firm specialized in cybersecurity and AI governance, with ISO 42001 Lead Auditors, CMMC Certified Assessors, and SWIFT CSP Certified Assessors on staff. Our engagements are designed to integrate cleanly with adjacent compliance programs, so that AI governance, information security, and privacy work as one system rather than three.
Frameworks we support: ISO 42001 · ISO 27001 · NIST AI RMF · EU AI Act readiness · GDPR · CPRA/CCPA · CMMC · FedRAMP · SOC 2 · SWIFT CSP · CMS EDE
ISO 42001 / AI Governance Services
Free AI Governance Training
SOVOS SOC 2 Case Study
All Case Studies
FAQ
How did Tealium prepare for ISO 42001 certification?
Tealium engaged Elevate Consult to scope its AI Management System (AIMS), perform a gap analysis against ISO 42001: 2023, prepare the Statement of Applicability, and produce mandatory AIMS documentation including the AIMS Manual, Policy, Corrective Action Plan, and Steering Committee Charter.
What does a website privacy and cookie compliance review include?
For Tealium, Elevate Consult reviewed cookie configurations and tracking against GDPR and CPRA/CCPA, audited privacy and cookie policies for required disclosures, assessed copyright image practices, and performed Section 508 Trusted Tester testing for WCAG 2.0 Level AA accessibility.
Can ISO 42001 and website privacy work be done in one engagement?
Yes. Tealium combined ISO 42001 AIMS readiness and a website privacy and cookie review into a single program with Elevate Consult, so that AI governance controls and website-facing data practices were aligned through one corrective action plan.
Ready to scope your AI Management System?
Audits don’t reward good intentions. They reward evidence.
Prefer to start on your own? Get the Free AI Governance Training