AI system inventory and role mapping
Every model, feature and third-party service, with your role as provider or deployer clarified per system. That role determination is a common source of ambiguity and it changes what you owe.
Governance, Risk & Compliance
ISO/IEC 42001 is the first certifiable management-system standard for artificial intelligence. If you ship AI features, enterprise buyers and the EU AI Act are about to ask how you govern them. We build the management system around AI systems we have actually tested — and we are honest that the standard is young.
ISO/IEC 42001 was published in December 2023 as the first management-system standard built specifically for artificial intelligence. It follows the same Plan-Do-Check-Act structure as ISO 27001, so if you already run an ISMS the shape will be familiar and much of the governance machinery carries over. What is genuinely new is the subject matter: an AI management system requires you to inventory your AI, assess its impact on the people it affects, govern the data your models learn from and infer over, and keep named humans accountable for outcomes.
The cleanest way to think about the relationship with regulation is this: the EU AI Act is the rulebook, and ISO 42001 is the operating system you run to satisfy it. They are related but not equivalent, and certification against 42001 does not by itself make you compliant with the Act. Vendors conflating the two are doing you a disservice, because the gap between them is where the obligations that actually bite tend to live.
An honest caveat, because it affects whether you should do this now. ISO 42001 is young and its certification ecosystem is still forming. A certificate today is a real and differentiating signal to enterprise buyers, but it is not yet the universally recognised badge that ISO 27001 has become. For some organisations readiness is the right target and certification can wait. We will tell you which of those you are, and we would rather lose the certification engagement than sell you one you did not need.
Coverage
Scoped to the AI you actually run — including the models you did not build, because a bought-in model in a customer-facing workflow is still your accountability.
Every model, feature and third-party service, with your role as provider or deployer clarified per system. That role determination is a common source of ambiguity and it changes what you owe.
Risk to the organisation, assessed with a documented and repeatable method — the familiar half of the standard for anyone who has run an ISMS.
Effects on individuals and groups affected by the system, which is the genuinely new discipline and the one most organisations have no existing process for.
Provenance, quality, representativeness and rights for training, fine-tuning and inference data — including what your vendors do with prompts you send them.
The AI-specific control set, tailored and justified control by control in the same way ISO 27001 expects.
Documented development, deployment, monitoring and decommissioning, plus the improvement loop the standard requires once a system is live.
Prompt injection, model abuse, data leakage and agent tool abuse, tested against the running system and fed back into the management system as evidence.
Approach
We test before we write policy. A management system built on an untested assumption about what your AI can be made to do is a document, not a control.
The boundary of the management system, your role or roles, and which AI systems are inside it.
Against the clauses and the Annex A controls, with existing ISO 27001 machinery credited rather than rebuilt.
Adversarial testing of the AI systems in scope, so the risk assessment is grounded in what actually happened rather than what was assumed.
Policy, risk and impact assessment processes, data governance and the Annex A controls, with named owners for AI decisions.
Confirming the management system genuinely operates — the same clause 9 discipline that decides ISO 27001 outcomes.
Support through external audit if certification is the right call, and post-deployment monitoring either way so the next model update does not quietly reopen a closed risk.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Every model and AI-enabled feature, with role, purpose, data sources and named owner.
Both halves — risk to the organisation and impact on affected individuals — with methodology recorded.
Annex A controls justified individually, with inclusions and exclusions defensible on their own terms.
Written for how your teams actually build and ship AI, not lifted from a template pack.
Prompt injection, data leakage and agent abuse findings feeding the management system as real evidence.
An honest position on whether you are ready for external audit, and what it would take if you are not.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
No. The EU AI Act is law and ISO 42001 is a voluntary management-system standard. Certification helps you operationalise and evidence many of the Act’s expectations — governance, risk management, documentation, post-market monitoring — but it does not by itself make you compliant, and no certificate can. Treat the Act as the rulebook and 42001 as the operating system you run to satisfy it, then check the gap between them deliberately.
Yes. It is the first certifiable AI management system standard, published in December 2023 (as of August 2026). The caveat is that the certification ecosystem is still maturing — accredited bodies and experienced auditors are fewer than for ISO 27001. A certificate is a genuine differentiator with enterprise buyers today, but for some organisations documented readiness is the better use of budget for now, and we will say so.
A great deal. The structure is the same, so your governance, internal audit, management review, document control and improvement processes largely transfer. What does not transfer is the AI-specific substance: the AI inventory, the impact assessment discipline, data governance for training and inference, and the Annex A controls. We map onto your existing management system rather than standing up a parallel one.
Both, and in that order. We test for prompt injection, guardrail bypass, retrieval-layer data leakage and agent tool abuse against the running system, then build the management system on what the testing found. A risk assessment written before anyone tried to break the thing is a statement of assumptions, and it tends not to survive contact with a motivated user.
Yes, and it has to. Your accountability for an AI-enabled workflow does not disappear because the model came from a vendor. The standard distinguishes provider and deployer roles, and part of the work is establishing which you are for each system — plus what your vendors do with the data you send them, which is a data governance question most organisations have not asked.
Mostly enterprise procurement teams, particularly where the buyer is in the EU or has EU exposure, and increasingly anyone whose customers are working through their own AI governance obligations and pushing them down the supply chain. If you sell AI-enabled software to large organisations, the questionnaire is coming whether or not the Act reaches you directly.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.