Skip to main content

Display options

These change how this site looks in your browser and are remembered on this device. They do not replace your own browser or device settings, which apply everywhere and will usually do more.

Text size
Reading
Colour and clarity
Movement and controls
Accessibility statement
SectorsAboutBlogNewsContactCall 01444 222889Book a Consultation

AI Security and ISO 42001 Consultancy

Govern your AI responsibly and prepare for emerging regulation.

AI Security and ISO 42001

As organisations adopt AI, new risks come with it: bias, lack of explainability, security weaknesses, and a fast-moving regulatory picture. ISO 42001 is the international standard for AI management systems, and aligning with it helps you govern your AI responsibly. We help you address the specific risks AI introduces, improve governance and accountability, and build stakeholder trust as AI regulation emerges.

Why AI needs its own governance

AI systems behave differently from traditional software. They can be biased, hard to explain, and introduce security and accountability risks that existing controls were not designed for. ISO 42001 provides a recognised framework for managing those risks deliberately.

How we help you align

From an introductory scoping workshop and a walkthrough of the standard's controls, through gap analysis and risk assessment, up to support developing a complete AI management system. The level you choose determines how far we take you toward full alignment.

Why act now

AI regulation is emerging quickly. Organisations that put governance in place early will be better placed to adopt AI confidently, demonstrate responsibility to stakeholders, and adapt as the rules take shape.

ISO 42001 and how it relates to ISO 27001

ISO/IEC 42001 was published in 2023 and sets out requirements for an AI management system: the policies, roles, risk assessments, controls and reviews an organisation uses to develop, provide or use AI responsibly. It follows the same high level structure as ISO 27001, the information security management system standard, so the two share familiar clauses on context, leadership, planning, support, operation, performance evaluation and improvement. If you already run an ISO 27001 system, much of the management framework can be extended rather than rebuilt. The difference is focus. ISO 27001 protects the confidentiality, integrity and availability of information, while ISO 42001 also asks you to consider how your AI affects people, including fairness, transparency and accountability. Our team includes ISO 27001 Lead Auditor and Lead Implementer experience, which helps when bringing the two together.

The everyday risks of using AI tools

For many organisations the most immediate AI risk is not a complex model but everyday use of generative AI tools. Staff may paste client information, personal data or confidential documents into a tool without knowing where that data goes or whether it may be used to improve the service. Outputs can be wrong while sounding confident, can reflect bias in the data a system learned from, and can be hard to explain when a customer or regulator asks how a decision was reached. AI features are also appearing inside software you already use, sometimes switched on by default. A practical starting point is an inventory of the AI you use, a clear acceptable use policy, and a risk assessment that covers data protection and security, which is exactly where the scoping and gap analysis in our ISO 42001 consultancy focus.

The EU AI Act and UK organisations

The UK has not adopted a single, comprehensive AI law in the way the EU has, and relies largely on existing laws and regulators, including the UK GDPR where AI involves personal data, with the ICO publishing guidance on AI and data protection. The EU AI Act takes a different, risk based approach, with its obligations being phased in over several years. It can also apply to organisations outside the EU, including UK businesses, where they place AI systems on the EU market or where the output of their systems is used in the EU. Whether and how it applies depends on your role and the systems involved, so it is worth taking suitable advice. ISO 42001 does not by itself guarantee compliance with any law, but the governance it builds gives you a sound footing for meeting regulatory expectations.

Who ISO 42001 is for

ISO 42001 is not only for companies building AI models. The standard is written for any organisation that develops, provides or uses AI systems, which includes software businesses adding AI features to their products, service providers using AI in client work, and organisations relying on AI tools in decisions about customers or staff. Certification is voluntary, but clients and partners often ask how suppliers govern their use of AI, and a structured management system gives you a clear, consistent answer. Because AI so often involves personal data, the work overlaps with data protection, and we can connect it with your UK GDPR obligations, data protection impact assessments and existing security controls. Our ISO 42001 consultancy supports organisations in Sussex, London and across the UK, with much of the work delivered remotely.

Where we work

We work with organisations across the UK. Much of our work is delivered remotely, so we support clients wherever they are based, with particular strength in London and the Southeast. We are based in Haywards Heath, West Sussex, and the areas we cover include London, Brighton and Hove, Crawley, Horsham, Haywards Heath, Burgess Hill, Worthing, Guildford, Tunbridge Wells, Reading, Slough, Newbury, Swindon and Bristol.

Want to know if this is the right fit for your organisation? We will talk it through with you, with no obligation.

Get in touch

Help to align with ISO 42001, the international standard for AI management systems. Manage AI-specific risks such as bias, lack of explainability and security, improve governance and accountability, and build stakeholder trust as AI regulation emerges.

Pricing and tiers

Bronze
£1,900
2 days at £950 per day
  • Introduction to ISO 42001 requirements and scoping workshop (half-day, online)
  • Walkthrough of the controls listed in the standard
  • Basic policy templates
  • Guidance on risk assessment methodology and documentation
Silver
Enquire for pricing
  • Full ISO 42001 gap analysis and risk assessment including AI asset inventory
  • Customised policy templates
  • Assistance with risk assessments of existing AI implementation
Gold
Enquire for pricing
  • Everything in Silver
  • Support in developing the complete AI management system

Ready to get started?

Book a consultation and we will tailor this service to your organisation and the risks it faces.

Book a consultation
Questions

Frequently asked questions

It is the international standard for AI management systems, providing a recognised framework for governing AI responsibly, covering risks such as bias, explainability, security, and accountability.

The direction of travel is clear, with AI governance and regulation developing internationally. Aligning with ISO 42001 now helps you prepare rather than scramble to catch up later.

Yes, arguably more so. Putting governance in place as you adopt AI is far easier than retrofitting it later, and it builds trust with stakeholders from the outset.

ISO 27001 is about protecting information, focusing on its confidentiality, integrity and availability. ISO 42001 is about governing AI, covering risks such as bias, lack of transparency and unintended impacts on people, as well as security. Both are management system standards with the same high level structure, so organisations with ISO 27001 can often build ISO 42001 on the same foundations rather than starting from scratch.

Certification is carried out by an independent certification body, ideally one accredited for the standard. Before the audit, you define the scope, carry out risk and impact assessments, put the required policies and controls in place, and run the system long enough to show it works, including internal audit and management review. We help you prepare for that audit, while the certification decision itself rests with the certification body.

It depends on the size of your organisation, the scope of the AI management system and how much is already in place. Costs usually fall into two parts: preparation, whether internal time or consultancy, and the certification body's audit fees. Our starting package, covering a scoping workshop, a walkthrough of the controls, basic policy templates and risk assessment guidance, is £1,900. Certification body fees are separate.

It can. The EU AI Act can apply to organisations based outside the EU, including in the UK, when they place AI systems on the EU market or when the output of their AI systems is used in the EU. What it requires depends on your role, for example as a provider or a deployer, and on the risk category of the system. If you sell into the EU, it is worth taking suitable advice on your position.

They can, with sensible guardrails. The main risks are staff entering personal or confidential information into tools that have not been approved, relying on inaccurate outputs, and using AI in decisions that affect people without appropriate human oversight. A clear acceptable use policy, approved tools with suitable settings, staff awareness and a risk assessment that considers data protection all help, and they fit naturally within an approach aligned to ISO 42001.

Interested in AI Security and ISO 42001?

Book a consultation and we will tailor the right level of support to your organisation.

Book a Consultation