Home  /  Services  /  AI Governance & ISO 42001

AI Governance & ISO 42001

ISO/IEC 42001 is the international standard for AI management systems. We help organisations find the AI they are actually running, understand the risk it carries, and build governance that holds up — technically, and in front of an auditor.

Our angle

Security practice, not audit practice

We assess the management system and the attack surface: prompt injection, data poisoning, model extraction, and the way autonomous agents use the permissions you give them.

Most ISO 42001 consultants can do the first. Far fewer can do the second.


What changed in 2026

The EU AI Act’s high-risk obligations were deferred. Standalone high-risk systems now have until 2 December 2027, and AI embedded in regulated products until 2 August 2028. Prohibitions, general-purpose AI rules and the Article 50 transparency obligations already apply — the last of those landed on 2 August 2026 and was never part of the deferral.

That is not a reason to wait. It is the difference between building governance that works and assembling documentation that merely exists.

EU AI ACTISO 42001 SERVICE LADDER2 FEB 2025Prohibitions · AI literacyIN FORCE2 AUG 2025GPAI model rulesIN FORCE2 AUG 2026Art. 50 transparencyIN FORCE · NOT DEFERREDDEFERRED 16 MONTHS2 DEC 2027Annex III high-riskWAS 2 AUG 20262 AUG 2028Annex I · in productsEMBEDDED HIGH-RISK AINothing in the deferral removesan obligation. It moves a date.PREPARATION WINDOW01AI inventory & risk triage1–2 WEEKSAI REGISTER · RISK TRIAGE02ISO 42001 gap analysis3–5 WEEKSGAP REPORT · CERTIFICATION PATH03AI security assessmentPER SYSTEMTHREAT MODEL · RANKED FINDINGS04Zero Trust for AI agentsPER DEPLOYMENTAGENT IDENTITY · SCOPED ACCESS

Digital Omnibus on AI · final Council approval 29 June 2026

What we do

Four steps, each sellable on its own

01

AI inventory & risk triage

Find the AI actually in use, including the tools business units adopted without telling IT. Classify by risk, and against the AI Act’s categories where they apply.

You get: an AI register, risk classification and a prioritised view · 1–2 weeks

02

ISO 42001 gap analysis

Assessment against the standard’s management clauses and Annex A controls, with an honest view of the distance to certification.

You get: gap report, remediation plan, certification timeline · 3–5 weeks

03

AI security assessment

Threat modelling of a specific system: prompt injection, training and retrieval data poisoning, model extraction, and the provenance of the models you rely on.

You get: threat model, ranked findings, control recommendations · per system

04

Zero Trust for AI agents

Agent identity, permissions scoped per task rather than granted standing, tool access limits, and protection of memory and context against poisoning.

You get: agent security assessment and remediation path · per deployment

Identity, least privilege and segmentation applied to a non-human actor — the disciplines we have worked in for years

Worth being clear about

ISO 42001 certification is not EU AI Act compliance

The two overlap substantially, and certification is strong evidence of governance maturity, but they are different instruments with different scopes. Certification helps you demonstrate control. It does not, by itself, discharge your obligations under the Act.

Anyone who tells you otherwise is selling you something.

Frequently asked

What is ISO/IEC 42001?

The international standard for an AI management system, published in 2023. It sets requirements for establishing, implementing, maintaining and improving the governance of artificial intelligence within an organisation, and it is certifiable by accredited certification bodies.

How long does certification take?

For an organisation already certified to ISO 27001, typically six to twelve months from gap analysis to certification audit. Without an existing management system, longer.

What is Zero Trust for AI agents?

Applying Zero Trust principles — verify explicitly, grant least privilege, assume breach — to autonomous agents. In practice: identities that are cryptographically rooted rather than shared, permissions scoped to a single task, constrained tool access, and protection of memory and context against poisoning.

What is shadow AI, and how do you find it?

AI tools adopted by teams without review by security or IT. It is found through discovery across code repositories, cloud environments and user activity — not by asking people, who routinely do not know or do not think to mention it.

We only use AI, we do not build it. Does this apply?

Yes. Deployers carry obligations under the EU AI Act, and in practice most AI risk arrives through third-party tools adopted without review.

Most engagements begin with the inventory, because most organisations cannot yet answer “what AI are we running?” with confidence. It is a short piece of work, and it usually changes the conversation.

Discuss scope