top of page
Insights


How to Integrate ISO 27001 and ISO 42001 Into a Single Management System
If your organisation already holds ISO 27001 certification and is now developing, deploying, or using AI systems, you are in the strongest possible position to integrate ISO 42001 into your existing management system. Both standards follow the same Annex SL structure. That shared backbone means you are not building a second management system from scratch. You are extending the one you already have.
Daniel Sampson
2 days ago4 min read


ISO 27001 and Investor Due Diligence: What Series A Companies Need to Know
You have just closed your term sheet. The champagne is barely flat when the investor’s due diligence checklist arrives. Somewhere around question fourteen, it asks about your information security framework. You check with your CTO. The honest answer is a shared Google Drive, a password manager you adopted six months ago, and a vague intention to “do something about security” next quarter.
Daniel Sampson
Apr 24 min read


ISO 42001 for AI Startups: Building Governance Before Regulators Force Your Hand
Your Series A investor has just asked how you govern your AI models. Your enterprise prospect wants to know how you manage bias in your product. Your board wants assurance that your AI systems are being developed responsibly. You have nothing documented.
This is the situation I see repeatedly when working with AI startups. The technology is impressive, the team is talented, but the governance is non-existent. And in 2026, that gap is becoming a commercial liability.
Daniel Sampson
Mar 314 min read
bottom of page