top of page
Insights


ISO 27001 and Investor Due Diligence: What Series A Companies Need to Know
You have just closed your term sheet. The champagne is barely flat when the investor’s due diligence checklist arrives. Somewhere around question fourteen, it asks about your information security framework. You check with your CTO. The honest answer is a shared Google Drive, a password manager you adopted six months ago, and a vague intention to “do something about security” next quarter.
Daniel Sampson
5 days ago4 min read


ISO 42001 for AI Startups: Building Governance Before Regulators Force Your Hand
Your Series A investor has just asked how you govern your AI models. Your enterprise prospect wants to know how you manage bias in your product. Your board wants assurance that your AI systems are being developed responsibly. You have nothing documented.
This is the situation I see repeatedly when working with AI startups. The technology is impressive, the team is talented, but the governance is non-existent. And in 2026, that gap is becoming a commercial liability.
Daniel Sampson
7 days ago4 min read


Auditing Agentic AI: When the Bot Becomes the User
Over the past couple of years, AI has evolved from a general-purpose tool into something far more autonomous. By 2025, it became a co-pilot. Now, in 2026, we have entered the era of agentic AI — autonomous systems that don't just suggest content but actually execute multi-step workflows, negotiate contracts, and manage cloud budgets without human intervention.
Daniel Sampson
Mar 244 min read


2026 Progress So Far For Sampson ISO Audit & Consult Ltd
It's been an extremely busy start to the year at Sampson ISO Audit & Consult Ltd — barely a moment to breathe. So I thought it sensible to take stock of what we've achieved, how we've delivered it, and where we want to go for the rest of the year.
Daniel Sampson
Mar 193 min read


Internal Audit in the Age of AI: How Risk Assurance Is Changing in 2026
The year 2026 marks a tipping point for risk assurance globally. With the EU AI Act in full effect and ISO/IEC 42001 set to become the global benchmark for trust, it’s quite telling that the traditional once a year internal audit has become obsolete and not fit for purpose in today’s ever changing world.
Daniel Sampson
Mar 123 min read


The EU AI Act Readiness Checklist: 10 Steps to Compliance
As the EU AI Act begins its staged rollout, waiting and seeing is no longer a viable business strategy. For UK firms selling into Europe or using AI internally, the time to audit needs to be now.
This checklist, informed by the ISO/IEC 42001 framework, provides a high level roadmap for your AI Governance and will enable you to get in an appropriate state of readiness ahead of the August 2026 deadline.
Daniel Sampson
Mar 33 min read


Managing Third Party Risk in 2026: Using ISO 27001 and ISO 42001 for Supply Chain Assurance
It’s February 2026. The traditional definition of a corporate perimeter has collapsed. In a hyper connected ecosystem driven by SaaS and integrated AI solutions, your organisation’s greatest vulnerabilities likely lie outside your own walls.
Daniel Sampson
Feb 194 min read


NIS2 vs ISO 27001: What UK Businesses Must Do to Stay Compliant in 2026
As alluded to in earlier articles,, the "Brussels Effect" has now come into play and is dictating laws, standards and policies globally. Even though the UK is outside the EU, the NIS2 (Network and Information Security Directive 2) is directing terms for any British firm serving European markets or acting as a critical supplier. So if you thought ISO 27001 was enough to keep the regulators at bay, it's time for a reality check.
Daniel Sampson
Feb 102 min read


EU AI Act Explained: How ISO 42001 Helps UK Companies Manage AI Risk
It’s a common misconception in 2026 that because we are post Brexit, the EU AI Act doesn't apply to the UK. In reality, if your AI system has an output used within the EU, or if you have a single customer in Paris or Berlin, you are likely within its extraterritorial reach.
It’s a common misconception in 2026 that because we are post Brexit, the EU AI Act doesn't apply to the UK. In reality, if your AI system has an output used within the EU, or if you have a single custom
Daniel Sampson
Feb 52 min read


ISO 42001 Explained: The New Global Standard for AI Risk Management
In 2023 and 2024, businesses rushed to integrate Large Language Models (LLMs) and automated decision making ahead of the increasing emergence of AI related business systems and processes . In 2026,with the EU AI Act in full force and global regulators tightening their grip, moving fast without due regard to compliance has been replaced by moving fast and staying compliant.
Daniel Sampson
Feb 32 min read


ISO 27001 After Certification: How to Maintain Continuous Compliance in 2026
So the champagne has been drunk, the certificate is framed on the wall and the ISO project team have finally gone back to their day jobs. This is what’s known as the ‘Certification Hangover’ and in 2026, it’s the number one reason businesses fail their Year 1 surveillance audits.
Daniel Sampson
Jan 293 min read


What Is Risk Assurance? Why ISO-Certified Businesses Need it in 2026.
Risk assurance is the structured process of providing confidence to stakeholders that risk controls are effective, proportionate and operating as intended. Unlike traditional audits, which assess compliance at a fixed point in time, risk assurance is forward-looking and ongoing.
Daniel Sampson
Jan 223 min read
bottom of page