top of page
Insights


Beyond the Checklist: 7 Top ISO 27001 Audit Findings and How to Avoid Them
For many organisations I’ve worked with, I’ve found that an ISO 27001 audit can be a source of anxiety and worries. But after years of working as a Lead Auditor, I’ve realized that most major Non Conformities don't actually stem from a lack of technology, but come from a lack of Risk Assurance culture.
Daniel Sampson
Mar 63 min read


The EU AI Act Readiness Checklist: 10 Steps to Compliance
As the EU AI Act begins its staged rollout, waiting and seeing is no longer a viable business strategy. For UK firms selling into Europe or using AI internally, the time to audit needs to be now.
This checklist, informed by the ISO/IEC 42001 framework, provides a high level roadmap for your AI Governance and will enable you to get in an appropriate state of readiness ahead of the August 2026 deadline.
Daniel Sampson
Mar 33 min read


NIS2 vs ISO 27001: What UK Businesses Must Do to Stay Compliant in 2026
As alluded to in earlier articles,, the "Brussels Effect" has now come into play and is dictating laws, standards and policies globally. Even though the UK is outside the EU, the NIS2 (Network and Information Security Directive 2) is directing terms for any British firm serving European markets or acting as a critical supplier. So if you thought ISO 27001 was enough to keep the regulators at bay, it's time for a reality check.
Daniel Sampson
Feb 102 min read


ISO 42001 Explained: The New Global Standard for AI Risk Management
In 2023 and 2024, businesses rushed to integrate Large Language Models (LLMs) and automated decision making ahead of the increasing emergence of AI related business systems and processes . In 2026,with the EU AI Act in full force and global regulators tightening their grip, moving fast without due regard to compliance has been replaced by moving fast and staying compliant.
Daniel Sampson
Feb 32 min read
bottom of page