AI Governance & ISO 42001 Readiness
Use AI with confidence. Put practical controls around its use and show customers how you manage the risks.
Discuss your AI Governance needsAI can be useful without becoming uncontrolled.
Many small and growing businesses are already using AI in day-to-day work. The challenge is making sure its use is understood, proportionate and reviewed as it changes.
Strategic Data Services helps organisations in Wokingham, Berkshire and the Thames Valley build practical AI governance on top of their existing cyber security processes and quality processes.
Staff using AI without clear guidance
Make sensible decisions about what is appropriate, what needs approval and what information should not be shared.
Customer and business information at risk
Consider data handling, access, suppliers and the safeguards needed when AI tools are introduced.
AI-generated work needs checking
Build appropriate human oversight around reliability, accuracy and the decisions that matter to your business.
Customers asking for evidence
Show how AI risks, suppliers and responsibilities are managed, without creating unnecessary bureaucracy.
Practical support at the stage you are in.
AI Governance Readiness Review
Review current AI use, responsibilities, supplier arrangements and controls, then receive a prioritised action plan for practical AI adoption and automation.
Responsible AI Foundations
Establish practical usage rules, ownership, supplier checks, human oversight and staff awareness.
ISO/IEC 42001 Readiness
Identify gaps and plan the management-system work needed, connecting it with existing information-security and quality processes.
Ongoing Governance Support
Review new AI uses, supplier changes, incidents and improvement actions as your use of AI develops.
SDS provides readiness reviews, practical foundations and ongoing governance support. Certification, independent certification audits and full ISO/IEC 42001 implementation are separate activities and are not included in this service.
Familiar management disciplines can support AI governance.
Risk management, document control, competence, supplier review and continual improvement already provide a useful foundation. AI also needs specific attention to impacts, output reliability, appropriate human oversight and changes over time.
Existing ISO 27001, ISO 9001 or Cyber Essentials Plus activity can inform the work, but it does not by itself establish responsible AI management.
Move from uncertainty to a proportionate plan.
Understand
Discuss the business, its AI use and the questions customers or colleagues are raising.
Assess
Review risks, responsibilities and existing controls against the needs of the organisation.
Agree
Set out a practical improvement plan with clear priorities and ownership.
Review
Support the agreed measures as AI use, suppliers and risks change.
AI governance and ISO/IEC 42001
What is ISO/IEC 42001?
ISO/IEC 42001 is an international management-system standard for organisations that develop, provide or use AI. It sets out requirements for establishing, implementing, maintaining and continually improving an AI management system. Read ISO’s overview of ISO/IEC 42001.
Is it relevant if we use AI rather than develop it?
It can be. The right level of governance depends on how you use AI, the information involved, the decisions affected and the expectations of your customers or suppliers.
Do we need certification?
Not necessarily. Some organisations first need a clear view of their AI use and practical controls. Independent certification is a separate decision and activity.
How does it relate to ISO 27001 and ISO 9001?
Those systems can provide useful disciplines for security, quality, risk and continual improvement. AI governance adds attention to the particular impacts and reliability considerations of AI.
Could the EU AI Act apply to a UK business?
Potentially. The EU AI Act can apply to organisations that place AI systems or general-purpose AI models on the EU market, use AI systems in the EU, or operate outside the EU where an AI system’s output is used in the EU. Applicability depends on the organisation’s role and use case, so take legal advice where scope matters. This is general information, not legal advice. Read the European Commission’s AI Act information.
Does SDS provide certification?
No. SDS provides practical governance readiness support; certification is carried out independently.
Understand your current position and agree a practical next step.
Talk to Strategic Data Services about an AI Governance Readiness Review.
Discuss an AI Governance Readiness Review