Emerging threats

We support organisations striving to build a trustworthy, safe online environment where users can engage authentically in their communities.
Commercial organisationsWe support commercial organisations operating in a digital world, seeking to protect their reputation and prevent business disruption caused by cyber attacks and compliance breaches.
International programmes and developmentWe support international government organisations and NGOs working to provide infrastructure or improve the capabilities, security and resilience of their nation.
UK government and public sectorWe support UK government organisations responsible for safeguarding critical infrastructure, preserving public trust, and maintaining national security.



It didn’t take long for organisations of all types and sizes to embed AI into their critical operations and products (enter the cliché about efficiency). But, as with all new technology, there is a downside, in that it has surfaced a new problem to address:
It’s often deployed without any formal review, clear ownership, or oversight of the data flowing through it. That means no one knows who's responsible when it makes a mistake, what sensitive data has been shared, or where it could leave you exposed.
Now that AI governance is becoming a standard requirement in client questionnaires, supplier onboarding and procurement processes, you’re probably being asked: “How do you govern AI?”, and many organisations don’t have an answer beyond “yep, we use it”.
ISO/IEC 42001:2023 is the international standard for AI Management Systems (AIMS). It defines how organisations should govern AI responsibly, including practical controls, policies, risk management, oversight and accountability.
The catch that organisations are now discovering is that formal governance frameworks like ISO 42001 assume a mature compliance function is already in place and most aren’t there yet.
So, what do those organisations do when there are still business risks to address?
AI governance is the oversight, policies and controls that determine how AI is managed responsibly within an organisation.
This includes accountability for AI outputs, how risks are identified and handled, what data AI can interact with and who owns it when something goes wrong.
The first question to ask yourself is: What AI do we actually use?
This can be a difficult question to answer – AI has likely been embedded into software and tools that you’ve already procured, perhaps without anyone even reviewing or signing it off.
You first need to identify every tool and use case for AI across the business, including anything that is an additional feature.
For each use case, document your answers to these questions:
This record is what’s known as your AI Register, which is the essential foundation for building your governance position.
Once you have visibility of your AI use, you can then establish how each use case should be governed.
A simple model to follow is “Would I give this task or capability to a child?”. It sounds odd, but it’s a useful guideline for understanding how AI behaves. AI takes instructions literally, it can’t apply context when making judgements, it can be unpredictable and doesn’t recognise when it’s exceeded the goal or made a mistake unless a human catches it.
So, with this in mind, this splits each of your use cases into three categories:
For those who are in a position to commit to the certification, the ISO 42001 framework requires the organisation to build and implement a formal AI Management System (AIMS).
An AIMS consists of:
If the above sounded overwhelming or far beyond your current operational maturity, don’t worry, many are in the same position.
ISO 42001 is a significant investment that requires dedicated time and resources. But it isn’t the only option available when it comes to AI governance, especially for smaller organisations.
Our AI Governance Foundations service has been developed for organisations who are at exactly this stage. You need to start building something tangible to show clients, but you’re not in a position to commit to ISO 42001.
Ultimately, you don't need a certificate to govern AI well. We build your governance on similar principles as ISO 42001, so you get the benefits of a matured compliance framework without the cost of a formal assessment.
When you're ready to certify, you'll already be on the right path towards a mature AIMS.
What you'll gain:
We support organisations with ISO 42001 implementation, including the build and embedding of a formal AIMS required to achieve certification.
What you'll gain:
Wherever you’re at on your AI governance journey, we can support you and help you achieve your goal.
Get in touch with us to discuss what the right next step is.

AI continues to reshape how we live our lives (for better or worse). We all agree there should be limits, but no one can agree where.

Every organisation has that one member of staff who everyone relies on—that single point of failure (or SPOF).

HMRC has just signed a £175 million, ten-year contract with Quantexa, a UK-based data, analytics and AI software company.