Our expertise
Our services
Who we serve
Insights
About us
Insights Resource Library Careers Let's talk

AI Governance (ISO 42001)

AI governance support for organisations at every stage

Download our brochureSpeak to an expert
Infrastructure

Why does AI governance matter?

AI tools are being embedded across organisations; into products, workflows and services. However, this has created a gap where AI is deployed without formal review, clear ownership when there's a problem, or any record of what data goes into them. Governance expectations around AI are now catching up and rapidly becoming a procurement requirement.

For many organisations, this creates a new problem: if a client or regulator asks how you govern AI, you might not be where you need to be. Staff may be using AI tools with no oversight, or you may be selling an AI-enabled product or service, but you’ve got no evidence to show clients or prospects how you manage it responsibly.

What is ISO 42001?

ISO/IEC 42001:2023 is the first international standard for AI Management Systems. It defines how organisations should govern AI responsibly, including controls, risk management, oversight and accountability.

PGI offers a portfolio of AI governance services designed around where you actually are, from building foundational governance for the first time, through to full ISO 42001 implementation and independent audit.
 

Download our ISO 42001 brochure

The problems we're solving

Most formal AI governance frameworks will assume a mature compliance function, and most organisations aren’t there yet. 

The good news is you may not necessarily need full certification. The cost is high, the resource commitment is significant, and the standard assumes a governance function that may not yet be in place.

But, there are still business risks to address:

Accountability gaps

If AI gets something wrong, or your client makes a complaint about an AI output, who owns it? How does it get fixed?

Data exposure

Do you have a record of what data your staff put into your AI tools? If sensitive client or personal data flows through your AI, what happens if a breach occurs?

Procurement blind spots

New software may have AI features that were never signed off. If left without assessment, this can become a liability later on.
 

Client and regulatory pressure

AI governance is rapidly becoming a procurement requirement. Without demonstratable safeguards, you could lose contracts to a competitor who can satisfy the client's questionnaire or concerns.
 

Talk to us

AI Governance Foundations

ISO 42001 implementation is a significant undertaking that wasn’t designed for smaller organisations who are new to governance. But, full certification isn’t the only option. 

Our Foundations service is designed for organisations that need to start building AI governance without the overhead of a formal certification programme. 

If you’ve been asked by a client or partner to demonstrate responsible use of AI, or you’re new to governance and don’t know where to start, this is the right service for you.

What you'll gain: 

  • Ability to confidently demonstrate to clients and regulators how you govern AI
  • Practical policies and controls embedded into your operations
  • An AI Register covering all systems and use cases across your organisation
  • A prioritised roadmap supporting your ongoing governance journey as your AI evolves
  • A team that understands their AI governance responsibilities
  • Matured governance practices supporting future alignment with ISO 42001
We work alongside your team across five key phases:
Scoping
We identify and document all current AI use across your organisation.

ISO 42001 Implementation 

Our Implementation service delivers end-to-end build and embedding of a formal AI Management System required for ISO/IEC 42001 certification. 

This is designed for organisations that already have governance foundations in place and are ready to commit to the standard.

What you'll gain: 

  • A fully implemented AI Management System aligned to ISO 42001 requirements
  • Audit-ready policies and procedures that meet regulatory expectations
  • Controls embedded into day-to-day operations 
  • Demonstrate to clients and regulators that you govern AI to an internationally recognised standard
  • A team equipped to sustain and mature your AIMS as your AI landscape evolves
We work alongside your team across four key phases:
Scoping
A targeted review and gap analysis of your current AI governance practices

ISO 42001 audit preparedness support

For organisations that have implemented an AI Management System and are looking for an independent, expert assessment of their controls. We will provide a clear assessment of your position to prepare you for audits, so you can pass with confidence and gain certification.

PGI’s consultants hold internationally recognised qualifications in Information Assurance and ISO management including ISO 42001 Auditor and Implementor.
 

Let's talk

Why choose PGI?

Hands on support

We work closely with your team to design and implement what you need, ensuring it aligns with your business operations.

Proportionate by design

Our services are designed by our experts to support organisations at every stage of their AI governance journey. 

Specialist focus

PGI is a dedicated digital security and intelligence consultancy. AI governance sits at the intersection of our expertise and is a core part of what we do.

Experience across sectors

Our consultants have helped organisations across a range of regulated sectors to build and mature their security management systems.

Get started