Emerging threats

We support organisations striving to build a trustworthy, safe online environment where users can engage authentically in their communities.
Commercial organisationsWe support commercial organisations operating in a digital world, seeking to protect their reputation and prevent business disruption caused by cyber attacks and compliance breaches.
International programmes and developmentWe support international government organisations and NGOs working to provide infrastructure or improve the capabilities, security and resilience of their nation.
UK government and public sectorWe support UK government organisations responsible for safeguarding critical infrastructure, preserving public trust, and maintaining national security.



AI tools are being embedded across organisations; into products, workflows and services. However, this has created a gap where AI is deployed without formal review, clear ownership when there's a problem, or any record of what data goes into them. Governance expectations around AI are now catching up and rapidly becoming a procurement requirement.
For many organisations, this creates a new problem: if a client or regulator asks how you govern AI, you might not be where you need to be. Staff may be using AI tools with no oversight, or you may be selling an AI-enabled product or service, but you’ve got no evidence to show clients or prospects how you manage it responsibly.
ISO/IEC 42001:2023 is the first international standard for AI Management Systems. It defines how organisations should govern AI responsibly, including controls, risk management, oversight and accountability.
PGI offers a portfolio of AI governance services designed around where you actually are, from building foundational governance for the first time, through to full ISO 42001 implementation and independent audit.
Most formal AI governance frameworks will assume a mature compliance function, and most organisations aren’t there yet.
The good news is you may not necessarily need full certification. The cost is high, the resource commitment is significant, and the standard assumes a governance function that may not yet be in place.
But, there are still business risks to address:
ISO 42001 implementation is a significant undertaking that wasn’t designed for smaller organisations who are new to governance. But, full certification isn’t the only option.
Our Foundations service is designed for organisations that need to start building AI governance without the overhead of a formal certification programme.
If you’ve been asked by a client or partner to demonstrate responsible use of AI, or you’re new to governance and don’t know where to start, this is the right service for you.
What you'll gain:
Our Implementation service delivers end-to-end build and embedding of a formal AI Management System required for ISO/IEC 42001 certification.
This is designed for organisations that already have governance foundations in place and are ready to commit to the standard.
What you'll gain:
For organisations that have implemented an AI Management System and are looking for an independent, expert assessment of their controls. We will provide a clear assessment of your position to prepare you for audits, so you can pass with confidence and gain certification.
PGI’s consultants hold internationally recognised qualifications in Information Assurance and ISO management including ISO 42001 Auditor and Implementor.