Compliance and AI governance
Speaks to the compliance or quality lead
- ISO/IEC 42001 readiness, worked as a delta from your ISO 27001
- AI policy, risk register and the audit evidence pack
Your intelligence partner
For regulated and professional services firms that have decided AI matters and want it done properly. We take you from a few keen people with a ChatGPT tab open to something the whole business runs on, with the evidence to prove it is controlled.
EPX Intelligence is a digital transformation practice built on AI, for UK regulated and professional services firms. We get AI working across the whole business, then wrap the governance around it so you can prove it is controlled. Four connected pillars: compliance and governance, AI enablement and adoption, AI driven transformation, and bespoke development.
What changes
Faster, and safe enough to prove it. Governance comes first because it is what lets you move at that speed with confidence.
Not just the handful of enthusiasts already saving a bit of drafting time. The measure is a baseline taken before we start and read again after.
The constraint in most professional services firms is senior capacity. Move the assembly, the chasing and the retrieval off those desks and the constraint moves with it.
A tender, an insurer or a board paper asks how AI is governed, and somebody answers it in a paragraph, from a document, without calling a meeting.
Illustrative. The measured version of this is the baseline we record before any work starts, which is what makes the change provable.
The problem
Most leadership teams have stopped asking whether AI matters. What bugs them is that it is still two or three keen people with a ChatGPT tab open, while the questions have started arriving from outside.
A few enthusiasts are faster. Nothing has changed for the other ninety per cent, because there is no plan to take it firm wide and nothing underneath it to make that safe.
People are pasting client material into tools nobody approved, because no policy told them not to. The first you hear of it is the incident.
Your IT manager is already full, and this is a programme of work rather than a ticket. Nobody can tell the board what good looks like, so it rolls to the next meeting.
Written for your sector
The four connected pillars
Not a menu to choose between. Governance makes everything after it defensible, enablement puts AI in your people's hands, transformation changes the work itself, and development builds what does not exist yet. Most firms start at one or two and move along.
Speaks to the compliance or quality lead
Speaks to the in house IT manager
Speaks to the operations lead and the COO
Speaks to the MD with a competitive problem
Each pillar makes the next one possible. Most firms start at 01 or 02 and move along as the evidence stacks up.
Why us
EPX Intelligence exists because EPX IT built the foundation it stands on. Twenty years of trading, an engineering team, a client base and the credentials below, all earned by the business behind us.
Cyber Essentials and Cyber Essentials Plus are held by EPX IT. ISO/IEC 42001 is the standard we prepare client firms for, and certification against it is awarded by a UKAS accredited body.
Who you actually get
You get the same team from first call to handover.
The people who scope your programme are the people who deliver it. If that has to change, we will tell you before it happens.
How it runs
What has already been asked of you, and which pillar answers it.
No cost, no proposal attachedYour data estate, permissions, licensing, policy position and current AI usage, with your IT manager in the room from the start.
Fixed scope, fixed priceNamed owners and a measured baseline, so you can show the board what changed and an auditor how it was controlled.
Reported quarterly
Are we a fit
The size of your firm is not what decides whether we are a fit.
Most of our clients sit between roughly 100 and 250 people, because that is where board pressure meets a shortage of internal capacity. It describes who tends to find us, and it is not an entry requirement. A 70 person firm with a real deadline is a better fit than a 240 person firm with a passing interest.
We are based in Stafford and we work with firms across the UK.
The business behind us
EPX Intelligence is its AI and governance practice. The engineers, the client relationships and the credentials on this page were all earned by EPX IT, and its managed services business carries on exactly as it is.
Day to day support, monitoring and cyber security for UK SMEs, built to catch problems before anyone has to report them.
Migrations, network and infrastructure refreshes, Microsoft 365 and Azure estate work, delivered as defined projects.
Business connectivity and hosted telephony, alongside the practical services that come with running an estate.




Straight answers
Yes, EPX Intelligence gets client firms ready for ISO/IEC 42001 certification. Getting your firm ready for ISO/IEC 42001 is the core of the governance pillar: the gap assessment, the AI policy and risk register, the control set and the evidence pack, then an internal audit dry run before the real one. The certificate itself is awarded by a UKAS accredited certification body after its own independent audit, and those two roles have to stay separate. On our own position, EPX IT holds Cyber Essentials Plus and is implementing ISO/IEC 27001.
An existing ISO/IEC 27001 certification counts for a great deal towards ISO/IEC 42001. ISO/IEC 42001 uses the same management system structure as 27001, so your scope, risk process, internal audit cycle and management review extend rather than get rebuilt. We put an existing 27001 holder at roughly 40 per cent of the way there. That is our own estimate rather than a published figure, and we will show you how we got to it. More on governance
No, working with EPX Intelligence does not require you to change IT provider. Programmes are bought standalone and work alongside your in house team and whoever supports you today. That is deliberate, because a co managed model is the norm at your size. What we touch, and what we do not
The next step is a conversation
No proposal attached. We will tell you which pillar to start at, what your certifications already buy you, and whether we are right for it.