Pillar 01, the entry point

Compliance and AI governance

Written for the person who has to answer the question. When a tender, a client questionnaire, an insurer or your board asks how AI is governed in your firm, you need a documented answer with a management system behind it.

In short

EPX Intelligence extends the ISO/IEC 27001 management system your firm already runs so that it covers artificial intelligence, producing the AI policy, risk register, control set and audit evidence you need. The output is a firm that is ready for ISO/IEC 42001, and can answer the AI governance question in a tender in one paragraph with a document behind it. Certification itself is awarded by a separate UKAS accredited certification body.

The honest position

We get you ready. An accredited body certifies you. Those two jobs have to stay apart.

Under ISO/IEC 17021-1, an accredited certification body may not provide management system consultancy to a client and then certify that client, and a consultancy relationship can bar them from certifying for two years afterwards. So the two roles are separate by design, and that separation is what makes your certificate worth having.

Our role is the readiness work: the gap assessment, the framework, the documentation, the internal audit dry run, and being in the room when the external auditor arrives. Your role is choosing an accredited body. We will point you at the ones holding UKAS accreditation for ISO/IEC 42001 and take no commission for doing so, because a referral fee would compromise exactly the independence you are paying for.

Where EPX IT stands on its own certifications

A fair question to ask before you buy governance advice. EPX IT holds Cyber Essentials Plus and is implementing ISO/IEC 27001. The ladder below shows exactly where we sit on it.

We think going through it ourselves while advising on it is the right way round. An implementer who has never had to keep a management system alive between audits does not know what they are handing you.

The ladder

The same ladder we are climbing ourselves.

Governance is not one certificate, it is an order of operations. This is the sequence we recommend and the sequence EPX IT is working through in its own business.

Cyber Essentials

The baseline technical controls. Fast, cheap, and the thing most insurers and public tenders now assume.

EPX IT holds
Cyber Essentials Plus

The same controls, independently tested rather than self assessed. A meaningful step up in evidential weight.

EPX IT holds
ISO/IEC 27001

A full information security management system: scope, risk, controls, internal audit, management review. The recognised way to evidence security governance under FCA SYSC 13.7 and SRA confidentiality duties.

In progress
ISO/IEC 42001

The AI management system, extending 27001 to cover how AI is chosen, deployed, monitored and retired. UKAS accredited certification became available in the UK in January 2026, and the number of accredited bodies is still small.

Readiness, offered to clients

What you get

What is actually in a governance engagement?

DeliverableWhat it isWho it satisfies
Gap assessmentYour current management system mapped against ISO/IEC 42001 clause by clause, with the delta from your existing 27001 quantified.You, before you commit budget
AI acceptable use policyWhat staff may and may not put into which tools, written to be read by a fee earner rather than by a lawyer, with an approved tool list behind it.Your people, and your auditor
AI risk register and impact assessmentsRisks recorded on the same methodology as your existing information security risks, so you keep one register and one review cycle.Compliance, and your board
Control set and evidence packThe Annex A controls selected, justified and evidenced, in the format your auditor already expects from you.The external auditor
Tender and questionnaire answersPre written, accurate responses to the AI governance questions now appearing in client due diligence, mapped to your evidence.Whoever fills in the questionnaire
Internal audit dry runWe audit you before the certification body does, and fix what we find.You, before the real audit
Regulatory position noteWhere your firm sits on the EU AI Act, UK GDPR and your own regulator's current AI expectations, written down so it can be reviewed each year.Compliance, and the board pack

Why now

What is driving this, by regulator

FCA and PRA

Security governance and operational resilience

Security governance expectations under SYSC 13.7 and the operational resilience regime both need evidencing, and ISO/IEC 27001 is the recognised way to do it. AI sits inside that same expectation rather than beside it.

SRA

Confidentiality plus live AI guidance

Confidentiality duties already bite hard on document handling, and live SRA guidance on the use of AI is forcing firms to write policy now rather than consider it later. The legal sector is further ahead on this than financial services.

Cross sector

The EU AI Act, and the client questionnaire

Firms exporting into the EU can fall in scope of the EU AI Act, and in our own client conversations most are not yet aware of it. Meanwhile tenders have started asking how AI is governed, which is the trigger that actually moves budget.

Straight answers

Governance questions we get asked

What is ISO/IEC 42001, in one paragraph?

ISO/IEC 42001 is the international management system standard for artificial intelligence. It covers how you decide which AI to use, how you assess the risk and the impact, what controls you put around it, how you audit yourself, and how management reviews it. It uses the same Annex SL structure as ISO/IEC 27001, which is why an existing 27001 holder is not starting from nothing. UKAS granted its first accreditation for it to a UK certification body in January 2026, so accredited certification is possible but the number of bodies able to award it is still small.

Who awards the certificate?

A UKAS accredited certification body awards the ISO/IEC 42001 certificate, after its own independent audit. EPX Intelligence does the readiness work and then stays out of that audit relationship, because under ISO/IEC 17021-1 the consultancy and the certification cannot come from the same organisation. We also take no referral commission from certification bodies, since that would undermine the independence you are paying for.

We hold ISO 27001. How much of 42001 do we already have?

A firm holding ISO/IEC 27001 already has much of ISO/IEC 42001 in place. Your scope statement, risk methodology, document control, internal audit programme, management review cycle, competence and awareness processes and corrective action process all carry across. What is genuinely new is the AI specific risk and impact assessment, the AI system inventory, the lifecycle controls and the third party model considerations. On our own comparison of the two standards we assess an existing 27001 holder at roughly 40 per cent of the way there, and the gap assessment turns that estimate into a number for your firm specifically.

Our management system is technically live but honestly a bit neglected. Is that a problem?

A neglected but technically live management system is very common, and it is better to say so at the start. The most frequent failure we see is a firm deciding it must have a management system and then not aligning the resources to keep it alive long term. If that is your position, the honest first step is remediating 27001 rather than layering 42001 on top of something that will not survive its next audit. We will tell you that rather than sell you the bigger piece of work.

Who do you actually need from our side?

The compliance or quality lead who owns the management system, an hour of the MD or FD at the start and at each review, and your IT manager for the technical control evidence. We would rather have the IT manager involved from day one than surprise them in month two.

Next pillar: AI enablement and adoption

Start with the gap assessment

Find out how far your existing management system already takes you.

A 30 minute discovery call, no proposal attached. Bring the question your last tender asked you and we will tell you honestly what it would take to answer it properly.