Pillar 01, the entry point
Compliance and AI governance
Written for the person who has to answer the question. When a tender, a client questionnaire, an insurer or your board asks how AI is governed in your firm, you need a documented answer with a management system behind it.
In short
EPX Intelligence extends the ISO/IEC 27001 management system your firm already runs so that it covers artificial intelligence, producing the AI policy, risk register, control set and audit evidence you need. The output is a firm that is ready for ISO/IEC 42001, and can answer the AI governance question in a tender in one paragraph with a document behind it. Certification itself is awarded by a separate UKAS accredited certification body.
The honest position
We get you ready. An accredited body certifies you. Those two jobs have to stay apart.
Under ISO/IEC 17021-1, an accredited certification body may not provide management system consultancy to a client and then certify that client, and a consultancy relationship can bar them from certifying for two years afterwards. So the two roles are separate by design, and that separation is what makes your certificate worth having.
Our role is the readiness work: the gap assessment, the framework, the documentation, the internal audit dry run, and being in the room when the external auditor arrives. Your role is choosing an accredited body. We will point you at the ones holding UKAS accreditation for ISO/IEC 42001 and take no commission for doing so, because a referral fee would compromise exactly the independence you are paying for.
Where EPX IT stands on its own certifications
A fair question to ask before you buy governance advice. EPX IT holds Cyber Essentials Plus and is implementing ISO/IEC 27001. The ladder below shows exactly where we sit on it.
We think going through it ourselves while advising on it is the right way round. An implementer who has never had to keep a management system alive between audits does not know what they are handing you.
The ladder
The same ladder we are climbing ourselves.
Governance is not one certificate, it is an order of operations. This is the sequence we recommend and the sequence EPX IT is working through in its own business.
The baseline technical controls. Fast, cheap, and the thing most insurers and public tenders now assume.
EPX IT holdsThe same controls, independently tested rather than self assessed. A meaningful step up in evidential weight.
EPX IT holdsA full information security management system: scope, risk, controls, internal audit, management review. The recognised way to evidence security governance under FCA SYSC 13.7 and SRA confidentiality duties.
In progressThe AI management system, extending 27001 to cover how AI is chosen, deployed, monitored and retired. UKAS accredited certification became available in the UK in January 2026, and the number of accredited bodies is still small.
Readiness, offered to clientsWhat you get
What is actually in a governance engagement?
| Deliverable | What it is | Who it satisfies |
|---|---|---|
| Gap assessment | Your current management system mapped against ISO/IEC 42001 clause by clause, with the delta from your existing 27001 quantified. | You, before you commit budget |
| AI acceptable use policy | What staff may and may not put into which tools, written to be read by a fee earner rather than by a lawyer, with an approved tool list behind it. | Your people, and your auditor |
| AI risk register and impact assessments | Risks recorded on the same methodology as your existing information security risks, so you keep one register and one review cycle. | Compliance, and your board |
| Control set and evidence pack | The Annex A controls selected, justified and evidenced, in the format your auditor already expects from you. | The external auditor |
| Tender and questionnaire answers | Pre written, accurate responses to the AI governance questions now appearing in client due diligence, mapped to your evidence. | Whoever fills in the questionnaire |
| Internal audit dry run | We audit you before the certification body does, and fix what we find. | You, before the real audit |
| Regulatory position note | Where your firm sits on the EU AI Act, UK GDPR and your own regulator's current AI expectations, written down so it can be reviewed each year. | Compliance, and the board pack |
Why now
What is driving this, by regulator
Security governance and operational resilience
Security governance expectations under SYSC 13.7 and the operational resilience regime both need evidencing, and ISO/IEC 27001 is the recognised way to do it. AI sits inside that same expectation rather than beside it.
Confidentiality plus live AI guidance
Confidentiality duties already bite hard on document handling, and live SRA guidance on the use of AI is forcing firms to write policy now rather than consider it later. The legal sector is further ahead on this than financial services.
The EU AI Act, and the client questionnaire
Firms exporting into the EU can fall in scope of the EU AI Act, and in our own client conversations most are not yet aware of it. Meanwhile tenders have started asking how AI is governed, which is the trigger that actually moves budget.
Straight answers
Governance questions we get asked
What is ISO/IEC 42001, in one paragraph?
ISO/IEC 42001 is the international management system standard for artificial intelligence. It covers how you decide which AI to use, how you assess the risk and the impact, what controls you put around it, how you audit yourself, and how management reviews it. It uses the same Annex SL structure as ISO/IEC 27001, which is why an existing 27001 holder is not starting from nothing. UKAS granted its first accreditation for it to a UK certification body in January 2026, so accredited certification is possible but the number of bodies able to award it is still small.
Who awards the certificate?
A UKAS accredited certification body awards the ISO/IEC 42001 certificate, after its own independent audit. EPX Intelligence does the readiness work and then stays out of that audit relationship, because under ISO/IEC 17021-1 the consultancy and the certification cannot come from the same organisation. We also take no referral commission from certification bodies, since that would undermine the independence you are paying for.
We hold ISO 27001. How much of 42001 do we already have?
A firm holding ISO/IEC 27001 already has much of ISO/IEC 42001 in place. Your scope statement, risk methodology, document control, internal audit programme, management review cycle, competence and awareness processes and corrective action process all carry across. What is genuinely new is the AI specific risk and impact assessment, the AI system inventory, the lifecycle controls and the third party model considerations. On our own comparison of the two standards we assess an existing 27001 holder at roughly 40 per cent of the way there, and the gap assessment turns that estimate into a number for your firm specifically.
Our management system is technically live but honestly a bit neglected. Is that a problem?
A neglected but technically live management system is very common, and it is better to say so at the start. The most frequent failure we see is a firm deciding it must have a management system and then not aligning the resources to keep it alive long term. If that is your position, the honest first step is remediating 27001 rather than layering 42001 on top of something that will not survive its next audit. We will tell you that rather than sell you the bigger piece of work.
Who do you actually need from our side?
The compliance or quality lead who owns the management system, an hour of the MD or FD at the start and at each review, and your IT manager for the technical control evidence. We would rather have the IT manager involved from day one than surprise them in month two.
Start with the gap assessment
Find out how far your existing management system already takes you.
A 30 minute discovery call, no proposal attached. Bring the question your last tender asked you and we will tell you honestly what it would take to answer it properly.