Governance is the product, not the paperwork
The difference between a model and a system you can defend is whether the decision can still be explained when nobody who built it is in the room. This page sets out what we are certified against, what we build into every system, and what you can ask us to evidence.
What we can evidence today
- ISO 27001
- Certified information security management
- ISO 42001
- AI management system alignment
- AWS · Azure · GCP
- Hyperscaler delivery partners
- IBM
- Enterprise AI delivery with watsonx
AI Trust, Risk and Security
AI TRiSM is a service line and an operating posture. These are the controls we build in rather than bolt on.
What you can ask us for
| Certification evidence | ISO 27001 certificate and scope statement, on request under NDA. |
|---|---|
| Security review | We complete client security questionnaires and participate in vendor assessment as standard. |
| Data handling | Delivery inside your tenancy by default. Where a hosted model is used, boundary and retention terms are agreed in writing first. |
| Model documentation | Model cards, evaluation results and risk register per use case, handed over with the system. |
| Sub-processors | LIST TO BE SUPPLIED BY NQ |
Frequently asked
Is ISO 42001 certification the same as alignment?
No, and we do not claim it. ISO 27001 is a certification we hold. ISO 42001 describes the AI management system our delivery is aligned to. If certification status changes, this page changes with it.
Who is accountable when a model is wrong?
Agreed before build and written into the engagement: which decisions the system may take alone, which require a human, and who owns the outcome in each case. An AI programme without that answer is not ready to deploy.
Do you work with clients under regulatory supervision?
Yes. Financial services, audit and regulated knowledge work are where most of our programmes sit, which is why evidence and traceability lead our design rather than following it.
Vetting us for a procurement process?
We complete client security questionnaires as standard, and our ISO 27001 certificate and scope statement are available under NDA.
