Home/Assurance

Governance is the product, not the paperwork

The difference between a model and a system you can defend is whether the decision can still be explained when nobody who built it is in the room. This page sets out what we are certified against, what we build into every system, and what you can ask us to evidence.

What we can evidence today

ISO 27001
Certified information security management
ISO 42001
AI management system alignment
AWS · Azure · GCP
Hyperscaler delivery partners
IBM
Enterprise AI delivery with watsonx

What you can ask us for

Certification evidenceISO 27001 certificate and scope statement, on request under NDA.
Security reviewWe complete client security questionnaires and participate in vendor assessment as standard.
Data handlingDelivery inside your tenancy by default. Where a hosted model is used, boundary and retention terms are agreed in writing first.
Model documentationModel cards, evaluation results and risk register per use case, handed over with the system.
Sub-processorsLIST TO BE SUPPLIED BY NQ

Frequently asked

Is ISO 42001 certification the same as alignment?

No, and we do not claim it. ISO 27001 is a certification we hold. ISO 42001 describes the AI management system our delivery is aligned to. If certification status changes, this page changes with it.

Who is accountable when a model is wrong?

Agreed before build and written into the engagement: which decisions the system may take alone, which require a human, and who owns the outcome in each case. An AI programme without that answer is not ready to deploy.

Do you work with clients under regulatory supervision?

Yes. Financial services, audit and regulated knowledge work are where most of our programmes sit, which is why evidence and traceability lead our design rather than following it.

Vetting us for a procurement process?

We complete client security questionnaires as standard, and our ISO 27001 certificate and scope statement are available under NDA.