Blog
Practical guidance on ISO 27001, SOC 2, ISO 42001, GDPR and penetration testing for scaling software companies.
ISO 42001 vs ISO 27001: Do You Need Both, and Which First?
ISO 27001 addresses information security management; ISO 42001 addresses AI management. They can work together, but using AI does not automatically mean you need both certificates. Start with your risks, actual customer requirements and the scope you need independently assessed. ISO 27001, ISO 42001. Your situation A sensible starting point Customers need assurance over information…
Does ISO 42001 Apply If We Use Third-Party AI?
Yes, ISO 42001 can apply to organisations using third-party AI, not only those training models. Whether certification is worthwhile is a separate decision, based on your risks, obligations and assurance needs. A supplier’s certificate does not automatically cover your organisation’s use of its system. ISO 42001 explained. Reason to consider certification now Reason to assess…
Do You Need Drata or Vanta for ISO 42001?
No particular compliance platform is required for ISO 42001. Drata or Vanta can help you manage evidence and workflows, but buying software is not the same as implementing or certifying an AI management system. Decide whether the platform solves a real operating problem for your team. ISO 42001. Situation What to assess You already use…
Do I Need a DPO? The Actual Test, in Plain Language
You do not need a Data Protection Officer simply because you sell software or handle personal data. The decision depends on your processing activities, whether you are a public authority and any additional applicable law. A small company can need a DPO; a large private company is not automatically exempt or automatically required to appoint…
ISO 27001 Surveillance Audit vs Recertification
An ISO 27001 surveillance audit checks continued conformity during the certification cycle. Recertification assesses renewal for the next cycle. Your certificate’s expiry date is therefore not the only date to plan around: keep the external audit schedule, internal audit programme and corrective actions visible throughout the year. NQA certification process. Checkpoint Purpose Planning implication Initial…
GDPR Certification: What Exists, What Does Not, and What Buyers Accept
There is no official GDPR certificate. No EU body issues one, no company can hold one, and any provider selling a “GDPR certified” badge is selling something the regulation does not recognise. What exists instead: approved certification schemes under Article 42 (Europrivacy is the first), ISO 27701 as the certifiable privacy management standard, and the evidence…
ISO 42001 Internal Audit: What the Standard Requires
Target queries: “iso 42001 internal audit requirements” · “iso 42001 clause 9.2” · “who audits an AI management system” Last reviewed: 28 August 2026. This page is refreshed quarterly; the next scheduled review is November 2026. Volatile facts are date-stamped where they appear. The direct answer: ISO/IEC 42001:2023 clause 9.2 requires your organisation to run internal audits of its…
UK GDPR vs EU GDPR: What Is Actually Different
UK GDPR and EU GDPR are substantively near-identical, because UK GDPR is retained EU law. Comply with one properly and you are most of the way to the other. The differences that create real work are administrative: a second representative, second transfer contracts, a second regulator, an annual ICO fee and fines in a different…
ISO 42001 Certification Bodies: Who Is Actually Accredited (and Who Is Not)
Byline: Mahrukh Fatima Last reviewed: 30 August 2026. This list is refreshed quarterly against the accreditation bodies’ own registers. As of 07-08-2026, 15 verified certification bodies hold a tier-1-verifiable accreditation to certify organisations against ISO/IEC 42001, across six accreditation bodies: ANAB (United States), UKAS (United Kingdom), RvA (Netherlands), JAS-ANZ (Australia and New Zealand), SAC (Singapore) and IAS (United…
Drata Partners in the UK and Ireland: Who They Are and How to Choose
Last reviewed: 7 August 2026. This list is refreshed quarterly; partner tiers, review counts and other volatile details are date-stamped as of 07-08-2026. Quick answer: If you have chosen Drata and need help implementing it in the UK or Ireland, the question that matters is who will actually run your programme and where they sit.…