Blog

Practical guidance on ISO 27001, SOC 2, ISO 42001, GDPR and penetration testing for scaling software companies.

  • Data Protection by Design: Building GDPR into Your Product

    Data protection by design means building privacy controls into a product from the first design decision, not bolting them on before launch. Article 25 of the GDPR makes it a legal requirement: you must apply data minimisation, purpose limitation and protective defaults by design and by default, and be able to show you did. What…

  • What is ISO 42001? The AI Management System Standard Explained

    ISO/IEC 42001 is the first international standard for an artificial intelligence management system (AIMS). Published in December 2023, it sets out how an organisation should govern, risk-assess and continually improve the AI it builds or uses. Any organisation can certify to it, whether you develop AI or deploy someone else’s, in any sector. What ISO…

  • EU AI Act and ISO 42001: How the Standard Maps to the Regulation

    ISO 42001 and the EU AI Act are not the same thing. The EU AI Act is binding law that regulates AI by risk level; ISO 42001 is a voluntary management-system standard. Certifying to ISO 42001 does not on its own make you AI Act compliant, but it gives you the governance backbone the regulation…

  • How to Interpret and Act on Penetration Test Results

    A penetration test report is the document a tester gives you after the engagement, setting out every weakness found, how serious each one is, and how to fix it. Acting on it means reading the findings in priority order, remediating the critical and high issues first, then retesting to confirm the fixes hold. What does…

  • ISO 42001 Implementation Guide: Step by Step

    You implement ISO 42001 by scoping your AI management system, running a gap analysis against the standard, inventorying your AI and assessing its impact, then building the policy, roles and lifecycle controls. An internal audit tests the system before an accredited body runs Stage 1 and Stage 2 audits to certify it. How do you…

  • Atoro Becomes Europe’s First ISO 42001 Certified Cyber Compliance Consultancy

    Atoro has become the first consultancy in Europe to achieve ISO 42001 certification, the international standard for artificial intelligence management systems. Certified by A-LIGN, the milestone establishes Atoro as a leader in responsible AI governance and means we now run the same AI management system we help our clients build. Setting the standard for AI…

  • AI Risk Management: Identifying and Mitigating Risk in AI Systems

    AI risk management is the practice of identifying, assessing, treating and monitoring the risks an AI system creates, both to your organisation and to the people affected by it. It covers bias, security, model drift, transparency and third-party risk, and it runs across the whole AI lifecycle rather than as a one-off check before launch.…