What we certify

Three schemes, one discipline.

Our certification scope covers information security, artificial intelligence and quality management systems.

ISO/IEC 27001:2022

Certification of an information security management system provides independent assurance that the organisation has established, implemented, maintained and continually improved a system for managing information security risks within a defined scope.

Our audit examines the management system against ISO/IEC 27001:2022 and the organisation's own stated arrangements. Certification is not a guarantee that incidents will never occur and is not a statement that every product, service or control is secure.

ISO/IEC 27001 certification in detail โ€” who the standard is for, what we assess, the evidence to prepare and common readiness gaps.

More about ISO/IEC 27001 certification

ISO/IEC 42001:2023

Certification of an artificial intelligence management system provides independent assurance that the organisation has established and operates a management system for the responsible development, provision or use of AI systems within a defined scope.

Our audit examines governance, risk, objectives, life-cycle controls, monitoring and improvement against ISO/IEC 42001:2023. Certification is not approval of a particular AI product, model or outcome.

ISO/IEC 42001 certification in detail โ€” role determination, the AI system inventory, life-cycle controls and human oversight.

More about ISO/IEC 42001 certification

ISO 9001:2015

Certification of a quality management system provides independent assurance that the organisation consistently meets customer and applicable regulatory requirements and pursues continual improvement. Our audit examines the management system against ISO 9001:2015 and the organisation's own stated arrangements. Certification is not a statement that every product or service is defect-free.

ISO 9001 certification in detail โ€” the process approach, records to prepare and the gaps that most often delay Stage 2.

More about ISO 9001 certification

Where we work

We intend to serve organisations through a mix of remote and on-site audit work. Audits may combine remote activity with on-site work where this is appropriate to the audit objectives, risk, scope and scheme requirements. We will travel nationally for on-site audits.

What we do not do

  • We do not provide consultancy on management systems that we certify.
  • We do not design, implement or maintain a client's management system.
  • We do not claim that a certified management system certifies the organisation's products or services.