Skip to main content
INSIGHTS

Insights from Delivery.

Practitioner writing on AI governance, information security, and the regulatory pressure UK organisations are now navigating.

Free assessment

Curious about your own ISO 27001 readiness? Take our free 5-minute ISMS maturity self-assessment, calibrated by an ISO 27001 Lead Implementer (PECB).

Take the assessment →
Topic
Sector

58 insights

AI Governance

10 min read

ISO 42001 for UK Public Sector Suppliers: Transparency Records, Procurement, and the Accountability Question

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

What central government AI transparency obligations mean for suppliers, how AI governance appears in public procurement, and where SC-cleared delivery matters.

  • ISO 42001
  • AI Governance
  • Public Sector
AI Governance

10 min read

ISO 42001 for Recruitment and HR Technology: The Highest-Risk AI Category Nobody Planned For

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Employment and worker management AI is named as high-risk under the EU AI Act. What that means for UK recruitment and HR tech, alongside Equality Act and ICO exposure.

  • ISO 42001
  • AI Governance
  • HR Technology
AI Governance

10 min read

Running a DPIA and an AI Impact Assessment as One Exercise

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP

UK GDPR requires a DPIA. ISO 42001 requires an AI impact assessment. The EU AI Act adds a FRIA. Where they overlap, and how to run them once.

  • AI Governance
  • Data Protection
  • ISO 42001
AI Governance

10 min read

ISO 42001 for UK Healthtech: MHRA, Clinical Safety, and NHS Procurement

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Where AI governance sits alongside medical device regulation, DCB clinical safety standards, and NHS procurement requirements for UK healthtech suppliers.

  • ISO 42001
  • AI Governance
  • Healthtech
Public Procurement

6 min read

Does PPN 014 require Cyber Essentials?

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

It requires it, and in the same sentence it expressly accepts equivalent controls instead. Both halves of that are in the primary text.

  • Cyber Essentials
  • Public Procurement
AI Governance

6 min read

Does Microsoft's SSPA require ISO 42001?

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

No. It names ISO 42001 as one of exactly two ways to satisfy a requirement it does make, and that requirement is a great deal more specific than most suppliers realise.

  • ISO 42001
  • AI Governance
AI Governance

10 min read

How to Answer the AI Section of an Enterprise Security Questionnaire

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP

Enterprise vendor assessments now carry dedicated AI domains. What CAIQ, SIG and sector instruments actually ask, and the artefacts that answer them.

  • AI Governance
  • Enterprise Procurement
  • ISO 42001
AI Governance

11 min read

Second-Party AI Vendor Audit versus a Supplier Questionnaire

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

A questionnaire is the supplier's account of itself. An audit tests it against evidence. When the second instrument earns its cost, and when it does not.

  • AI Governance
  • ISO 42001
  • Enterprise Procurement
  • Supplier Assurance
AI Governance

10 min read

ISO 42001 for UK Financial Services: FCA Expectations, Consumer Duty, and Automated Decisioning

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

How FCA-regulated firms are being asked about AI governance, where Consumer Duty and SM&CR create accountability exposure, and what ISO 42001 evidences. From £2,500.

  • ISO 42001
  • AI Governance
  • Financial Services
AI Governance

8 min read

EU AI Act Article 53 Binds Model Providers, Not Organisations Using Third-Party Models

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP

Article 53 general purpose AI obligations apply to model providers. Organisations deploying third-party models are not caught, though buyers still ask the provenance question.

  • AI Governance
  • EU AI Act
  • ISO 42001
Defence

9 min read

DEFCON 658 versus Def Stan 05-138

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

One is the contract clause that binds you. The other is the control set you are bound to. Confusing them is why suppliers buy the certificate before doing the thing the contract actually asks for.

  • Defence
  • DEFCON 658
  • DEFSTAN 05-138
  • Cyber Security Model
Defence

8 min read

DCC versus Cyber Essentials

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

It is not a choice. Cyber Essentials is a prerequisite for every level of Defence Cyber Certification, and Cyber Essentials Plus for Levels 2 and 3. What each one actually measures.

  • Defence
  • DCC
  • Cyber Essentials
  • DEFSTAN 05-138
Defence

7 min read

What DCC Level 2 Requires That Level 1 Does Not

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

The obvious answer is thirty eight controls. The expensive answer is that you cannot upgrade, Cyber Essentials Plus becomes a prerequisite, and the assessor starts looking for governance.

  • Defence
  • DCC
  • DEFSTAN 05-138
  • Cyber Essentials
Defence

8 min read

DCC versus JOSCAR

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

One is a certification against a defence standard, owned by the MOD. The other is a commercially operated supplier data platform. Neither substitutes for the other, and different people decide whether you need each.

  • Defence
  • DCC
  • JOSCAR
  • Supply Chain
Defence

8 min read

Choosing a DCC Certification Body

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

One rule matters more than price or availability. Your certification body can advise you or assess you, not both, and IASME write that separation into the scheme rather than leaving it to conscience.

  • Defence
  • DCC
  • Certification
  • DEFSTAN 05-138
ISO 42001

7 min read

Who Can Issue an ISO 42001 Certificate in the UK?

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Anyone can issue a certificate. Accredited certification is a different thing, it was unavailable for twenty five months, and no published list stays current. How to check the register yourself.

  • ISO 42001
  • Certification
  • UKAS
  • AI Governance
ISO 42001

7 min read

What ISO 42001 Costs in the UK

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Four different costs with four different owners, and only two of them are published by anyone. How to separate them, and the two variables that actually move your total.

  • ISO 42001
  • Pricing
  • Certification
  • AI Governance
ISO 42001

6 min read

What ISO 19011 Requires of an Internal Auditor

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.

  • Internal Audit
  • ISO 42001
  • ISO 27001
  • Certification
ISO 42001

7 min read

What a Stage 2 Auditor Asks About Clause 9.2

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.

  • Internal Audit
  • ISO 42001
  • Certification
  • ISO 27001
ISO 42001

6 min read

ISO 42001 Internal Audit versus Pre-Certification Readiness Audit

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Bought at the same point, priced similarly, and routinely assumed to be the same thing. One discharges clause 9.2. The other cannot, and the sequencing is where the money leaks.

  • Internal Audit
  • ISO 42001
  • Certification
Certification

6 min read

Readiness Assessment, Internal Audit, Certification Audit: Three Different Things

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.

  • Certification
  • Internal Audit
  • ISO 27001
  • ISO 42001
ISO 42001

8 min read

Can the Consultancy That Built Your AIMS Also Audit It?

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.

  • ISO 42001
  • Internal Audit
  • Certification
  • AI Governance
ISO 42001

9 min read

Why a GRC Platform Is Not an AI Management System

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

What compliance platforms do well for ISO 42001, what they cannot do, and where the practitioner work actually sits.

  • ISO 42001
  • AI Governance
  • GRC

12 min read

How to Choose an ISO 42001 Consultant in the UK

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Six things to check before you engage an ISO 42001 consultant, including the independence rule in ISO/IEC 42006 that decides who is allowed to audit what they built.

  • ISO 42001
  • AI Governance
  • Procurement
Defence

9 min read

Defence Cyber Certification: the four levels, and what each one actually asks

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP

The four levels, the control counts, and the three things that catch suppliers out.

  • Defence
  • DCC
  • DEFCON 658
  • DEFSTAN 05-138
ISO 42001

10 min read

Why ISO 42001 Certification Does Not Answer an AI Security Questionnaire

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP

ISO 42001 certifies a management system. Enterprise AI questionnaires ask for artefacts the standard does not require. What the gap is, and what closes it.

  • ISO 42001
  • AI Governance
  • Enterprise Procurement
AI Governance

9 min read

ISO 42001 vs NIST AI RMF: Which AI Governance Framework Your Buyers Actually Want

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

A certifiable international standard and a voluntary US framework. What each covers, which buyers recognise which, and when holding both makes sense.

  • AI Governance
  • ISO 42001
  • NIST AI RMF
AI Governance

10 min read

NHS Digital Assurance Is Moving Beyond DTAC: What AI Vendors Need

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP

NHS digital assurance is shifting from a single DTAC pack toward framework-specific routes. What AI vendors bidding into the NHS should prepare, and what to verify.

  • AI Governance
  • Healthtech
  • NHS
AI Governance

12 min read

ISO 42001 and the EU AI Act: What the Standard Covers and What It Does Not

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Where ISO 42001 supports EU AI Act readiness, which obligations the standard does not reach, and how to sequence a compliance programme against the enforcement timetable.

  • AI Governance
  • ISO 42001
  • EU AI Act
AI Governance

9 min read

Microsoft's Supplier Requirements Put ISO 42001 on the Table for AI Suppliers

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP

Microsoft's Supplier Data Protection Requirements v12 add a dedicated AI section and accept ISO 42001 as an assurance route. What that means for AI suppliers.

  • AI Governance
  • ISO 42001
  • Enterprise Procurement

10 min read

Drata Plus ISO 42001: How the AIMS Layers onto the Platform

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

UK senior practitioner read on the Drata ISO 42001 framework module. How cross-mapped controls accelerate Tier A AIMS. Where Tier B needs standalone build.

  • ISO 42001
  • Drata
  • AI Governance
  • GRC Platform
ISO 42001

11 min read

ISO 27001 vs ISO 42001: What Each Standard Actually Governs

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

The practical difference between an information security management system and an AI management system, where the controls overlap, and which one to implement first.

  • ISO 42001
  • ISO 27001
  • AI Governance

9 min read

ISO 42001 for UK SaaS at Series A: What Changes When You Raise

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

UK SaaS Series A and AI governance maturity. What investors ask, what enterprise procurement exposes, and why ISO 42001 before the gate beats ISO 42001 after.

  • ISO 42001
  • AI Governance
  • UK SaaS
  • Series A

11 min read

EU AI Act for UK SaaS Founders: August 2026 in Practical Terms

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

UK SaaS founder selling into EU customers? Practitioner read on what changes 2 August 2026, how the Digital Omnibus moved the high-risk dates, and where ISO 42001 fits.

  • EU AI Act
  • ISO 42001
  • AI Governance
  • UK SaaS

10 min read

Running SOC 2 and ISO 27001 in Parallel: A UK Scaleup Playbook for 2026

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

UK scaleup running SOC 2 and ISO 27001 together? Practitioner playbook on overlap, sequencing, GRC platform choice, audit timing, and what stops most teams.

  • SOC 2
  • ISO 27001
  • Scaleup
  • GRC Platform

10 min read

Board-Ready Cyber Governance: The DSIT Cyber Governance Code in Practice (2026)

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

UK Cyber Governance Code of Practice for boards. Senior practitioner read on what the DSIT Code requires, board accountability, and building board-ready governance.

  • ISO 27001
  • AI Governance
  • Mid-Market
  • Board Governance

7 min read

ISO 27001 vs Cyber Essentials Plus: Which Framework Does Your UK Organisation Need?

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

ISO 27001 or Cyber Essentials Plus? This practical comparison covers scope, cost, procurement recognition, and which UK organisations need which certification.

  • ISO 27001
  • Cyber Essentials
  • Procurement
Bank of Ghana Regulated

8 min read

Third-Party Risk Management for BoG-Regulated Institutions

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Third-party risk is the most common BoG CISD gap. Practitioner guide to supplier risk programmes that satisfy BoG supervisory and ISO 27001 audit expectations.

  • Bank of Ghana
  • CISD
  • Third-Party Risk
  • ISO 27001
Defence Supply Chain

6 min read

Tier 2 UK Aerospace Supplier Achieves Cyber Essentials Plus and JOSCAR Submission in Fourteen Weeks

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Composite case study. A 35 FTE tier-2 UK aerospace supplier closes the JOSCAR gap and lands CE Plus in fourteen weeks. Defence Cyber Foundation engagement.

  • Defence
  • JOSCAR
  • Cyber Essentials Plus
  • Case Study
Defence Supply Chain

11 min read

DEFCON 658 Explained for UK Tier-2 and Tier-3 Defence Suppliers

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

DEFCON 658 explained for UK defence supply chain SMEs. What the clause requires, the five risk profiles, and the most common documentation mistakes.

  • DEFCON 658
  • Defence
  • DEFSTAN 05-138
  • MOD
Defence Supply Chain

11 min read

JOSCAR Stage 2: What UK Tier-2 Defence SMEs Miss

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

JOSCAR Stage 2 explained for UK tier-2 defence SMEs. The cyber security module, the evidence gaps, and the seven-question readiness checklist.

  • JOSCAR
  • Defence
  • ISO 27001
  • Cyber Essentials Plus
Defence Supply Chain

12 min read

DEFSTAN 05-138 Risk Profiling Explained: Very Low to Very High and What Each Means in Evidence

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

DEFSTAN 05-138 risk profiling explained. The five profiles from Very Low to Very High, evidence at each level, and the DCC relationship for UK defence SMEs.

  • DEFSTAN 05-138
  • Defence
  • DCC
  • ISO 27001
ISO 27001

9 min read

ISO 27001 for Ghanaian Fintechs: The International Contract Unlock

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Why UK and EU enterprise buyers require ISO 27001 from Ghanaian fintechs. Practitioner guide to certification for international SaaS contract pipelines.

  • ISO 27001
  • Ghana
  • Fintech
  • Enterprise Sales

9 min read

How long does ISO 27001 implementation actually take?

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

Honest timelines for ISO 27001:2022 implementation calibrated by an ISO 27001 Lead Implementer (PECB). The factors that determine 12 weeks versus 24 weeks.

  • ISO 27001
  • Implementation
  • Timeline

11 min read

Cyber Security and Resilience Bill: what UK organisations need to know

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

The CSRB is the UK's response to NIS2. What it means for UK essential service operators, managed service providers, data centres, and how it intersects with ISO 27001.

  • Regulation
  • CSRB
  • NIS2

11 min read

EU AI Act enforcement timeline for UK organisations

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

UK organisations selling AI products into the EU are in scope of the EU AI Act. The enforcement timeline, key milestones, the Digital Omnibus deferral question, and what to do now.

  • ISO 42001
  • EU AI Act
  • AI Governance

10 min read

ISO 27001 Stage 1 vs Stage 2 audits: what to expect

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

The difference between Stage 1 and Stage 2 certification audits, what auditors actually look for, common nonconformities, and how to avoid them.

  • ISO 27001
  • Audit
  • Certification

10 min read

Choosing a UKAS-accredited certification body for ISO 27001

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

How to choose the right UKAS-accredited certification body for ISO 27001:2022. The factors that affect cost, timeline, audit experience, and certificate acceptance.

  • ISO 27001
  • Certification
  • UKAS
ISO 27001

11 min read

How ISO 27001 Implementation Satisfies BoG CISD Requirements

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

How ISO 27001 Annex A controls map to Bank of Ghana CISD requirements. Single-engagement compliance and certification for BoG-regulated institutions.

  • ISO 27001
  • Bank of Ghana
  • CISD
  • Ghana

6 min read

SOC 2 Cost in the UK (2026): What to Budget and What Drives the Price

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

SOC 2 certification costs in the UK vary widely. This 2026 guide breaks down what drives the price, what Type I vs Type II costs, and how to reduce your total spend.

  • SOC 2
  • Procurement
  • SaaS

9 min read

JOSCAR ISO 27001 Requirements Explained

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

How JOSCAR assessors evaluate ISO 27001 evidence and what that means for defence supply chain bidders preparing for reassessment.

  • JOSCAR
  • ISO 27001
  • Defence

10 min read

Choosing an ISO 27001 Consultant: A Buyer's Guide

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

What to look for, what to avoid, and how to scope an engagement when procuring ISO 27001 implementation support.

  • ISO 27001
  • Procurement

12 min read

ISO 42001 and EU AI Act Readiness for UK Organisations

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

How ISO 42001 maps to the EU AI Act's high-risk obligations, and what a board-ready AI assurance programme looks like ahead of the December 2027 high-risk deadline.

  • ISO 42001
  • AI Governance
  • EU AI Act

11 min read

The UK Cyber Security and Resilience Bill: A Practical Guide

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

What the incoming UK Cyber Security and Resilience Bill means for defence suppliers, regulated enterprise, and central government, and how to prepare your governance posture now.

  • Regulation
  • CSRB
  • Defence
Bank of Ghana Regulated

12 min read

Bank of Ghana CISD: A Practitioner Guide for Regulated Institutions

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

Practitioner guide to the Bank of Ghana Cyber and Information Security Directive. Scope, five domains, enforcement, and ISO 27001 alignment for regulated institutions.

  • Bank of Ghana
  • CISD
  • ISO 27001
  • Ghana

9 min read

The First Enterprise Security Questionnaire: A UK SaaS Founder's Survival Guide for 2026

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

First enterprise security questionnaire paused your UK SaaS deal? Practitioner read on what enterprises actually ask, why your deal stalled, and how to clear the gate.

  • SOC 2
  • ISO 27001
  • Startup
  • Enterprise Sales

10 min read

ISO 27001 vs Cyber Essentials Plus: What Really Differs

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

The real difference between the two UK cyber standards, the twenty-three-control overlap, and realistic CE Plus to ISO 27001 timelines for SMEs.

  • ISO 27001
  • Cyber Essentials

11 min read

ISO 27001 for UK Defence Suppliers: The Practical Guide

By Alfred Obeng, Founder and Principal Consultant

CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

Why MOD prime contractors are mandating ISO 27001, what JOSCAR expects, how to budget and plan an implementation from a Cyber Essentials Plus baseline.

  • ISO 27001
  • Defence
  • JOSCAR

New insights every month. No newsletter yet. We would rather write fewer better pieces than fill an inbox. Bookmark the page or follow us on LinkedIn.

Get in touch

JOSCAR RegisteredCyber Essentials CertifiedFounder-Led Delivery

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.