Insights from Delivery.
Practitioner writing on AI governance, information security, and the regulatory pressure UK organisations are now navigating.
Curious about your own ISO 27001 readiness? Take our free 5-minute ISMS maturity self-assessment, calibrated by an ISO 27001 Lead Implementer (PECB).
58 insights
10 min read
ISO 42001 for UK Public Sector Suppliers: Transparency Records, Procurement, and the Accountability Question
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
What central government AI transparency obligations mean for suppliers, how AI governance appears in public procurement, and where SC-cleared delivery matters.
- ISO 42001
- AI Governance
- Public Sector
10 min read
ISO 42001 for Recruitment and HR Technology: The Highest-Risk AI Category Nobody Planned For
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Employment and worker management AI is named as high-risk under the EU AI Act. What that means for UK recruitment and HR tech, alongside Equality Act and ICO exposure.
- ISO 42001
- AI Governance
- HR Technology
10 min read
Running a DPIA and an AI Impact Assessment as One Exercise
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP
UK GDPR requires a DPIA. ISO 42001 requires an AI impact assessment. The EU AI Act adds a FRIA. Where they overlap, and how to run them once.
- AI Governance
- Data Protection
- ISO 42001
10 min read
ISO 42001 for UK Healthtech: MHRA, Clinical Safety, and NHS Procurement
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Where AI governance sits alongside medical device regulation, DCB clinical safety standards, and NHS procurement requirements for UK healthtech suppliers.
- ISO 42001
- AI Governance
- Healthtech
6 min read
Does PPN 014 require Cyber Essentials?
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
It requires it, and in the same sentence it expressly accepts equivalent controls instead. Both halves of that are in the primary text.
- Cyber Essentials
- Public Procurement
6 min read
Does Microsoft's SSPA require ISO 42001?
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
No. It names ISO 42001 as one of exactly two ways to satisfy a requirement it does make, and that requirement is a great deal more specific than most suppliers realise.
- ISO 42001
- AI Governance
10 min read
How to Answer the AI Section of an Enterprise Security Questionnaire
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP
Enterprise vendor assessments now carry dedicated AI domains. What CAIQ, SIG and sector instruments actually ask, and the artefacts that answer them.
- AI Governance
- Enterprise Procurement
- ISO 42001
11 min read
Second-Party AI Vendor Audit versus a Supplier Questionnaire
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
A questionnaire is the supplier's account of itself. An audit tests it against evidence. When the second instrument earns its cost, and when it does not.
- AI Governance
- ISO 42001
- Enterprise Procurement
- Supplier Assurance
10 min read
ISO 42001 for UK Financial Services: FCA Expectations, Consumer Duty, and Automated Decisioning
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
How FCA-regulated firms are being asked about AI governance, where Consumer Duty and SM&CR create accountability exposure, and what ISO 42001 evidences. From £2,500.
- ISO 42001
- AI Governance
- Financial Services
8 min read
EU AI Act Article 53 Binds Model Providers, Not Organisations Using Third-Party Models
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP
Article 53 general purpose AI obligations apply to model providers. Organisations deploying third-party models are not caught, though buyers still ask the provenance question.
- AI Governance
- EU AI Act
- ISO 42001
9 min read
DEFCON 658 versus Def Stan 05-138
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
One is the contract clause that binds you. The other is the control set you are bound to. Confusing them is why suppliers buy the certificate before doing the thing the contract actually asks for.
- Defence
- DEFCON 658
- DEFSTAN 05-138
- Cyber Security Model
8 min read
DCC versus Cyber Essentials
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
It is not a choice. Cyber Essentials is a prerequisite for every level of Defence Cyber Certification, and Cyber Essentials Plus for Levels 2 and 3. What each one actually measures.
- Defence
- DCC
- Cyber Essentials
- DEFSTAN 05-138
7 min read
What DCC Level 2 Requires That Level 1 Does Not
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
The obvious answer is thirty eight controls. The expensive answer is that you cannot upgrade, Cyber Essentials Plus becomes a prerequisite, and the assessor starts looking for governance.
- Defence
- DCC
- DEFSTAN 05-138
- Cyber Essentials
8 min read
DCC versus JOSCAR
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
One is a certification against a defence standard, owned by the MOD. The other is a commercially operated supplier data platform. Neither substitutes for the other, and different people decide whether you need each.
- Defence
- DCC
- JOSCAR
- Supply Chain
8 min read
Choosing a DCC Certification Body
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
One rule matters more than price or availability. Your certification body can advise you or assess you, not both, and IASME write that separation into the scheme rather than leaving it to conscience.
- Defence
- DCC
- Certification
- DEFSTAN 05-138
7 min read
Who Can Issue an ISO 42001 Certificate in the UK?
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Anyone can issue a certificate. Accredited certification is a different thing, it was unavailable for twenty five months, and no published list stays current. How to check the register yourself.
- ISO 42001
- Certification
- UKAS
- AI Governance
7 min read
What ISO 42001 Costs in the UK
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Four different costs with four different owners, and only two of them are published by anyone. How to separate them, and the two variables that actually move your total.
- ISO 42001
- Pricing
- Certification
- AI Governance
6 min read
What ISO 19011 Requires of an Internal Auditor
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.
- Internal Audit
- ISO 42001
- ISO 27001
- Certification
7 min read
What a Stage 2 Auditor Asks About Clause 9.2
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.
- Internal Audit
- ISO 42001
- Certification
- ISO 27001
6 min read
ISO 42001 Internal Audit versus Pre-Certification Readiness Audit
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Bought at the same point, priced similarly, and routinely assumed to be the same thing. One discharges clause 9.2. The other cannot, and the sequencing is where the money leaks.
- Internal Audit
- ISO 42001
- Certification
6 min read
Readiness Assessment, Internal Audit, Certification Audit: Three Different Things
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.
- Certification
- Internal Audit
- ISO 27001
- ISO 42001
8 min read
Can the Consultancy That Built Your AIMS Also Audit It?
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.
- ISO 42001
- Internal Audit
- Certification
- AI Governance
9 min read
Why a GRC Platform Is Not an AI Management System
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
What compliance platforms do well for ISO 42001, what they cannot do, and where the practitioner work actually sits.
- ISO 42001
- AI Governance
- GRC
12 min read
How to Choose an ISO 42001 Consultant in the UK
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Six things to check before you engage an ISO 42001 consultant, including the independence rule in ISO/IEC 42006 that decides who is allowed to audit what they built.
- ISO 42001
- AI Governance
- Procurement
9 min read
Defence Cyber Certification: the four levels, and what each one actually asks
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP
The four levels, the control counts, and the three things that catch suppliers out.
- Defence
- DCC
- DEFCON 658
- DEFSTAN 05-138
10 min read
Why ISO 42001 Certification Does Not Answer an AI Security Questionnaire
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP
ISO 42001 certifies a management system. Enterprise AI questionnaires ask for artefacts the standard does not require. What the gap is, and what closes it.
- ISO 42001
- AI Governance
- Enterprise Procurement
9 min read
ISO 42001 vs NIST AI RMF: Which AI Governance Framework Your Buyers Actually Want
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
A certifiable international standard and a voluntary US framework. What each covers, which buyers recognise which, and when holding both makes sense.
- AI Governance
- ISO 42001
- NIST AI RMF
10 min read
NHS Digital Assurance Is Moving Beyond DTAC: What AI Vendors Need
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP
NHS digital assurance is shifting from a single DTAC pack toward framework-specific routes. What AI vendors bidding into the NHS should prepare, and what to verify.
- AI Governance
- Healthtech
- NHS
12 min read
ISO 42001 and the EU AI Act: What the Standard Covers and What It Does Not
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Where ISO 42001 supports EU AI Act readiness, which obligations the standard does not reach, and how to sequence a compliance programme against the enforcement timetable.
- AI Governance
- ISO 42001
- EU AI Act
9 min read
Microsoft's Supplier Requirements Put ISO 42001 on the Table for AI Suppliers
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP
Microsoft's Supplier Data Protection Requirements v12 add a dedicated AI section and accept ISO 42001 as an assurance route. What that means for AI suppliers.
- AI Governance
- ISO 42001
- Enterprise Procurement
10 min read
Drata Plus ISO 42001: How the AIMS Layers onto the Platform
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
UK senior practitioner read on the Drata ISO 42001 framework module. How cross-mapped controls accelerate Tier A AIMS. Where Tier B needs standalone build.
- ISO 42001
- Drata
- AI Governance
- GRC Platform
11 min read
ISO 27001 vs ISO 42001: What Each Standard Actually Governs
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
The practical difference between an information security management system and an AI management system, where the controls overlap, and which one to implement first.
- ISO 42001
- ISO 27001
- AI Governance
9 min read
ISO 42001 for UK SaaS at Series A: What Changes When You Raise
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
UK SaaS Series A and AI governance maturity. What investors ask, what enterprise procurement exposes, and why ISO 42001 before the gate beats ISO 42001 after.
- ISO 42001
- AI Governance
- UK SaaS
- Series A
11 min read
EU AI Act for UK SaaS Founders: August 2026 in Practical Terms
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
UK SaaS founder selling into EU customers? Practitioner read on what changes 2 August 2026, how the Digital Omnibus moved the high-risk dates, and where ISO 42001 fits.
- EU AI Act
- ISO 42001
- AI Governance
- UK SaaS
10 min read
Running SOC 2 and ISO 27001 in Parallel: A UK Scaleup Playbook for 2026
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
UK scaleup running SOC 2 and ISO 27001 together? Practitioner playbook on overlap, sequencing, GRC platform choice, audit timing, and what stops most teams.
- SOC 2
- ISO 27001
- Scaleup
- GRC Platform
10 min read
Board-Ready Cyber Governance: The DSIT Cyber Governance Code in Practice (2026)
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
UK Cyber Governance Code of Practice for boards. Senior practitioner read on what the DSIT Code requires, board accountability, and building board-ready governance.
- ISO 27001
- AI Governance
- Mid-Market
- Board Governance
7 min read
ISO 27001 vs Cyber Essentials Plus: Which Framework Does Your UK Organisation Need?
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
ISO 27001 or Cyber Essentials Plus? This practical comparison covers scope, cost, procurement recognition, and which UK organisations need which certification.
- ISO 27001
- Cyber Essentials
- Procurement
8 min read
Third-Party Risk Management for BoG-Regulated Institutions
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Third-party risk is the most common BoG CISD gap. Practitioner guide to supplier risk programmes that satisfy BoG supervisory and ISO 27001 audit expectations.
- Bank of Ghana
- CISD
- Third-Party Risk
- ISO 27001
6 min read
Tier 2 UK Aerospace Supplier Achieves Cyber Essentials Plus and JOSCAR Submission in Fourteen Weeks
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Composite case study. A 35 FTE tier-2 UK aerospace supplier closes the JOSCAR gap and lands CE Plus in fourteen weeks. Defence Cyber Foundation engagement.
- Defence
- JOSCAR
- Cyber Essentials Plus
- Case Study
11 min read
DEFCON 658 Explained for UK Tier-2 and Tier-3 Defence Suppliers
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
DEFCON 658 explained for UK defence supply chain SMEs. What the clause requires, the five risk profiles, and the most common documentation mistakes.
- DEFCON 658
- Defence
- DEFSTAN 05-138
- MOD
11 min read
JOSCAR Stage 2: What UK Tier-2 Defence SMEs Miss
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
JOSCAR Stage 2 explained for UK tier-2 defence SMEs. The cyber security module, the evidence gaps, and the seven-question readiness checklist.
- JOSCAR
- Defence
- ISO 27001
- Cyber Essentials Plus
12 min read
DEFSTAN 05-138 Risk Profiling Explained: Very Low to Very High and What Each Means in Evidence
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
DEFSTAN 05-138 risk profiling explained. The five profiles from Very Low to Very High, evidence at each level, and the DCC relationship for UK defence SMEs.
- DEFSTAN 05-138
- Defence
- DCC
- ISO 27001
9 min read
ISO 27001 for Ghanaian Fintechs: The International Contract Unlock
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Why UK and EU enterprise buyers require ISO 27001 from Ghanaian fintechs. Practitioner guide to certification for international SaaS contract pipelines.
- ISO 27001
- Ghana
- Fintech
- Enterprise Sales
9 min read
How long does ISO 27001 implementation actually take?
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Honest timelines for ISO 27001:2022 implementation calibrated by an ISO 27001 Lead Implementer (PECB). The factors that determine 12 weeks versus 24 weeks.
- ISO 27001
- Implementation
- Timeline
11 min read
Cyber Security and Resilience Bill: what UK organisations need to know
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The CSRB is the UK's response to NIS2. What it means for UK essential service operators, managed service providers, data centres, and how it intersects with ISO 27001.
- Regulation
- CSRB
- NIS2
11 min read
EU AI Act enforcement timeline for UK organisations
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
UK organisations selling AI products into the EU are in scope of the EU AI Act. The enforcement timeline, key milestones, the Digital Omnibus deferral question, and what to do now.
- ISO 42001
- EU AI Act
- AI Governance
10 min read
ISO 27001 Stage 1 vs Stage 2 audits: what to expect
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The difference between Stage 1 and Stage 2 certification audits, what auditors actually look for, common nonconformities, and how to avoid them.
- ISO 27001
- Audit
- Certification
10 min read
Choosing a UKAS-accredited certification body for ISO 27001
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
How to choose the right UKAS-accredited certification body for ISO 27001:2022. The factors that affect cost, timeline, audit experience, and certificate acceptance.
- ISO 27001
- Certification
- UKAS
11 min read
How ISO 27001 Implementation Satisfies BoG CISD Requirements
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
How ISO 27001 Annex A controls map to Bank of Ghana CISD requirements. Single-engagement compliance and certification for BoG-regulated institutions.
- ISO 27001
- Bank of Ghana
- CISD
- Ghana
6 min read
SOC 2 Cost in the UK (2026): What to Budget and What Drives the Price
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
SOC 2 certification costs in the UK vary widely. This 2026 guide breaks down what drives the price, what Type I vs Type II costs, and how to reduce your total spend.
- SOC 2
- Procurement
- SaaS
9 min read
JOSCAR ISO 27001 Requirements Explained
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
How JOSCAR assessors evaluate ISO 27001 evidence and what that means for defence supply chain bidders preparing for reassessment.
- JOSCAR
- ISO 27001
- Defence
10 min read
Choosing an ISO 27001 Consultant: A Buyer's Guide
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
What to look for, what to avoid, and how to scope an engagement when procuring ISO 27001 implementation support.
- ISO 27001
- Procurement
12 min read
ISO 42001 and EU AI Act Readiness for UK Organisations
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
How ISO 42001 maps to the EU AI Act's high-risk obligations, and what a board-ready AI assurance programme looks like ahead of the December 2027 high-risk deadline.
- ISO 42001
- AI Governance
- EU AI Act
11 min read
The UK Cyber Security and Resilience Bill: A Practical Guide
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
What the incoming UK Cyber Security and Resilience Bill means for defence suppliers, regulated enterprise, and central government, and how to prepare your governance posture now.
- Regulation
- CSRB
- Defence
12 min read
Bank of Ghana CISD: A Practitioner Guide for Regulated Institutions
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
Practitioner guide to the Bank of Ghana Cyber and Information Security Directive. Scope, five domains, enforcement, and ISO 27001 alignment for regulated institutions.
- Bank of Ghana
- CISD
- ISO 27001
- Ghana
9 min read
The First Enterprise Security Questionnaire: A UK SaaS Founder's Survival Guide for 2026
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
First enterprise security questionnaire paused your UK SaaS deal? Practitioner read on what enterprises actually ask, why your deal stalled, and how to clear the gate.
- SOC 2
- ISO 27001
- Startup
- Enterprise Sales
10 min read
ISO 27001 vs Cyber Essentials Plus: What Really Differs
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The real difference between the two UK cyber standards, the twenty-three-control overlap, and realistic CE Plus to ISO 27001 timelines for SMEs.
- ISO 27001
- Cyber Essentials
11 min read
ISO 27001 for UK Defence Suppliers: The Practical Guide
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Why MOD prime contractors are mandating ISO 27001, what JOSCAR expects, how to budget and plan an implementation from a Cyber Essentials Plus baseline.
- ISO 27001
- Defence
- JOSCAR
New insights every month. No newsletter yet. We would rather write fewer better pieces than fill an inbox. Bookmark the page or follow us on LinkedIn.
JOSCAR RegisteredCyber Essentials CertifiedFounder-Led Delivery
