Skip to main content
The Goldline Method: Integrated Sprint

ISO 27001 and ISO 42001 built as one management system, certified as two.

For regulated UK organisations and AI-enabled UK scaleups being asked for information security certification and AI governance certification at the same time. Founder-led delivery. Fixed scope. The sequence is fixed. Your timeline is set at the free diagnostic. Investment shared at qualified discovery. The certification decision rests with your certification body.

Delivered by

ISO 42001 Lead Implementer (PECB)
ISO 42001 Lead Auditor (PECB)
ISO 27001 Senior Lead Implementer (PECB)
ISO 27001 Lead Auditor (PECB)
CISSP
Open booking calendar

45 minute call. No sales pitch. Senior practitioner-led discovery.

Book a 45 minute strategy call

Loading the calendar

Open the booking page

Calendar not loading? Open Calendly directly

Why buyers ask for both

The two questions arrive together.

Buyers ask both questions in one questionnaire

Enterprise questionnaires increasingly include AI governance questions alongside the standard ISO 27001 and SOC 2 controls. Answering one and deferring the other holds the deal in review.

EU AI Act obligations are dated

Article 50 transparency obligations apply from 2 August 2026 and Annex III high-risk obligations from 2 December 2027. An AI management system is the structure that carries the evidence.

Two programmes duplicate the same backbone

Scope, risk methodology, objectives, document control, internal audit and management review are written once for both standards, or written twice at twice the cost.

Against the generalist route

Two programmes, or one built properly.

Two separate engagements

  • Two separate engagements, two scoping exercises, two document sets
  • Controls evidenced twice because nobody cross-maps them
  • Two internal audit programmes and two management reviews
  • Consultant fluent in one standard and reading up on the other
  • Overlap discovered late, after the duplicate work is already paid for

Integrated Sprint

  • One scoping exercise producing one management system with two control sets
  • Cross-mapped controls identified once and evidenced once
  • One internal audit programme and one management review covering both
  • Lead Implementer and Lead Auditor credentials in both standards
  • The overlap priced into the engagement from the first day
Why Goldline

The cross-mapping is the product.

01

The cross-mapping is the product

ISO 27001 Annex A controls that also carry AIMS evidence are identified once and evidenced once. That is why the integrated route costs materially less than two programmes, and doing it requires practitioner judgement in both frameworks rather than two consultants working in parallel.

02

Credentials in both standards, held by one practitioner

Alfred Obeng holds the PECB ISO 42001 Lead Implementer and Lead Auditor credentials and the PECB ISO 27001 Senior Lead Implementer and Lead Auditor credentials. The mapping decisions are taken by somebody who has audited against both.

03

One management system, operated as one

One risk methodology, one document control regime, one competence and awareness programme, one internal audit programme, one management review. After handover you run a single operating calendar, not two.

04

Founder-led senior delivery

No subcontracted hours, no associate handoff. The practitioner who scopes the engagement is the practitioner who delivers it.

The method

Four phases across both standards.

Phases are sequenced, not timed. Fixed scope. Timeline calibrated at scoping.

Phase 01: Define · One scope, two standards

What blocks organisations here

Scope is drawn twice and the two drafts disagree. AI systems have never been formally inventoried, so the AIMS boundary has nothing solid to sit against.

What happens in this phase

One scope covering both management systems. Interested parties documented once. AI system inventory built with risk classification. One risk methodology serving information security risk and AI risk. Both policy frameworks drafted. Governance accountability named.

Deliverables

  • One scope and boundary covering the ISMS and the AIMS
  • Interested parties and their requirements, documented once
  • AI system inventory with risk classification
  • One risk methodology, security risk and AI risk
  • Both policy frameworks, approved by top management
  • Governance accountability, named individuals against named decisions
Programme components

What you hold at the end.

One integrated management system

Scope, interested parties, risk methodology, objectives, document control, competence and awareness, internal audit programme and management review, written once to serve both standards.

Two Statements of Applicability

93 ISO 27001 Annex A controls and 38 ISO 42001 Annex A controls, with the cross-mapped controls identified so the same evidence answers both.

The AI-specific layer

AI system inventory and risk classification, AI impact assessment, data governance for training and inference data, explainability records, human oversight procedures.

Evidence packs for both scopes

Assembled against both Statements of Applicability, structured the way an auditor reads them rather than the way a folder tree grows.

Not included: the clause 9.2 internal audit. Where Goldline has built your management system, the internal audit must be run independently and cannot be run by us. We tell you exactly what it has to cover. Budget separately for it. Certification body fees are paid to the body direct, are separate from the Goldline fee and carry no Goldline margin. Goldline is not a certification body and does not issue certificates, in any tense, and will not sell implementation and certification to the same organisation for the same scope.

Scope tiers

Fixed scope. Investment shared at qualified discovery.

Tier is set on the diagnostic. Buying the two programmes separately costs about 20 per cent more at every tier.

Tier 1

Single entity, contained AI estate, an information security foundation already in place or in active implementation.

Tier 2

Multiple products or business units, a wider AI estate, or an information security posture being built from a standing start.

Tier 3

Group structures, multiple certification scopes, regulated sectors, or an AI estate that needs classification work before scope can close.

See the tier bands on the pricing page
The platform layer

Delivered on your GRC platform of choice, or ours.

Cross-mapped controls, both Statements of Applicability and the evidence trail are configured on the platform you already run, or on ours if you do not have one. The platform operationalises the evidence the practitioner designs. It does not replace the judgement.

Alfred Obeng, founder and senior practitioner at Goldline Consultancy
The practitioner

Alfred Obeng

Founder and senior practitioner. Integrated engagements are delivered by the practitioner who scopes them, from the diagnostic call through to the certification audit.

  • ISO 42001 Lead Implementer and Lead Auditor (PECB)
  • ISO 27001 Senior Lead Implementer and Lead Auditor (PECB)
  • CISSP
  • PMP
Frequently asked

Questions before discovery.

Because the backbone is built once and the cross-mapped controls are evidenced once. Scope, interested parties, risk methodology, objectives, document control, competence, the internal audit programme and the management review serve both standards. Buying the two programmes separately costs about 20 per cent more at every tier.

Readiness checklist

Whether this is the right programme.

AI systems in production or active development

Your product or operations embed AI in customer-facing or decisioning workflows. The AIMS scopes around those systems, so somebody has to be able to describe what each model decides and where a human signs off.

Both certificates actually required

Buyers, investors or a regulator are asking for information security certification and AI governance certification. If only one is being asked for, the single-standard programmes are the cheaper answer.

A named internal owner with authority

One person accountable for the management system, with access to leadership and to the teams that build and run the models.

Leadership available for the management review

Both standards require top management to review the system. That meeting cannot be delegated to the compliance function.

One management system, two certificates.

Fixed scope. Timeline calibrated at scoping. Investment shared at qualified discovery.

Book a Free Diagnostic

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.