ISO 27001 and ISO 42001 built as one management system, certified as two.
For regulated UK organisations and AI-enabled UK scaleups being asked for information security certification and AI governance certification at the same time. Founder-led delivery. Fixed scope. The sequence is fixed. Your timeline is set at the free diagnostic. Investment shared at qualified discovery. The certification decision rests with your certification body.
Delivered by
45 minute call. No sales pitch. Senior practitioner-led discovery.
Loading the calendar
Open the booking pageCalendar not loading? Open Calendly directly
The two questions arrive together.
Buyers ask both questions in one questionnaire
Enterprise questionnaires increasingly include AI governance questions alongside the standard ISO 27001 and SOC 2 controls. Answering one and deferring the other holds the deal in review.
EU AI Act obligations are dated
Article 50 transparency obligations apply from 2 August 2026 and Annex III high-risk obligations from 2 December 2027. An AI management system is the structure that carries the evidence.
Two programmes duplicate the same backbone
Scope, risk methodology, objectives, document control, internal audit and management review are written once for both standards, or written twice at twice the cost.
Two programmes, or one built properly.
Two separate engagements
- Two separate engagements, two scoping exercises, two document sets
- Controls evidenced twice because nobody cross-maps them
- Two internal audit programmes and two management reviews
- Consultant fluent in one standard and reading up on the other
- Overlap discovered late, after the duplicate work is already paid for
Integrated Sprint
- One scoping exercise producing one management system with two control sets
- Cross-mapped controls identified once and evidenced once
- One internal audit programme and one management review covering both
- Lead Implementer and Lead Auditor credentials in both standards
- The overlap priced into the engagement from the first day
The cross-mapping is the product.
The cross-mapping is the product
ISO 27001 Annex A controls that also carry AIMS evidence are identified once and evidenced once. That is why the integrated route costs materially less than two programmes, and doing it requires practitioner judgement in both frameworks rather than two consultants working in parallel.
Credentials in both standards, held by one practitioner
Alfred Obeng holds the PECB ISO 42001 Lead Implementer and Lead Auditor credentials and the PECB ISO 27001 Senior Lead Implementer and Lead Auditor credentials. The mapping decisions are taken by somebody who has audited against both.
One management system, operated as one
One risk methodology, one document control regime, one competence and awareness programme, one internal audit programme, one management review. After handover you run a single operating calendar, not two.
Founder-led senior delivery
No subcontracted hours, no associate handoff. The practitioner who scopes the engagement is the practitioner who delivers it.
Four phases across both standards.
Phases are sequenced, not timed. Fixed scope. Timeline calibrated at scoping.
Phase 01: Define · One scope, two standards
What blocks organisations here
Scope is drawn twice and the two drafts disagree. AI systems have never been formally inventoried, so the AIMS boundary has nothing solid to sit against.
What happens in this phase
One scope covering both management systems. Interested parties documented once. AI system inventory built with risk classification. One risk methodology serving information security risk and AI risk. Both policy frameworks drafted. Governance accountability named.
Deliverables
- One scope and boundary covering the ISMS and the AIMS
- Interested parties and their requirements, documented once
- AI system inventory with risk classification
- One risk methodology, security risk and AI risk
- Both policy frameworks, approved by top management
- Governance accountability, named individuals against named decisions
What you hold at the end.
One integrated management system
Scope, interested parties, risk methodology, objectives, document control, competence and awareness, internal audit programme and management review, written once to serve both standards.
Two Statements of Applicability
93 ISO 27001 Annex A controls and 38 ISO 42001 Annex A controls, with the cross-mapped controls identified so the same evidence answers both.
The AI-specific layer
AI system inventory and risk classification, AI impact assessment, data governance for training and inference data, explainability records, human oversight procedures.
Evidence packs for both scopes
Assembled against both Statements of Applicability, structured the way an auditor reads them rather than the way a folder tree grows.
Not included: the clause 9.2 internal audit. Where Goldline has built your management system, the internal audit must be run independently and cannot be run by us. We tell you exactly what it has to cover. Budget separately for it. Certification body fees are paid to the body direct, are separate from the Goldline fee and carry no Goldline margin. Goldline is not a certification body and does not issue certificates, in any tense, and will not sell implementation and certification to the same organisation for the same scope.
Fixed scope. Investment shared at qualified discovery.
Tier is set on the diagnostic. Buying the two programmes separately costs about 20 per cent more at every tier.
Tier 1
Single entity, contained AI estate, an information security foundation already in place or in active implementation.
Tier 2
Multiple products or business units, a wider AI estate, or an information security posture being built from a standing start.
Tier 3
Group structures, multiple certification scopes, regulated sectors, or an AI estate that needs classification work before scope can close.
Delivered on your GRC platform of choice, or ours.
Cross-mapped controls, both Statements of Applicability and the evidence trail are configured on the platform you already run, or on ours if you do not have one. The platform operationalises the evidence the practitioner designs. It does not replace the judgement.

Alfred Obeng
Founder and senior practitioner. Integrated engagements are delivered by the practitioner who scopes them, from the diagnostic call through to the certification audit.
- ISO 42001 Lead Implementer and Lead Auditor (PECB)
- ISO 27001 Senior Lead Implementer and Lead Auditor (PECB)
- CISSP
- PMP
Questions before discovery.
Because the backbone is built once and the cross-mapped controls are evidenced once. Scope, interested parties, risk methodology, objectives, document control, competence, the internal audit programme and the management review serve both standards. Buying the two programmes separately costs about 20 per cent more at every tier.
Whether this is the right programme.
AI systems in production or active development
Your product or operations embed AI in customer-facing or decisioning workflows. The AIMS scopes around those systems, so somebody has to be able to describe what each model decides and where a human signs off.
Both certificates actually required
Buyers, investors or a regulator are asking for information security certification and AI governance certification. If only one is being asked for, the single-standard programmes are the cheaper answer.
A named internal owner with authority
One person accountable for the management system, with access to leadership and to the teams that build and run the models.
Leadership available for the management review
Both standards require top management to review the system. That meeting cannot be delegated to the compliance function.
If this is not the right size.
Integrated Guided
Single entity, roughly fifty people or fewer, one to five AI systems and a named owner with the hours. The same integrated build, directed by us and executed by your team, fixed at £12,500 + VAT.
Read more →ISO 27001 alone
If only information security certification is being asked for, ISO 27001 Guided at £7,000 + VAT or the ISO 27001 Sprint is the proportionate route.
Read more →ISO 42001 alone
If the information security posture is already certified, the ISO 42001 Sprint or ISO 42001 Guided at £9,000 + VAT adds the AI management system on top of it.
Read more →One management system, two certificates.
Fixed scope. Timeline calibrated at scoping. Investment shared at qualified discovery.
Book a Free Diagnostic