About Accreditations ISO 27001
What ISO 27001 means for AI systems.
The management system settles access, suppliers, residency and incident handling before a project starts.
What changes when an AI project touches your data.
Most AI work starts with somebody asking where the data goes, and the honest answer often arrives late, after a tool has already been chosen. Certification puts that answer first: the management system governs how client data is classified, who can access it, where it may be stored and how incidents are handled. Those decisions apply to everything we build for you.
The questions your security review will ask.
Each one maps to a control the certificate is audited against, so the answer does not change from project to project.
Who can reach our data?
We grant access per engagement, and we never carry credentials over from a previous project.
What happens if you use a model you do not control?
A model provider is a supplier, so it goes through the same assessment as any other supplier before anything of yours reaches it. Where that assessment does not pass, the work runs inside an environment you control instead.
Where will the data physically sit?
We agree data residency at the outset and build it into the design. We never leave it to whichever service happens to be convenient mid-build.
What do you do when something goes wrong?
We work to a documented incident procedure with named responsibilities and defined reporting routes, and we tell you in writing what happened and when.
How does this sit with UK GDPR?
We operate in compliance with UK GDPR and the Data Protection Act 2018. We show you where your data lives, who can reach it and how erasure works. You stay the controller.
What the certificate does not do.
ISO 27001 certifies our management system: our controls are designed to the standard and independently assessed by an external body. It says nothing about how a particular model behaves, and it does not move your obligations as the data controller onto us. It gives you a way to check the controls, and a person who is accountable for them.
Where this has already been tested.
Audited while the build was live.
We built Rubrical with the Department for Education, and it closed its ISO 27001 audit during the pilot. It runs on a private stack in a UK Azure tenant, under a data protection impact assessment the DfE approved.
Read the Rubrical caseCheck it yourself.
Your compliance team can check all of this on a public register without us.
- Standard
- ISO/IEC 27001:2022
- Certificate number
- 24112
- Certifying body
- Alcumus ISOQAR
- Accreditation
- UKAS
- First certified
- November 2024
Enter certificate number 24112 in the Alcumus ISOQAR certificate checker to confirm the certificate is current. Scope statements and renewal dates go to your compliance team on request, along with the certifying body’s own record.
Where this connects.
Every mark we hold
ISO 27001, ISO 9001 and Cyber Essentials are certifications we hold. We operate in compliance with UK GDPR, and we design toward the EU AI Act. The register says which is which.
See the accreditations registerThe quality management side
ISO 9001:2015 sits under the same certificate number and covers how work is scoped, reviewed, tested and handed over.
What ISO 9001 coversAI governance and compliance
The service where these controls become your own policy: we classify use-case risk and write the charter your team works to.
Explore AI governance