Skip to content

About Accreditations ISO 27001

What ISO 27001 means for AI systems.

Access, suppliers, residency and incident handling are settled by the management system before a project starts.

What changes when an AI project touches your data.

Most AI work starts with somebody asking where the data goes, and the honest answer often arrives late, after a tool has already been chosen. Certification puts that answer first: the management system governs how client data is classified, who can access it, where it may be stored and how incidents are handled. Those decisions apply to everything we build for you.

The questions your security review will ask.

Each one maps to a control the certificate is audited against, so the answer does not change from project to project.

Who can reach our data?

Access is granted per engagement. Credentials are never carried over from a previous project.

What happens if you use a model you do not control?

A model provider is a supplier, so it goes through the same assessment as any other supplier before anything of yours reaches it. Where that assessment does not pass, the work runs inside an environment you control instead.

Where will the data physically sit?

Data residency is agreed at the outset and built into the design; never left to the service that happens to be convenient mid-build.

What do you do when something goes wrong?

There is a documented incident procedure with named responsibilities and defined reporting routes, and we tell you in writing what happened and when.

How does this sit with UK GDPR?

We operate in compliance with UK GDPR and the Data Protection Act 2018. What we show you is where your data lives, who can reach it and how erasure works. You stay the controller.

What the certificate does not do.

ISO 27001 certifies our management system: our controls are designed to the standard and independently assessed by an external body. It says nothing about how a particular model behaves, and it does not move your obligations as the data controller onto us. What it gives you is a way to check the controls, and a person who is accountable for them.

Where this has already been tested.

Audited while the build was live.

Rubrical, built with the Department for Education, ran on a private stack in a UK Azure tenant, has a DfE-approved data protection impact assessment, and closed its ISO 27001 audit during the pilot.

Read the Rubrical case

Check it yourself.

Every accreditation below is listed on a public register and can be verified independently.

ISO 27001 ISOQAR registered mark beside the UKAS Management Systems mark, accreditation number 0026.
Standard
ISO/IEC 27001:2022
Certificate number
24112
Certifying body
Alcumus ISOQAR
Accreditation
UKAS
First certified
November 2024

Enter certificate number 24112 in the Alcumus ISOQAR certificate checker to confirm the certificate is current. Scope statements and renewal dates go to your compliance team on request, along with the certifying body’s own record.

Where this connects.

Send the questions your due diligence asks.

Point us at the clause your process needs answered and we will tell you what the certificate covers and who signs for it. We reply within one working day.