About Accreditations ISO 27001
What ISO 27001 means for AI systems.
Access, suppliers, residency and incident handling are settled by the management system before a project starts.
What changes when an AI project touches your data.
Most AI work starts with somebody asking where the data goes, and the honest answer often arrives late, after a tool has already been chosen. Certification puts that answer first: the management system governs how client data is classified, who can access it, where it may be stored and how incidents are handled. Those decisions apply to everything we build for you.
The questions your security review will ask.
Each one maps to a control the certificate is audited against, so the answer does not change from project to project.
Who can reach our data?
Access is granted per engagement. Credentials are never carried over from a previous project.
What happens if you use a model you do not control?
A model provider is a supplier, so it goes through the same assessment as any other supplier before anything of yours reaches it. Where that assessment does not pass, the work runs inside an environment you control instead.
Where will the data physically sit?
Data residency is agreed at the outset and built into the design; never left to the service that happens to be convenient mid-build.
What do you do when something goes wrong?
There is a documented incident procedure with named responsibilities and defined reporting routes, and we tell you in writing what happened and when.
How does this sit with UK GDPR?
We operate in compliance with UK GDPR and the Data Protection Act 2018. What we show you is where your data lives, who can reach it and how erasure works. You stay the controller.
What the certificate does not do.
ISO 27001 certifies our management system: our controls are designed to the standard and independently assessed by an external body. It says nothing about how a particular model behaves, and it does not move your obligations as the data controller onto us. What it gives you is a way to check the controls, and a person who is accountable for them.
Where this has already been tested.
Audited while the build was live.
Rubrical, built with the Department for Education, ran on a private stack in a UK Azure tenant, has a DfE-approved data protection impact assessment, and closed its ISO 27001 audit during the pilot.
Read the Rubrical caseCheck it yourself.
Every accreditation below is listed on a public register and can be verified independently.
- Standard
- ISO/IEC 27001:2022
- Certificate number
- 24112
- Certifying body
- Alcumus ISOQAR
- Accreditation
- UKAS
- First certified
- November 2024
Enter certificate number 24112 in the Alcumus ISOQAR certificate checker to confirm the certificate is current. Scope statements and renewal dates go to your compliance team on request, along with the certifying body’s own record.
Where this connects.
Every mark we hold
ISO 27001, ISO 9001 and Cyber Essentials are certifications we hold. We operate in compliance with UK GDPR, and we design toward the EU AI Act. The register says which is which.
See the accreditations registerThe quality management side
ISO 9001:2015 sits under the same certificate number and covers how work is scoped, reviewed, tested and handed over.
What ISO 9001 coversAI governance and compliance
The service where these controls become your own policy, from classifying use-case risk to writing the charter your team works to.
Explore AI governance