• About Us
  • Contact

ISO 42001 and the Real Cost of Ungoverned AI 

Published: 14th August 2026

This piece draws on insight from Peter Wells, Head of Consultancy at Risk Crew, who has advised on numerous AI risk assessments and ISO 42001 readiness projects for UK organisations. For a deeper discussion of these themes, listen to the full conversation between Tom Exelby and Peter Wells on Red Helix Cyber in Focus, and get in touch with Risk Crew for support with AI risk assessments or ISO 42001 preparation. 

Most businesses have less visibility over their AI use than they think. Copilot gets rolled out because it comes bundled with Microsoft 365, yet a large share of staff barely touches it. Meanwhile marketing has quietly adopted Claude, someone in finance has ChatGPT open in another tab, and a handful of people are logging into a personal Gemini account on a work device because nobody told them not to. 

This is shadow AI, and it has become the defining risk of this stage of AI adoption. It isn’t really about people doing something wrong, it’s about organisations that haven’t yet drawn a line between sanctioned and unsanctioned use and so have no way of knowing where their data ends up once someone pastes it into a prompt. 

That gap is exactly what ISO 42001, the new international standard for AI Management Systems, is designed to close. 

Why Visibility Comes Before Governance

Before any business can talk seriously about governing AI, it needs to know what’s being used. That sounds obvious, but in practice it’s the step most organisations skip. Security teams can list the software on the corporate network. Far fewer can say with confidence which AI tools their staff are relying on day to day, what they’re being used for, or where the data involved is going. 

Once information is entered into an LLM, the question stops being abstract. Is it staying within the region a business is obligated to keep it in. Is it moving to infrastructure hosted elsewhere. Could the organisation answer that question if a regulator asked. For most businesses right now, the honest answer is no. 

Regulation Hasn’t Caught Up, But GDPR Still Applies

There’s a common assumption that because AI itself isn’t heavily regulated in the UK, organisations have a free pass to move quickly and sort out the governance later. That assumption doesn’t hold up. The EU AI Act applies to any business trading into Europe, and UK bodies including the National Cyber Security Centre and the Department for Science, Innovation and Technology have both published guidance aimed at closing the gap. None of it carries the same weight as GDPR, though, and that’s where organisations are most exposed. 

Feeding personal data into an AI tool constitutes processing, in the legal sense, regardless of whether a business set out to think of it that way. If the ICO asks to see an organisation’s Record of Processing Activities, “we hadn’t considered it” is not a workable answer. It’s a pattern that shows up repeatedly in risk assessments: a business treats its AI use as low risk because it wasn’t formally sanctioned, then finds it can’t demonstrate where personal data went once it left its own systems. 

What ISO 42001 Requires

Strip away the certification and the audit process, and ISO 42001 asks two things of a business: maintain a clear picture of what AI is in use and manage the risk that comes with it properly.

In practice, that means two core components. The first is an asset inventory, a live, maintained record of every AI tool in use across the organisation and who is using it, whether the business sits on the provider or consumer side of AI, or both. The second is a genuine risk management process that covers inaccurate or hallucinated outputs, data exposure, and how updates to AI tools are tested before they reach staff.

Organisations that have already been through ISO 27001 will recognise the shape of it. The mandatory controls around scoping and management buy-in are largely the same, with the annex controls pointed at AI rather than general information security, and the certification itself follows the same two-stage audit process.

Whether formal certification makes sense depends on the business. It’s increasingly showing up as a contractual requirement, with organisations that are already ISO 27001 certified being asked by their own clients why they haven’t taken the next step to 42001. For businesses not under that kind of pressure, there are cheaper routes that still cover most of the same ground: the NCSC’s Guidelines for Secure AI System Development, the ICO’s guidance on AI and data protection, and the NIST AI Risk Management Framework are all free, and each offers a genuinely useful starting point without the cost of formal certification. 

The Cost Risk Nobody Budgets For

AI governance conversations tend to focus on data and compliance, but cost deserves equal attention. AI providers have shown they can change the terms of a deal without warning. One recent example saw a provider hold its published pricing steady while quietly halving the compute delivered for that price, effectively doubling the real cost overnight for anyone relying on it. A marketing or design team that has built a workflow around a tool like that, with no budget oversight in place, absorbs that shock with zero notice. 

The same lack of visibility shows up from the other direction too. It’s not unusual for a business to have paid for a full set of Copilot licences only to discover that fewer than a third of staff are using them, with everyone else having drifted to Claude or ChatGPT instead. Visibility isn’t only a compliance issue. It’s also a question of whether the business is spending its money in the right place. 

Where to Start

For a UK SMB that isn’t ready to commit to full ISO 42001 certification, the starting point doesn’t need to be complicated. Talk to people. Find out what tools staff are using, what for, and where the data goes. Build an asset inventory from that conversation, then apply guidance from the free frameworks already available. 

It’s worth being cautious about over-restricting AI use in response. Lock it down too hard with technical controls and no explanation, and staff will simply find a way around it. A more durable approach combines sensible guardrails with an honest conversation about what’s expected, backed by clear ownership at senior level so the issue doesn’t drift unclaimed between IT, security and whichever department happens to raise it first. 

The Bottom Line

AI adoption isn’t slowing down, and waiting for regulation to catch up isn’t a strategy. Whether or not formal ISO 42001 certification is the right move for a given business right now, the underlying discipline it demands, knowing what AI is in use, understanding the risk, and having someone accountable for it, is worth building regardless.