Compliance guides

Practical, plain-English guides to every standard ISO-STANDARD.app supports. Written by practitioners, free to read, no email gate.

Pillar guides

Thought leadership
ISO standards

ISO 27001 certification cost (2026)

A transparent, line-by-line breakdown of what ISO 27001 really costs a UK/EU SME — registrar fees, internal effort, consultancy and tooling.

12 min read
AI governance

EU AI Act compliance guide for SMEs

Risk tiers, obligations, timelines and the documentation auditors will ask for — with Harvard-referenced sources throughout.

16 min read
AI governance

AI adoption: a risk-based approach

A practitioner's frame for adopting AI by inventory, classification, treatment and monitoring — not by accident.

16 min read
AI governance

The AI-assisted human

Michael McCarroll's sociotechnical model of person-plus-AI as the real unit of governance — drawing on Tavistock and actor-network theory.

18 min read
AI governance

AI adoption in resource-constrained organisations

The staged pattern that produced ROI in twelve weeks inside a UK housing association — governance and workforce first, tooling last.

16 min read
Risk management

The State of Risk Management in 2026

Why the spreadsheet era is finally ending — a four-stage maturity model, where most organisations actually sit, and what good looks like next.

14 min read
ISO standards

Internal audit, CAPA and management review

How ISO clauses 9.2, 10.1/10.2 and 9.3 form a single loop — and how to run it without the spreadsheet stack that fails at surveillance.

15 min read
Trust & business

Trust as competitive advantage

Why trust — evidenced, not asserted — is the fastest-compounding B2B moat, and how to operationalise it.

18 min read
Trust & business

The long-term trust flywheel

Trust is not a campaign. Chained into a rhythm, artefacts become a flywheel that compounds into dominant advantage.

17 min read
New series

AI governance & risk — 11 new articles

Showing 132 of 132 guides.

ISO 27001 certification cost (2026)

A transparent, line-by-line breakdown of what ISO 27001 really costs a UK/EU SME — registrar fees, internal effort, consultancy and tooling.

ISO standardsSoftware & tooling

EU AI Act compliance guide for SMEs

Risk tiers, obligations, timelines and the documentation auditors will ask for — with Harvard-referenced sources throughout.

AI governanceComparisons

NIS2 Directive compliance guide

How Directive (EU) 2022/2555 changes cyber obligations for essential and important entities — scope, controls, reporting and penalties.

CybersecurityRisk management

DORA compliance guide for financial entities

ICT risk management, incident reporting, third-party oversight and resilience testing under the Digital Operational Resilience Act.

CybersecurityRisk management

ISO 27001 vs SOC 2: which to pick

An evidence-based comparison — scope, audit model, cost, buyer expectations and how to run both without doubling the work.

ComparisonsISO standardsSOC & attestations

AI adoption: a risk-based approach

A practitioner's frame for adopting AI by inventory, classification, treatment and monitoring — not by accident.

AI governanceRisk management

The AI-assisted human

Michael McCarroll's sociotechnical model of person-plus-AI as the real unit of governance — drawing on Tavistock and actor-network theory.

AI governance

Ongoing management of AI systems

Drift, evaluation, change control and the weekly/monthly/quarterly rhythm that keeps AI in production safe.

AI governanceRisk management

Supplier management for AI

The four-layer AI supply chain, an AI-specific due diligence addendum and the contract clauses that matter.

AI governanceRisk management

Decommissioning AI tools

Retiring an AI tool safely — data, embeddings, downstream consumers, credentials and the records you'll need years later.

AI governanceRisk management

Cross-border AI risk

Why a single AI call can cross three jurisdictions in a second, and how to govern the resulting transfer risk.

AI governancePrivacy & data protection

Preventing inadvertent AI data disclosure

Paste-and-prompt is the dominant leak pattern. A layered control set — technical, contractual and cultural — that actually works.

AI governancePrivacy & data protectionCybersecurity

AI on the board agenda

Five questions, three artefacts and the difference between meaningful oversight and oversight theatre.

AI governanceRisk management

Shadow AI: finding the tools your people already use

Discovery, classification and the provision-and-onboard response that beats the block-and-police one.

AI governanceCybersecurity

AI incident response

Hallucination, leakage, bias, prompt injection and supplier-side change — and the four-stage playbook that adapts what you already have.

AI governanceCybersecurity

People, skills and change in AI adoption

Why the human side determines AI risk, and the literacy programme the EU AI Act now requires.

AI governance

AI adoption in resource-constrained organisations

The staged pattern that produced ROI in twelve weeks inside a UK housing association — governance and workforce first, tooling last.

AI governanceRisk management

Action research for AI programmes

Plan, act, observe, reflect — the disciplined method that turns AI change into evidence you can defend to a board or an auditor.

AI governance

The economic Turing test

When hiring managers consistently prefer the machine — the workforce and governance implications for knowledge work.

AI governance

From Copilot pilot to agentic AI

The five gates that separate a safe agent programme from a headline incident, and the staged pattern that has produced evidence in practice.

AI governanceRisk management

The State of Risk Management in 2026

Why the spreadsheet era is finally ending — a four-stage maturity model, where most organisations actually sit, and what good looks like next.

Risk management

Internal audit, CAPA and management review

How ISO clauses 9.2, 10.1/10.2 and 9.3 form a single loop — and how to run it without the spreadsheet stack that fails at surveillance.

ISO standardsRisk management

The ISO 42001 AI risk management playbook

An AI-specific threat taxonomy, how to score AI risks when likelihood is unknowable, and how AIMS fits with ISO 27001 and the EU AI Act.

AI governanceISO standardsRisk management

Modern information security risk management

Beyond the annual spreadsheet refresh — continuous risk, KRIs and KCIs, and why control-centric compliance suites miss the risk layer.

Risk managementCybersecurity

ISO 27001 vs SOC 2

Scope, audit process, costs and how to choose between the two most common infosec assurance programmes.

ComparisonsISO standardsSOC & attestations

ISO 42001 vs NIST AI RMF

Certifiable AI management system vs voluntary risk framework — what each covers, how they differ, and how to run them together.

ComparisonsAI governanceISO standards

Enterprise risk management software

What ERM software actually does and how to evaluate a platform without a six-week procurement cycle.

Software & toolingRisk management

Risk management software & platforms

A practical buyer's guide to risk management software, methodology and the features that matter.

Software & toolingRisk management

ISO 27001 risk assessment methodology

The 5×5 likelihood × impact model, scoring tables and treatment workflow.

ISO standardsRisk management

ISO 27001 risk treatment plan

The four Ts — Treat, Transfer, Tolerate, Terminate — and mapping risks to Annex A.

ISO standardsRisk management

ISO 27001 third-party risk assessment

How to evaluate vendor risk, manage supply-chain security and record supplier risks in the register.

ISO standardsRisk managementCybersecurity

ISO 31000 risk management framework

Principles, framework and process for enterprise risk — without GRC bloat.

ISO standardsRisk management

Risk management frameworks comparison

Compare ISO 31000, NIST SP 800-30, COSO ERM and COBIT to choose the right framework for your organisation.

Risk managementComparisons

ISO 9001 quality management system

Risk-based thinking, the PDCA cycle and the documents auditors actually ask for.

ISO standards

ISO 42001 AI management system

The first international AI management standard, mapped to the EU AI Act.

ISO standardsAI governance

ISO 42001 certification readiness for AI startups

The 12–16 week path AI startups take to certify — and how it accelerates enterprise deals.

ISO standardsAI governance

ISO 20000-1 IT service management

How the SMS differs from ITIL and what an accredited audit actually tests.

ISO standards

SOC 2 compliance

Trust Services Criteria, Type I vs Type II and a 90-day path to readiness.

SOC & attestationsCybersecurity

GDPR compliance checklist

Lawful bases, data subject rights, DPIAs, breach notification and ROPAs.

Privacy & data protection

PCI DSS compliance

v4.0, the right SAQ, the 12 requirements and scope-reduction moves.

Cybersecurity

Cyber Essentials certification

The five technical controls and the two-week path to certification.

Cybersecurity

Cyber Essentials Plus

What the audit actually tests and how to pass first time.

Cybersecurity

Trust as competitive advantage

Why trust — evidenced, not asserted — is the fastest-compounding B2B moat, and how to operationalise it.

Trust & businessRisk management

Building buyer trust in procurement

How modern procurement really evaluates trust and how to put your firm inside the shortlist before the RFP is issued.

Trust & business

Trust signals that actually work

A practitioner's ranking of the badges, testimonials, artefacts and behaviours that measurably shift decisions.

Trust & business

Radical transparency as a growth strategy

Why publishing incidents, prices and mistakes wins share from competitors who still hide them.

Trust & business

Rebuilding trust after a breach

The disclosure, evidence and remediation playbook that turns incidents into commercial recovery.

Trust & businessCybersecurity

Building customer trust in the age of AI

The new buyer questions on data handling, model choice and human oversight — and how to publish credible answers.

Trust & businessAI governance

From claims to evidence

Convert every trust claim into a downloadable artefact — the biggest win-rate lever most B2B firms haven't pulled.

Trust & business

Compliance as trust currency

How compliance done well unlocks enterprise deals, faster procurement, better pricing and higher renewals.

Trust & businessRisk management

Trust in remote-first teams

The operating patterns and rituals that hold distributed organisations together — and make trust visible to buyers.

Trust & business

Earning vendor trust through third-party risk transparency

Your customers inherit every risk from your suppliers — how to build a programme that reassures buyers as much as it protects you.

Trust & businessRisk management

Brand trust and security

How marketing and security teams can compound each other into a durable commercial advantage.

Trust & business

How SMEs win enterprise trust

The plays small firms use to convert size from a disadvantage into a differentiator in enterprise procurement.

Trust & business

Measuring trust: metrics that matter to boards

The KPIs that turn trust into a boardroom conversation and connect security, sales and product.

Trust & businessRisk management

Founder credibility and the trust premium

In evidence-driven markets, founder credibility is often the deciding trust asset. How to build and deploy it.

Trust & business

The long-term trust flywheel

Trust is not a campaign. Chained into a rhythm, artefacts become a flywheel that compounds into dominant advantage.

Trust & business

Writing an ISO 27001 Statement of Applicability that buyers respect

Learn how to transform your ISO 27001 Statement of Applicability from a compliance tick-box into a high-stakes sales tool that wins enterprise trust.

ISO standards

Building an ISO 27001 internal audit programme that finds real issues

Stop treating internal audits as a checkbox exercise. Learn how to build a rigorous ISO 27001 audit programme that surfaces risk and strengthens your security posture.

ISO standards

The ISO 27001 management review agenda that unlocks board sponsorship

Stop treating the ISO 27001 Management Review as a checkbox exercise. Learn how to structure your agenda to secure budget, visibility, and genuine board-level commitment.

ISO standards

Defining ISO 27001 scope: the decision that determines audit cost

Defining your ISO 27001 scope is the single most important decision in your certification journey. Learn how to map boundaries that satisfy auditors without inflating costs.

ISO standards

ISO 27001 continual improvement: turning findings into value

Stop treating ISO 27001 non-conformities as failures. Learn how to transform audit findings into a high-performance security engine that drives revenue and operational resilience.

ISO standards

ISO 9001 context of the organization: the clause most SMEs get wrong

Clause 4 isn't just paperwork; it's the foundation of your QMS. Stop treating 'Context' as a tick-box exercise and start using it to drive genuine business strategy.

ISO standards

The ISO 9001 process approach — beyond the flowchart

Stop treating ISO 9001 processes like static diagrams. Michael McCarroll explains how to build a dynamic, performance-led system that scales with your business.

ISO standards

Measuring customer satisfaction for ISO 9001 (that actually informs strategy)

Stop treating ISO 9001 customer satisfaction as a vanity metric. Learn how to transform Clause 9.1.2 into a strategic engine for retention and growth.

ISO standards

ISO 9001 nonconformity and corrective action done well

Ditch the administrative box-ticking. Learn how to transform ISO 9001 nonconformity management into a genuine competitive advantage that drives operational excellence.

ISO standards

An ISO 42001 AI policy that boards and buyers both approve

Ditch the generic AI ethics statements. Learn how to draft a pragmatic ISO 42001 policy that satisfies rigorous board oversight and complex enterprise procurement demands.

AI governance

AI impact assessments under ISO 42001: a working template

Master the Artificial Intelligence Impact Assessment (AIIA) under ISO 42001 with a practical, evidence-based framework for senior GRC practitioners and founders.

AI governance

ISO 42001 vs the EU AI Act: mapping controls to obligations

A practical guide for security leaders to align ISO 42001 certification and EU AI Act compliance, avoiding redundant effort and ensuring market access.

AI governance

Model lifecycle governance under ISO 42001

Mastering the AI model lifecycle is the core of ISO 42001. Learn how to govern AI development from data sourcing to decommissioning without stifling innovation.

AI governance

Building a service catalogue that satisfies ISO 20000-1 and customers

Master ISO 20000-1 service catalogues: move beyond simple lists to technical and business views that satisfy auditors and drive commercial value.

ISO standards

ISO 20000-1 change management without ticket sprawl

Modern change control in ISO 20000-1 doesn't require bureaucratic bloat; it requires smart automation and risk-based decision making to maintain service excellence.

ISO standards

ISO 22301 business continuity: a plain-English implementation guide

Stop treating business continuity as a paper exercise. Learn how to implement ISO 22301 using a practical, impact-first approach that protects your reputation and revenue.

ISO standards

ISO 22301 tabletop exercises that actually build resilience

Move beyond tick-box compliance with high-impact ISO 22301 tabletop exercises that stress-test your business continuity plans and prove resilience to stakeholders.

ISO standards

ISO 27701: adding a privacy layer to your ISMS

Ditch the confusion between GDPR and ISO 27001. ISO 27701 provides the missing structural link to turn privacy from a legal headache into a scalable operational asset.

Privacy & data protection

ISO 27701 for controllers and processors: what changes

Stop treating privacy as a sidecar to security. ISO 27701 extends ISO 27001 by forcing specific accountabilities on controllers and processors to bridge the gap to GDPR.

Privacy & data protection

A 90-day SOC 2 readiness plan that survives contact with the auditor

Stop treating SOC 2 as a tick-box exercise. This 90-day readiness plan focuses on operational reality, ensuring your controls actually work when the auditor arrives.

SOC & attestations

SOC 2 common criteria explained without the jargon

A practical guide for founders and security leads on decoding the SOC 2 Common Criteria to build a defensible, audit-ready security posture without the technical fluff.

SOC & attestations

SOC 2 evidence collection: from screenshots to continuous assurance

Stop the screenshot madness. Move from manual SOC 2 evidence gathering to a continuous assurance model that scales with your engineering team and builds real buyer trust.

SOC & attestations

GDPR data mapping and ROPA: the artefact that unblocks enterprise deals

Stop treating the Record of Processing Activities (ROPA) as a compliance chore. It is the single most important document for clearing enterprise vendor security assessments.

Privacy & data protection

GDPR DPIAs in practice: a template you will actually use

Cut through the bureaucratic fog of GDPR Data Protection Impact Assessments with a pragmatic, risk-based approach designed for fast-moving product teams.

Privacy & data protection

GDPR international data transfers after Schrems II

Navigating the complexities of international data transfers post-Schrems II requires more than just signing a contract; it demands rigorous impact assessments and monitoring.

Privacy & data protection

Cyber Essentials: the five failure points that cost first-time applicants

Avoid the common pitfalls that lead to Cyber Essentials failure. Learm how to master the five key technical controls and secure your certification on the first attempt.

Cybersecurity

What to expect on Cyber Essentials Plus audit day

Forget the marketing jargon; here is the blunt reality of what happens when a Cyber Essentials Plus assessor audits your infrastructure and how to pass without breaking a sweat.

Cybersecurity

PCI DSS 4.0 transition: the changes that matter to SMEs

Forget the 360-page PDF; the transition to PCI DSS 4.0 is about shifting from 'point-in-time' compliance to continuous evidence. Here is how SMEs survive the March 2025 deadline.

Cybersecurity

PCI DSS scope reduction: proven moves to shrink the audit

Stop treating your entire network like a cash register. Learn how to aggressively descoped your PCI DSS environment to reduce audit costs and security risks.

Cybersecurity

The honest buyer's guide to GRC tools in 2026

An uncompromising guide to navigating the 2026 GRC software landscape, focusing on evidence over automation and trust over compliance badges.

Software & tooling

The first 90 days of a GRC programme: what to build, defer and kill

Stop treating GRC as a paperwork exercise. Learn how to architect a risk-first programme in 90 days that actually protects the business and closes deals.

Risk management

Policy management lifecycle: from draft to attested to retired

Stop treating policies as static PDF documents. Learn to manage the full GRC lifecycle to ensure your controls remain auditable, enforceable, and actually useful.

Risk management

Control testing that doesn't waste anyone's time

Stop treats control testing as a box-ticking chore. Learn how to build a lean, evidence-first testing programme that satisfies ISO 27001 auditors without burning out your team.

Risk management

Building a third-party risk management programme buyers trust

Stop wasting time on security questionnaires. Build a defensible Third-Party Risk Management (TPRM) programme that proves your maturity to enterprise buyers.

Risk management

The security questionnaire response playbook that halves turnaround

Stop wasting engineering time on repeat security queries. Learn how a structured ISO 27001-aligned knowledge base cuts response times by 50% and accelerates your deal cycle.

Trust & business

Quantitative risk analysis for SMEs: FAIR without the PhD

Ditch the 'High-Medium-Low' guesswork. Learn how to apply formal quantitative risk analysis to your SME using a simplified FAIR framework that board members actually value.

Risk management

Key risk indicators that boards actually use

Stop reporting 'missing patches' to the board. Learn how to build Key Risk Indicators (KRIs) that link security posture to commercial stability and board-level decision-making.

Risk management

Risk appetite statements that survive the next crisis

Stop treating risk appetite as a compliance tick-box. Learn how to craft quantitative, resilient statements that drive growth while keeping your ISO 27001 posture intact.

Risk management

Operational resilience beyond business continuity plans

Ditch the dust-gathering BCP. Learn why true operational resilience requires a shift from 'recovery' to 'continuity' through evidence-based risk management and ISO 22301 principles.

Risk management

Scenario planning for trust-eroding events

Stop waiting for the breach. Learn how to use proactive scenario planning to defend your brand’s reputation and satisfy ISO 27001:2022 risk requirements.

Risk management

Designing a trust centre that closes deals

Learn how to transform your security posture from a cost centre into a sales engine by building a high-performance Trust Centre that accelerates procurement.

Trust & business

Public status pages: turning outages into trust deposits

Stop hiding your outages. A well-managed public status page is a sophisticated GRC tool that converts system downtime into measurable market credibility and customer retention.

Trust & business

Proof-driven marketing: replacing adjectives with artefacts

Stop telling customers you are secure. Start proving it. Learn how to transform your GRC artefacts into your most powerful sales assets.

Trust & business

Customer onboarding as a trust-building programme

Transform your onboarding process from a legal hurdle into a strategic engine for customer trust and accelerated revenue.

Trust & business

The executive trust narrative every founder should be able to deliver

Master the executive trust narrative to bridge the gap between technical security and board-level commercial assurance.

Trust & business

Trust for SaaS startups selling upmarket

Winning enterprise deals requires more than a good product; it requires a 'Trust Stack' that satisfies cynical procurement teams and risk-averse CISOs.

Trust & business

Trust in fintech: passing bank due diligence at Series A speed

Master the brutal world of Tier-1 bank due diligence by shifting from reactive compliance to a proactive trust posture that accelerates your Series A growth.

Trust & business

Trust in healthtech: DTAC, DCB0129 and buyer confidence

Master the NHS trust landscape by aligning DTAC, DCB0129, and ISO 27001 to secure contracts and demonstrate clinical safety.

Trust & business

Trust in legaltech: confidentiality as commercial edge

Discover why robust information security is the most effective sales tool for modern legaltech firms and how to leverage ISO 27001 to close larger enterprise deals faster.

Trust & business

Trust for public sector suppliers: winning framework work

A practitioner's guide to navigating public sector procurement by leveraging ISO standards to bypass hurdles and win framework spots.

Trust & business

ISO 27001 for cyber security firms: certifying the shoemaker

Cyber consultancies, MSSPs and pentest firms are the group most likely to get away with 'trust us, we're the security people' — and the group where a buyer's compliance question lands hardest. This...

ISO standardsCybersecurity

ISO 42001 for cyber security firms: governing the AI you sell and use

Cyber firms sit in an awkward spot with AI: you sell AI-augmented services, you use AI in the SOC, and your clients now ask about both in the same questionnaire. ISO 42001 is the cleanest way to an...

AI governanceCybersecurityISO standards

SOC 2 for cyber security firms: when to add it to ISO 27001

If half your pipeline is US-headquartered, ISO 27001 alone will start losing deals. A pragmatic view on when a cyber firm should add SOC 2, and how to run both without duplicating effort.

SOC & attestationsCybersecurityISO standards

Risk management for cyber security firms: eating your own dog food

Cyber firms give risk advice all day and often run their internal risk register in a spreadsheet nobody has opened in six months. Here is what a credible risk programme actually looks like inside a...

Risk managementCybersecurity

ISO 9001 for cyber security firms: quality as competitive advantage

Cyber engagements are famously variable in quality. ISO 9001 is the underrated standard that formalises how a cyber firm scopes, delivers and improves — and it is often the differentiator in enterp...

ISO standardsCybersecurity

ISO 20000-1 for cyber security firms delivering managed detection

MDR, managed SIEM and managed EDR are services. ISO 20000-1 formalises how you run them — the standard behind the phrase 'we operate a mature service management system' on enterprise RFPs.

ISO standardsCybersecurity

ISO 27001 for managed service providers: the ISMS your clients inherit

When an MSP gets breached, every client is in scope. ISO 27001 is now table stakes for winning mid-market and enterprise MSP work — here's how a 20–200 person MSP certifies without a full-time comp...

ISO standardsCybersecurity

ISO 20000-1 for MSPs: the service management standard buyers now ask for

ITIL is a body of knowledge. ISO 20000-1 is the certifiable proof you actually run services the way you claim to. For MSPs bidding beyond SME accounts, it is fast becoming the deciding standard.

ISO standards

ISO 9001 for MSPs: managing quality across a multi-tenant estate

Every MSP swears their service is consistent. Every client eventually experiences that it isn't. ISO 9001 is the standard that closes the gap between the story and the reality across a multi-tenant...

ISO standards

ISO 42001 for MSPs: governing AI copilots inside client environments

AIOps, ticket triage copilots and AI-assisted patching are now everywhere in the MSP stack — often without a governing standard on top. ISO 42001 gives MSPs an answer to the 'what AI are you runnin...

AI governanceISO standards

Risk management for MSPs: your risk is every client's risk

One credential compromise, one misconfigured backup, one supplier failure — inside an MSP each of those cascades across every tenant. A grown-up risk programme is the difference between a bad week...

Risk managementCybersecurity

Multi-tenant compliance for MSPs: one ISMS, many clients

MSPs live at the intersection of one internal ISMS and dozens of client environments each with their own regulatory obligations. Here is the operating model that keeps one certifiable ISMS while ge...

ISO standardsRisk managementCybersecurity

ISO 27001 for B2B SaaS: the standard your enterprise pipeline needs

Beyond about £5m ARR, B2B SaaS deals stop closing without an infosec assurance certificate. ISO 27001 is the most portable answer — here is the pragmatic path for a 20–200 person SaaS without a ded...

ISO standardsCybersecurity

ISO 42001 for B2B SaaS shipping AI features

If your product includes an LLM feature, buyer questionnaires now include an AI section. ISO 42001 is the standard that lets you answer it credibly, and — crucially — differentiates you from every...

AI governanceISO standards

ISO 9001 for B2B SaaS: the underrated quality standard for scale-ups

Every SaaS founder talks about quality. ISO 9001 is the standard that turns 'we care about quality' into a system that survives founder handover, VP transitions and cross-region expansion.

ISO standards

ISO 20000-1 for B2B SaaS: when service management becomes the standard buyers ask for

For SaaS firms selling into regulated industries, financial services and public sector, ISO 20000-1 is the standard that formalises what your ops team already half-does. It's simpler than SREs fear...

ISO standards

Risk management for B2B SaaS: from spreadsheet to boardroom

SaaS risk is unusual: dependencies you don't own, customers who inherit your posture, and a founder who is often the ultimate risk owner. Here is a risk model that scales from Series A through Seri...

Risk management

Answering SaaS security questionnaires without a full-time compliance manager

The single biggest hidden cost in mid-market B2B SaaS is the founder or CTO spending days on questionnaires. A repeatable answer bank, evidence library and trust centre eliminate almost all of it.

Trust & businessCybersecurity

The SaaS trust centre that measurably shortens sales cycles

A trust centre isn't a marketing page — it's a procurement tool. The right structure turns week-long security reviews into a self-serve pass and moves deals into legal review faster.

Trust & businessCybersecurity

ISO 27001 for manufacturing: OT, IT and the standard buyers now demand

UK and EU manufacturers now face infosec assurance questions from every tier-one customer. ISO 27001 is the answer that scopes across corporate IT and shop-floor OT without becoming a two-year prog...

ISO standardsCybersecurity

ISO 9001 for modern manufacturers: beyond the audit binder

Most UK manufacturers have held ISO 9001 for decades and lost the plot along the way. Here is what a modern, useful ISO 9001 system looks like in a 20–200 person manufacturer — one that survives di...

ISO standards

ISO 42001 for manufacturing: governing AI on the shop floor

Predictive maintenance, visual inspection and demand forecasting are now AI-powered in most modern manufacturers. ISO 42001 is the standard that governs them the way ISO 9001 governs quality.

AI governanceISO standards

ISO 20000-1 for manufacturing IT: services underneath a physical business

Manufacturing IT teams run ERPs, MES, OT bridges and site services that the shop floor cannot run without. ISO 20000-1 formalises how that IT is delivered — a natural companion to a mature ISO 9001...

ISO standards

Risk management for manufacturers: from HSE clipboard to enterprise register

Most UK manufacturers manage safety risk brilliantly and enterprise risk badly. Here is the operating model that unifies HSE, quality, supply chain and cyber risk into one live register a board can...

Risk management

Cyber risk for connected manufacturing: IIoT, OT and the ransomware target on your back

Connected manufacturing has quietly become one of the most targeted sectors for ransomware in the UK and EU. Here is the cyber risk view that maps genuine OT/IT exposure and the ISO 27001-anchored...

CybersecurityRisk management

Have a question we haven't covered?

Email hello@iso-standard.app — a practitioner will reply within one business day. No sales script.