Insights | Cybercontrols

We practise what we implement: three lessons from running our own ISO 27001 and ISO 42001 systems

Written by Marius van Aswegen | Oct 1, 2026, 8:00:04 AM

We implement and audit management systems for a living. We also run our own. Cybercontrols holds ISO 27001 and ISO 42001 certification, and living under both standards has taught us more than any training course could.

Here are three lessons we now pass on to every client, whether they are starting from scratch or adding AI governance to an existing ISMS.

1. Run one system, not two

ISO 42001 shares its clause structure with ISO 27001 for good reason. Context, leadership, planning, support, operation, performance evaluation and improvement: the headings are the same, and so is most of the machinery underneath.

So we run one risk process, one internal audit programme and one management review covering information security and AI together. That means one set of meetings, one set of records and one story to tell an auditor, not two competing ones maintained by different people on different timetables.

The same logic extends to ISO 27701 for privacy and ISO 9001 for quality. Integration is not a shortcut; it is how the standards were designed to be used.

2. Keep a live AI inventory

Every new tool a team adopts, from a meeting transcriber to a coding assistant, raises a scope question. Is it in the AI management system? What does it do with our data? Who approved it, and against what criteria?

Keeping the AI inventory current is a habit, not a project you complete once before the audit. We review ours as part of normal change management, which means a new tool is assessed when it arrives, not discovered six months later in an internal audit.

For most SMEs this is the single most useful thing ISO 42001 asks for. You cannot govern AI you do not know you are using.

3. Let evidence be a by-product

If gathering evidence for an audit takes a week, the control is probably not operating. It is being reconstructed.

The aim is for records to fall out of normal work: access reviews logged where they happen, incidents recorded in the tool the team already uses, supplier checks captured at onboarding rather than chased at renewal. When that is true, the audit becomes a conversation about how the system works rather than a scramble to prove that it did.

It also changes how the system feels to the people running it. Evidence as a by-product is lighter to maintain, and far more convincing to an auditor, than evidence produced for the occasion.

Why this matters to our clients

None of this is theory to us. It is how we run the business, and it is why our advice tends to be short and practical. We have made the mistakes on our own system first, and we also sit on the other side of the table, auditing for UK certification bodies. That combination shapes everything we build: systems designed to survive scrutiny, not just to pass it.

If you are weighing up ISO 27001, ISO 42001 or both together, talk to us or email hello@cybercontrols.io.