#238 Umony's ISO 42001 Journey - Setting the Standard for effective AI Management
Release Date: 12/12/2025
The ISO Show
It’s been a busy year for ISO Standards, with that set to ramp up in 2026 thanks to upcoming Standard transitions. Before we dive into a new year, we’d like to take a step back and highlight some of the key ISO milestones from 2025. In this episode, Steph Churchman, Communications Manager at Blackmores, looks back at the major Standard updates from 2025, including changes to existing Standards, new ISO’s published and key upcoming changes you need to be aware of for 2026. You’ll learn · What ISO Standards have been updated in 2025? ...
info_outlineThe ISO Show
AI has become inescapable over the past years, with the technology being integrated into tools that most people use every day. This has raised some important questions about the associated risks and benefits related to AI. Those developing software and services that include AI are also coming under increasing scrutiny, from both consumers and legislators, regarding the transparency of their tools. This ranges from how safe they are to use to where the training data for their systems originates from. This is especially true of already heavily regulated industries, such as the financial...
info_outlineThe ISO Show
When embarking on your ISO journey, a crucial first step is evaluating your current level of compliance and identifying what gaps need to be filled to gain certification or fully align with a Standard. This is typically done by conducting a Gap Analysis. This exercise sets the foundations for your ISO Implementation project, from setting key actions and objectives, to resourcing and establishing a project timeline. In this episode, Ian Battersby dives into the purpose of a Gap Analysis, who should be involved in the exercise and what inputs and outputs you should expect to have from...
info_outlineThe ISO Show
One of the common pain points when calculating your carbon emissions is simply gathering the data. When collating data from different departments and suppliers, it can be easy to get overwhelmed. The struggle doesn’t stop there, as after obtaining all that data you have to find the best way to capture and display it in a way that’s useable for the necessary number crunching. Many will turn to an old favourite, spreadsheets, but these can quickly become very unwieldy and impractical if you’ve got a lot of data to process. Thankfully, there’s a lot of new tech and tools available to...
info_outlineThe ISO Show
An ISO project can typically be completed within 6 – 12 months depending on an organisations size and complexity. Anyone who’s been through the process of ISO Implementation knows that there is a lot of work involved in that time span, from coordinating teams, gathering and creating documentation to auditing your processes. Now imagine doing that for 3 ISO Standards simultaneously within 3 months! Which is exactly what today’s guest, PUBLIC, have achieved. While it’s not a timeframe we recommend, their efforts deserve to be celebrated, and displays what good project management with...
info_outlineThe ISO Show
Continual Improvement is at the heart of ISO Management, a large part of which is dedicated to ensuring issues don’t reoccur. This is more than just putting a plaster on it and calling it a day, it’s about finding the root cause. This not only eliminates wasted time, effort and money with firefighting repeated mistakes, but also drives meaningful improvement. Over the years, many techniques have been developed to help with finding cause. In this episode, Ian Battersby explores the need to find the root cause of issues in ISO Management and explains some key techniques for root cause...
info_outlineThe ISO Show
When thinking of sectors that need effective energy management, the ones that typically come to mind include the likes of transportation and manufacturing. However, energy management is something that any business can benefit from. Such is the case with today’s feature, Clyde & Co, a global law firm who made the decision to Implement ISO 50001 energy management to tackle the largest part of their sustainability impact. In this episode, Ian Battersby is joined by Paul Barnacle, Head of Health, Safety, Security and Environment at Clyde & Co, to discuss their journey towards ISO...
info_outlineThe ISO Show
The topic of suicide is all too often a discussion avoided due to its tragic and uncomfortable nature. However, the reality is that there are 6,000 deaths by suicide in the UK each year, with in excess of 727,000 deaths annually worldwide. In recent years there has been more awareness about the topic, with a range of resources targeted to help with the prevention and support of those affected. For businesses seeking further guidance, a new Standard is on the horizon. In this episode, Ian Battersby is joined by Marcus Long, Chief Executive at IIOA, who shares his inspirational story of...
info_outlineThe ISO Show
When stating ISO Management System ‘compliance’, that in reality means the conformance to ISO Standard requirements, compliance in ISO terminology actually refers to compliance with legal and other statutory regulations. It may sound like semantics, but the difference is distinct for a reason, as you don’t get a ‘non-compliance’ for not meeting requirements, rather you get a ‘non-conformity’. When it comes to compliance with the law as required by ISO Standards, you need more than a Legal Register to prove compliance. In this episode, Ian Battersby dives into what is meant by...
info_outlineThe ISO Show
How often have you heard someone say they aspire to be an ISO consultant? Likely not at all! That’s not surprising as it’s quite a niche world to find yourself in, yet despite that, there are still thousands of ISO professionals worldwide. We’re continuing with our latest mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification. In this episode we introduce Anju Punetha, a QHSE Consultant at Blackmores, to share the journey of how she...
info_outlineAI has become inescapable over the past years, with the technology being integrated into tools that most people use every day. This has raised some important questions about the associated risks and benefits related to AI.
Those developing software and services that include AI are also coming under increasing scrutiny, from both consumers and legislators, regarding the transparency of their tools. This ranges from how safe they are to use to where the training data for their systems originates from.
This is especially true of already heavily regulated industries, such as the financial sector. Today’s guest saw the writing on the wall while developing their unique AI software, that helps the financial sector detect fraud, and got a jump start on becoming accredited to the world’s first best practice Standard for AI, ISO 42001 AI Management.
In this episode, Mel Blackmore is joined by Rachel Churchman, The Global Head of GRC at Umony, to discuss their journey towards ISO 42001 certification, including the key drivers, lessons learned, and benefits gained from implementation.
You’ll learn
· Who is Rachel?
· Who are Umony?
· Why did Umony want to implement ISO 42001?
· What were the key drivers behind gaining ISO 42001 certification?
· How long did it take to implement ISO 42001?
· What was the biggest gap identified during the Gap Analysis?
· What did Umony learn from implementing ISO 42001?
· What difference did bridging this gap make?
· What are the main benefits of ISO 42001?
· The importance of accredited certification
· Rachel’s top tip for ISO 42001 Implementation
Resources
· Umony
In this episode, we talk about:
[02:05] Episode Summary – Mel is joined by Rachel Churchman, The Global Head of GRC at Umony, to explore their journey towards ISO 42001 certification.
[02:15] Who is Rachel?: Rachel Churchman is currently The Global Head of GRC (Governance, Risk and Compliance) at Umony, however keen listeners to the show may recognise her as she was once a part of the Blackmores team. She originally created the ISO 42001 toolkit for us while starting the Umony project under Blackmores but made the switch from consultant to client during the project.
[04:15] Who are Umony? Umony operate in the financial services industry. For context, in that industry every form of communication matters, and there are regulatory requirements for firms to capture, archive and supervise all business communications.
That covers quite a lot! From phone calls, to video calls, instant messaging etc, and failures to capture that info can lead to fines.
Umony are a compliance technology company operating within the financial services space, and provide a platform that can capture all that communications data and store that securely.
[05:55] Why did Umony embark on their ISO 42001 journey? Umony have recently developed an AI platform call CODA, which uses advanced AI to review all communications to detect financial risks such as market abuse, fraud or other misconduct.
This will flag those potential high-risk communications to a human to continue the process. The benefit of this is that rather than financial institutions only being able to monitor a very small set of communications due to it being a very labour intensive task, this AI system would allow for monitoring of 100% of communications with much more ease.
Ultimately, it’s taking communications capture from reactive compliance to proactive oversight.
[08:15] Led by industry professionals: Umony have quite the impressive advisory board, made up of both regulatory compliance personnel as well as AI technology experts.
This includes the likes of Dr.Thomas Wolfe, Co-Founder of Hugging Face, former Chief Compliance Officer at JP Morgan and the CEO of the FCA.
[09:00] What were the key drivers behind obtaining ISO 42001 certification? Originally, Rachel had been working for Blackmores to assist Umony with their ISO 27001:2022 transition back in early 2024. At the time, they had just started to develop their AI platform CODA.
Rachel learned about what they were developing and mentioned that a new Standard was recently published to address AI specifically. After some discussion, Umony felt that ISO 42001 would be greatly beneficial as it took a proactive approach to effective AI management.
While they were still in the early stages of creating CODA they wanted to utilise best practice Standards to ensure that the responsible and ethical development of this new AI system.
When compared to ISO 27001, ISO 42001 provided more of a secure development lifecycle and was a better fit for CODA as it explores AI risks in particular. These risks include considerations for things like transparency of data, risk of bias and other ethical risks related to AI.
At the time, no one was asking for companies to be certified to ISO 42001, so it wasn’t a case of industry pressure for Umony, they simply knew that this was the right thing to do.
Rachel was keen to sink her teeth into the project because the Standard was so new that Umony would be early adopters. It was so new, that certification bodies weren’t even accredited to the Standard when they were implementing the Standard.
[12:20] How long did it take to get ISO 42001 certified? Rachel started working with Anna Pitt-Stanley, COO of Umony, around April 2024. However the actual project work didn’t start until October 2024, Umony already had a fantastic head start with ISO 27001 in place, and so project completion wrapped up around July of 2025.
They had their pre-assessment with BSI in July, which Rachel considered a real value add for ISO 42001 as it gave them more information from the assessors point of view for what they were looking for in the Management System.
This then led onto Stage 1 in August 2025 and Stage 2 in early September 2025. That is an unusually short period of time between a Stage 1 & 2, but they were in remarkably good shape at the end of Stage 1 and could confidently tackle Stage 2 in quick succession.
The BSI technical audit finished at the end of September, so in total from start to finish the Implementation of ISO 42001 took just under 12 months.
[15:50] What was the biggest gap identified during the Gap Analysis? A lot of the AI specific requirements were completely new to this Standard, so processes and documentation relating to things like ‘AI Impact Assessment’ had to be put in place.
ISO 42001 includes an Annex A which details a lot of the AI related technical controls, these are unique to this Standard, so their current ISO 27001 certification didn’t cover these elements.
These weren’t unexpected gaps, the biggest surprise to Rachel was the concept of an AI life cycle. This concept and its related objectives underpin the whole management system and its aims. It covers the utilisation or development of AI all the way through to the retirement of an AI system.
It’s not a standalone process and differs from ISO 27001’s secure development life cycle, which is a contained subset of controls. ISO 42001’s AI life cycle in comparison is integrated throughout the entire process and is a main driver for the management system.
[19:30] What difference did bridging this gap make? After Umony understood the AI life cycle approach and how it applied to everything, it made implementing the Standard a lot easier. It became the golden thread that ran through the entire management system.
They were building into an existing ISMS, and as a result it created a much more holistic management system.
It also helped with the internal auditing, as you can’t take a process approach to auditing in ISO 42001 because controls can’t be audited in isolation.
[21:30] What did Umony learn from Implementing ISO 42001? Rachel in particular learned a lot, not just with ISO 42001 but with AI itself.
AI is new to a lot of people, herself included, and it can be difficult to distinguish what is considered a risk or opportunity regarding AI.
In reality, it’s very much a mix of the two. There’s a lot of risk around data transparency, bias and data poisoning as well as new risks popping up all the time due to the developing technology. There’s also a creeping issue of shadow IT, which is where employees may use hardware of software that hasn’t been verified or validated by the company. For example, many people have their own Chat GPT accounts, but do you have oversight of what emplyees may be putting into that AI tool to help with their own tasks?
On a more positive note, there are so many opportunities that AI can provide. Whether that’s productivity, helping people focus more on the strategic elements of their role or reduction of tedious tasks.
Umony is a great example of where an AI has been developed to serve a very specific purpose, preventing or highlighting potential fraud in a highly regulated industry. They’re not the only one, with many others developing equally crucial AI systems to tackle some of our most labour-intensive tasks.
In terms of experience with Implementing ISO 42001, Rachel feels it cemented her opinion that an ISO Standard provides a best practice framework that is the right way to go about managing AI in an organisation. Whether you’re developing it, using it or selling it, ISO 42001 puts in place the right guardrails to make sure that AI is used responsibly, ethically, and that people understand the risks and opportunities associated with AI.
[26:30] What benefits were gained from Implementing ISO 42001? The biggest benefit is having those AI related processes in place, regardless of if you go for certification.
Umony in particular were keen to ensure that their certification was accredited, as this is a recognised certification. With Umony being part of such a regulated industry, it made sense that this was a high priority. As a result, they went with BSI as their Certification Body, who were one of the first CB’s in the UK to get IAF accredited, quickly followed by UKAS accreditation.
[27:55] The Importance of accredited certification: Sadly, a new Standard creates a lot of tempting offers from cowboy certification bodies that operate without a recognised accreditation.
They will offer a very quick and cheap route to certification, usually provided through a generic management system which isn’t reflective of how you work. Their certificate will also not hold up to scrutiny as it’s not accredited with any recognisable body. For the UK this is UKAS, who is the only body in the UK under the IAF that is able to certify companies to be able to provide a valid accredited certificate.
There’s are easily available tools to help identify if a certificate is accredited or not, so it’s best to go through the proper channels in the first place!
Other warning signs of cowboy companies to look out for include:
· Off the shelf Management system provided for a fee
· Offering of both consultancy and certification services – no accredited CB can provide both to a client, as this is a conflict of interest.
· A 5 – 10 year contract
It’s vital that you use an accredited Certification Body, as they will leave no stone unturned when evaluating your Management System. They are there to help you, not judge you, and will ensure that you have the upmost confidence in your management system once you’ve passed assessment.
Umony were pleased to have only received 1 minor non-conformity through the entire assessment process. A frankly astounding result for such a new and complex Standard!
[32:15] Rachel’s top tip: Firstly, get a copy of the Standard. Unlike a lot of other Standards where you have to buy another Standard to understand the first one, ISO 42001 provides all that additional guidance in its annexes.
Annex B in particular is a gold mine for knowledge in understanding how to implement the technical controls required for ISO 42001.
It also points towards other helpful supporting Standards as well, that cover aspects like AI risks and AI life cycle in more detail.
Rachel’s second tip is: You need to scope out your Management System before you start diving into the creation of the documentation. This scoping process is much more in-depth for ISO 42001 than with other ISO Standards as it gets you to understand your role from an AI perspective. It helps determine whether you’re an AI user, producer or provider, it also gets you to understand what the management system is going to cover.
This creates your baseline for the AI life cycle and AI risk profile. These you need to get right from the start, as they guide the entire management system.
If you’ve already got an ISO Standard in place, you cannot simply re-use the existing scope, as it will be different for ISO 42001. If you’re struggling, CB’s like BSI can help you with this.
[35:20] Rachel’s Podcast recommendation: Diary of a CEO with Stephen Bartlett.
[32:15] Rachel’s favourite quote: “What’s the worst that can happen?” – An extract from a Dale Carnegie course, where the full quote is: “First ask yourself what is the worst that can happen? Then, you prepare to accept it and then proceed to improve on the worst.”
If you’d like to learn more about Umony and their services, check out their website.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List