← Back to Case Studies

Healthcare Technology — Building an AIMS on an Existing ISMS in 20 Weeks

A healthcare technology provider already certified to ISO 27001 needed ISO 42001 (AI governance) and ISO 27701 (privacy) added within a 20-week contractual deadline set by a client. Because the management system already existed, roughly half the AIMS build was already done.

Healthcare Technology 20 weeks ISO 27001ISO 27701ISO 42001Integrated Management SystemAI GovernanceAI System Inventory
20 weeksContractual deadline, met
ISO 27701 + 42001Built on an existing ISO 27001 ISMS
~50%Of the AIMS management-system clauses already in place
ISO 27001, ISO 27701 and ISO 42001 sharing one management-system core

The engagement

20 weeks
Situation
A healthcare technology provider — clinical records software, already ISO 27001 certified — was contractually required by a client to extend its management system to cover AI governance and privacy, on a fixed 20-week deadline.
Constraint
The 20 weeks wasn't a target — it was a contractual date. There was no room for the AIMS and PIMS to be built as parallel, disconnected projects; the only way to hit the deadline was to build directly on the existing ISO 27001 management system rather than start two new ones from scratch.
Delivery
ISO 42001's management-system clauses (leadership, planning, resourcing, internal audit, management review) map closely onto the ISO 27001 clauses already in place and operating. Extending the existing ISMS to formally cover AI systems and privacy processing did roughly half the work before a single AI-specific control was touched — the genuinely new effort concentrated almost entirely in Annex A: the AI system inventory, AI risk and impact assessments, human oversight controls, and the privacy-specific PIMS controls for ISO 27701.
Outcome
All three frameworks — ISO 27001 (maintained), ISO 27701, and ISO 42001 — were in place and evidenced within the 20-week contractual window, satisfying the client's requirement without a certification-body delay putting the contract at risk.
20Weeks to deliver
3Frameworks in scope
2New frameworks built
Contractual, metDeadline

At a Glance

SectorHealthcare Technology (clinical records software)
Starting pointISO 27001 certified and operating — no privacy management system, no AI governance
TriggerA contractual obligation from a client, with a fixed 20-week deadline
Timeline20 weeks — ISO 27701 and ISO 42001 built on the existing ISMS
EnvironmentMicrosoft 365 (SharePoint, Purview, Entra ID)

The Challenge

The organisation had a mature ISO 27001 information security management system already in place and operating — policies, risk register, internal audit programme, management review, all functioning. What it didn’t have was a formal privacy management system or any AI governance structure, despite AI features already being part of the product.

A client contract changed the timeline from “eventually” to “in 20 weeks.” The client’s own procurement and risk requirements specified both ISO 27701 privacy alignment and ISO 42001 AI governance evidence, on a fixed date tied to the contract itself — not a target to aim for, a deadline that mattered commercially if missed.

The constraint wasn’t the standards themselves — it was building two management systems, from a standing start, inside a window set by someone else’s contract.


Our Approach

The insight that shaped the whole engagement

ISO 42001’s management-system clauses — leadership, planning, resourcing, competence, internal audit, management review — follow the same structure as ISO 27001’s. They’re not identical, but they’re close enough that an organisation with a working ISMS has already built the machinery an AIMS needs; it just isn’t yet scoped to cover AI systems.

That meant the 20-week plan didn’t start with “build an AI management system.” It started with extending what already existed.

1. Extending the existing management system (weeks 1–3)

The ISO 27001 policy hierarchy, risk register, internal audit programme and management review cadence were extended in scope to formally cover AI systems and personal-data processing — not rebuilt. This is the roughly 50% of the AIMS “hard work” that was already sitting inside the existing ISMS.

2. AI system inventory and risk assessment (weeks 3–9)

The genuinely new work started here. Every AI capability in the product — built, embedded, and vendor-supplied — was inventoried, risk-tiered, and assigned an owner. AI risk and impact assessments were conducted for the highest-risk clinical features, with a documented human oversight point for each.

3. Annex A build-out (weeks 6–14)

The AI-specific Annex A controls — data governance for AI, third-party AI supplier assessment, monitoring and incident logging for AI systems, disclosure and transparency requirements — were built against the existing evidence infrastructure rather than a parallel one.

4. ISO 27701 privacy management system (weeks 5–15)

Run in parallel with the AIMS build, using the same extended management-system foundation: a ROPA covering all personal information processing, DPIAs for high-risk processing activities (including AI-assisted features), and a data rights handling workflow.

5. Integration, internal audit and evidence pack (weeks 15–20)

All three frameworks were consolidated into a single audit-ready structure with one internal audit covering all of them, and a client-facing evidence pack built specifically to answer the contractual requirement — not a generic policy document set.


Results

ISO 27701 and ISO 42001 delivered and evidenced within the 20-week contractual window — with roughly half the AIMS management-system effort already in place before the engagement started, because it didn’t need to be built twice.

  • The contractual deadline was met without a certification-body scheduling delay putting the client relationship at risk
  • The AI system inventory surfaced AI capability the organisation hadn’t formally tracked before the exercise, including a vendor-embedded feature that needed a documented human oversight point added
  • The integrated management system was structured so the next framework — if one is ever required — extends the same foundation again, rather than starting a third parallel programme

Key Deliverables

  • Extended ISO 27001 management system scope, policy hierarchy and governance cadence covering AI and privacy
  • AI system inventory, risk-tiered, with human oversight points and named owners
  • AI risk and impact assessments for high-risk clinical AI features
  • Annex A control evidence for ISO 42001 — data governance, supplier assessment, monitoring, disclosure
  • ROPA and DPIAs for ISO 27701, integrated with the existing risk register
  • Single integrated internal audit covering all three frameworks
  • Client-facing evidence pack built to the contract’s specific requirements

The Bottom Line

Building an AI management system from zero and building one on top of an existing ISMS are different projects with different timelines. The standards were written expecting the second case — ISO 42001’s structure deliberately mirrors ISO 27001’s. Organisations that already hold ISO 27001 aren’t starting an AIMS from scratch; they’re extending infrastructure that already works, and the real effort concentrates almost entirely in the AI-specific Annex A controls.

20 weeks. A contractual deadline, met. Two frameworks built on one existing management system — because building the management system twice was never actually necessary.

Need a similar outcome?

We help government, health, and technology organisations achieve certification faster with automated evidence and expert delivery.

Book a free 30-min call
Microsoft Teams