At a Glance
| Sector | Healthcare Technology (clinical records software) |
| Starting point | ISO 27001 certified and operating — no privacy management system, no AI governance |
| Trigger | A contractual obligation from a client, with a fixed 20-week deadline |
| Timeline | 20 weeks — ISO 27701 and ISO 42001 built on the existing ISMS |
| Environment | Microsoft 365 (SharePoint, Purview, Entra ID) |
The Challenge
The organisation had a mature ISO 27001 information security management system already in place and operating — policies, risk register, internal audit programme, management review, all functioning. What it didn’t have was a formal privacy management system or any AI governance structure, despite AI features already being part of the product.
A client contract changed the timeline from “eventually” to “in 20 weeks.” The client’s own procurement and risk requirements specified both ISO 27701 privacy alignment and ISO 42001 AI governance evidence, on a fixed date tied to the contract itself — not a target to aim for, a deadline that mattered commercially if missed.
The constraint wasn’t the standards themselves — it was building two management systems, from a standing start, inside a window set by someone else’s contract.
Our Approach
The insight that shaped the whole engagement
ISO 42001’s management-system clauses — leadership, planning, resourcing, competence, internal audit, management review — follow the same structure as ISO 27001’s. They’re not identical, but they’re close enough that an organisation with a working ISMS has already built the machinery an AIMS needs; it just isn’t yet scoped to cover AI systems.
That meant the 20-week plan didn’t start with “build an AI management system.” It started with extending what already existed.
1. Extending the existing management system (weeks 1–3)
The ISO 27001 policy hierarchy, risk register, internal audit programme and management review cadence were extended in scope to formally cover AI systems and personal-data processing — not rebuilt. This is the roughly 50% of the AIMS “hard work” that was already sitting inside the existing ISMS.
2. AI system inventory and risk assessment (weeks 3–9)
The genuinely new work started here. Every AI capability in the product — built, embedded, and vendor-supplied — was inventoried, risk-tiered, and assigned an owner. AI risk and impact assessments were conducted for the highest-risk clinical features, with a documented human oversight point for each.
3. Annex A build-out (weeks 6–14)
The AI-specific Annex A controls — data governance for AI, third-party AI supplier assessment, monitoring and incident logging for AI systems, disclosure and transparency requirements — were built against the existing evidence infrastructure rather than a parallel one.
4. ISO 27701 privacy management system (weeks 5–15)
Run in parallel with the AIMS build, using the same extended management-system foundation: a ROPA covering all personal information processing, DPIAs for high-risk processing activities (including AI-assisted features), and a data rights handling workflow.
5. Integration, internal audit and evidence pack (weeks 15–20)
All three frameworks were consolidated into a single audit-ready structure with one internal audit covering all of them, and a client-facing evidence pack built specifically to answer the contractual requirement — not a generic policy document set.
Results
ISO 27701 and ISO 42001 delivered and evidenced within the 20-week contractual window — with roughly half the AIMS management-system effort already in place before the engagement started, because it didn’t need to be built twice.
- The contractual deadline was met without a certification-body scheduling delay putting the client relationship at risk
- The AI system inventory surfaced AI capability the organisation hadn’t formally tracked before the exercise, including a vendor-embedded feature that needed a documented human oversight point added
- The integrated management system was structured so the next framework — if one is ever required — extends the same foundation again, rather than starting a third parallel programme
Key Deliverables
- Extended ISO 27001 management system scope, policy hierarchy and governance cadence covering AI and privacy
- AI system inventory, risk-tiered, with human oversight points and named owners
- AI risk and impact assessments for high-risk clinical AI features
- Annex A control evidence for ISO 42001 — data governance, supplier assessment, monitoring, disclosure
- ROPA and DPIAs for ISO 27701, integrated with the existing risk register
- Single integrated internal audit covering all three frameworks
- Client-facing evidence pack built to the contract’s specific requirements
The Bottom Line
Building an AI management system from zero and building one on top of an existing ISMS are different projects with different timelines. The standards were written expecting the second case — ISO 42001’s structure deliberately mirrors ISO 27001’s. Organisations that already hold ISO 27001 aren’t starting an AIMS from scratch; they’re extending infrastructure that already works, and the real effort concentrates almost entirely in the AI-specific Annex A controls.
20 weeks. A contractual deadline, met. Two frameworks built on one existing management system — because building the management system twice was never actually necessary.