Governance. Risk. Compliance. Cybersecurity.
Extended FAQs

Extended FAQs — AI Governance & ISO 42001

Extended answers to the questions buyers, boards and procurement teams ask before commissioning AI Governance & ISO 42001.

  • ISO/IEC 27001 Certified
  • ISO/IEC 27701 Certified
  • ISO 9001 Certified

Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation

Does ISO 42001 replace ISO 27001?

No — they are complementary. 27001 secures information, 42001 governs AI systems.

How does the EU AI Act apply to us if we are outside the EU?

It applies extraterritorially if you place an AI system on the EU market, if your output is used in the EU, or if you provide a high-risk system to an EU deployer. Most cross-border SaaS is in scope.

We use third-party LLMs — does this still apply?

Yes. Embedded AI (OpenAI, Anthropic, Google, Azure OpenAI, Bedrock) sits in your inventory as a 'system in use' and must be governed, evaluated and monitored.

How long does ISO 42001 certification take?

Typically 16 to 24 weeks for a focused AIMS scope. Faster for organisations with a mature ISO 27001 ISMS to build on.

How do you evaluate generative AI risk?

We run model evaluations covering bias, robustness, prompt injection, jailbreak resistance, hallucination, PII leakage and abuse — calibrated to the use-case risk tier.

Will this slow down our AI roadmap?

No — the opposite. A risk-tiered approval pathway lets low-risk use-cases ship quickly while concentrating governance effort on the genuinely high-risk ones.

Who owns AI governance — security, legal or product?

All three, with an executive AI Governance Forum we help you stand up. ISO 42001 expects named accountability across the model lifecycle, not a single function.

How experienced is the team that will actually deliver AI Governance & ISO 42001?

Every engagement is led by a partner or principal with at least 12 years in ai governance & risk and supported by certified consultants (CISA, CISM, CISSP, CIPP/E, ISO 27001 Lead Auditor, ISO 42001 Lead Implementer, OSCP, CREST). You meet the actual delivery team before contracts are signed.

How do you handle confidentiality and data residency?

All client data stays within the regions you authorise. NDAs are signed before scoping calls, and we offer fully on-premise delivery for sensitive engagements. For UAE and KSA clients, evidence remains in-country by default.

Can MAST work alongside our existing Big 4 auditor?

Yes. We routinely collaborate with EY, Deloitte, KPMG, PwC, BDO and Grant Thornton as your implementation partner while they retain audit independence. Roles are agreed upfront in writing to preserve auditor independence rules.

Do you offer multi-year continuous compliance?

Yes — our Managed Compliance Service operates the programme on a monthly subscription, covering control monitoring, evidence collection, internal audit and recertification across every framework in scope.

How is success measured?

Success criteria are agreed in the engagement charter — typically a passed certification or regulator submission, an audit-ready evidence repository, trained control owners and a 12-month continuous-improvement plan.