ISO Standards

Zoocha achieves ISO/IEC 42001 certification for responsible AI management

David Pratt

David Pratt

CTO

We are delighted to announce that Zoocha has achieved ISO 42001:2023 certification, the international standard for Artificial Intelligence Management Systems.

This certification recognises the structured, responsible, and continually improving way in which we select, configure, use and oversee artificial intelligence across our organisation and client delivery.

The scope of our assessment covered the design, development, integration, configuration, and governance of digital services, web applications, and cloud based solutions incorporating artificial intelligence and machine learning capabilities across Zoocha.

This achievement represents nearly 12 months of focused work to turn responsible AI principles into practical, auditable controls that are embedded in how Zoocha operates.

“Zoocha demonstrates a controlled and evolving approach, where monitoring, incident management, and continuous improvement processes are clearly established and actively applied.”

Building responsible AI into the way Zoocha works

AI tools are increasingly part of modern digital delivery. They can support research, knowledge retrieval, software development, testing, content production and operational decision-making. However, their use also introduces important questions about accuracy, accountability, privacy, security, transparency, bias and human oversight; ISO 42001 provides a framework for consistently addressing those questions.

At Zoocha, our Artificial Intelligence Management System, or AIMS, governs our use of approved third-party AI systems and AI-enabled services. We do not design or train foundational AI models. Instead, our focus is on taking responsibility for selecting, assessing, configuring, using, monitoring, and, where necessary, retiring AI tools.

A key principle of our approach is that AI supports people rather than replacing professional judgement. AI generated outputs remain subject to appropriate human review, testing and approval before they are relied upon or included in client deliverables. This is reflected in feedback we received from the auditor:

“AI is treated as a decision-support and productivity tool rather than an autonomous decision-maker, with responsibility for outcomes remaining with Zoocha personnel.”

Led by our AI Management Officers

The implementation has been led by Reece Marsland and Owen Williams, acting as Zoocha’s AI Management Officers.

The AI Management Officer role coordinates the operation of the AIMS, maintains oversight of the AI systems and use cases within scope, and provides a central point of escalation for AI-related risks, incidents and concerns.

Reece and Owen were supported by Hannah McDermott, Zoocha’s Operations Director, who helped plan the implementation approach and ensure that ISO 42001 was integrated effectively with our existing management systems rather than developed as a separate compliance exercise.

Together, they worked closely with colleagues across development, DevOps, QA, data protection, information security, HR, delivery and the wider management team. This cross-functional approach was essential because responsible AI cannot sit within a single department. It touches how we develop software, manage suppliers, protect information, train our people, communicate with clients and continually improve our services.

Fully integrated into our Business Management System

One of the most important decisions we made was not to create a standalone or isolated AI compliance programme.

Instead, we fully integrated ISO 42001 into Zoocha’s existing Business Management System, which already brings together our certified management systems for:

  • ISO 9001: Quality Management
  • ISO 14001: Environmental Management
  • ISO 20000-1: IT Service Management
  • ISO 22301: Business Continuity Management
  • ISO 27001: Information Security Management
  • ISO 27701: Privacy Information Management

This gave us a strong foundation for rapid implementation.

Many of the underlying disciplines required by ISO 42001 were already embedded at Zoocha, including risk management, document control, internal audit, management review, supplier assurance, incident management, continual improvement, secure development, privacy impact assessment and staff competence.

Rather than duplicate these systems, we extended them to address AI specific risks and responsibilities. AI related decisions and improvements now flow through the same established governance channels used throughout the wider business.

The auditor recognised this integrated approach, noting that Zoocha has:

“established mature and well-embedded processes for the management of continual improvement and nonconformities, supported by experience gained through the implementation and maintenance of multiple ISO-certified management systems.”

This existing maturity helped us move from the initial idea to full implementation and certification in just under 12 months.

Policies, processes and controls introduced

Achieving ISO 42001 required us to examine the full lifecycle of AI use, from the first proposal for a new tool or use case through to approval, operation, monitoring, change and decommissioning.

The work led to the introduction or formalisation of a broad set of policies, registers, procedures and supporting controls, including:

  • an Artificial Intelligence Policy
  • an AI Data Management Policy
  • an AI Management Plan (how Zoocha operationally integrate the AI management system)
  • an AI Inventory and Register (of all systems and tools that use AI)
  • AI risk and impact management processes
  • AI System Impact Assessments (of every AI system)
  • lifecycle controls for AI systems
  • an AI Management RACI
  • an AI deployment approval process
  • AI incident management and escalation procedures
  • AI usage guidelines and acceptable use requirements
  • bias, fairness and ethical assessment processes
  • supplier and vendor risk assessments against their use of AI
  • AI data-flow and data-provenance records for each system
  • AI monitoring and continual-improvement processes
  • documentation and evidence registers
  • client-facing transparency and disclosure controls

The resulting governance framework establishes clear expectations for ethical and lawful AI use, and ensures that human oversight, privacy, security, transparency and risk management is considered.

It also ensures that new or significantly updated AI systems are evaluated before use. Depending on the context, this can include reviewing the intended purpose, affected users, data types, supplier terms, security controls, privacy impacts, potential bias, human-review arrangements and monitoring requirements.

“Impact assessments are conducted prior to deployment of any AI system.”

Training the whole Zoocha team

Policies only work when people understand how to apply them.

A major part of the implementation was therefore dedicated to awareness, competence and practical training across Zoocha. AI governance was discussed through team meetings, departmental sessions, technical knowledge sharing and formal learning pathways.

We introduced three annual learning paths through the Zoocha Learning Management System:

  1. AIMS training for all team members, covering responsible day-to-day use, governance, security, privacy, information handling, human oversight and incident reporting.
  2. AIMS training for developers and technical teams, covering AI-assisted development, validation of generated outputs, secure data handling and accountability throughout the software-development lifecycle.
  3. AIMS training for department heads and senior leads, covering governance, risk and impact management, lifecycle oversight, transparency, data governance and responsible adoption across teams.

This training will continue to evolve as AI tools, regulations, and client expectations change.

What the certification means for Zoocha clients

ISO 42001 provides Zoocha clients with independent, external assurance that our use of AI is not adhoc or uncontrolled. It is governed by a documented management system with clear responsibilities, controls, evidence, and continual improvement mechanisms.

For clients, this means:

  • Greater confidence in how AI is used: Our teams work within approved boundaries and defined use cases. AI-assisted work remains subject to professional judgement, human review and established quality controls.
  • Stronger privacy and information-security safeguards: The AIMS is closely integrated with our ISO 27001 Information Security Management System and ISO 27701 Privacy Information Management System.

    This has strengthened how we assess AI suppliers, understand data flows, apply data minimisation, protect confidential information, document processing arrangements and consider whether information is suitable for use with an AI-enabled service.
  • More consistent risk and impact assessment: AI systems and material use cases can be assessed for risks affecting individuals, clients, services and wider stakeholders. This includes security, privacy, bias, fairness, accessibility, transparency, reliability, legal obligations and potential over-reliance on generated outputs.
  • Clear accountability and human oversight: Clear ownership and responsibilities are defined across Zoocha roles and specialist team members. AI systems are not permitted to make unreviewed decisions or autonomously publish, commit or deploy work where human approval is required.
  • Better supplier governance: Third-party AI providers/sytems are evaluated through a robust supplier management and information governance process. Contractual terms, data-processing & residency arrangements, along with security posture, service risks and continuity considerations are reviewed and recorded.
  • Transparent client communication: Our governance framework enables clear communication with interested parties about where and how AI is used across our service delivery. In the event of client specific requirements related to AI, these can be reflected through contracts, project controls, impact assessments and agreed disclosure arrangements.
  • Continual improvement: Monitoring, incidents, audit findings, user feedback and lessons learned feed into our established improvement processes. This means our controls will continue to evolve as technology and the regulatory environment evolve.

In the process of integrating ISO 42001 into our business management system, the implementation prompted broader improvements in data governance, supplier assurance, information security, privacy, quality assurance, and development practices. These stronger controls benefit every client, including those whose projects do not currently contain an AI-enabled feature.

Our certification has also been achieved through a UKAS-accredited certification framework, providing clients with independently assessed assurance that our AIMS has been evaluated competently and consistently against ISO/IEC 42001.

Making Drupal delivery more efficient

As a specialist Drupal agency, one of the most practical benefits of the AIMS is that it provides our teams with a safe framework for using AI to improve the efficiency of Drupal development, support, and quality assurance.

Approved AI-assisted development tools can help developers understand unfamiliar code, investigate technical issues, suggest refactoring approaches, generate examples and accelerate repetitive analysis. This can reduce the time needed to diagnose problems or explore possible solutions, particularly across large or long-lived Drupal codebases.

These tools do not replace our Drupal engineering expertise however, AI-generated code is treated as untrusted input and must meet the same Drupal coding standards, security controls, peer-review requirements, automated checks and QA gates as any other code. 

The result is a more efficient development process without lowering the standards that protect client platforms.

Turning controlled AI use into client efficiencies

Alongside AI-assisted development, several practical threads of work are already helping us use AI to deliver measurable efficiencies for clients.

Faster support diagnosis and knowledge retrieval

We have controlled ways to combine AI with trusted internal sources such as Jira projects, Jira Service Management, Logging systems, GitHub, Drupal.org and our own documentation. This type of system helps teams retrieve relevant knowledge rapidly, improve the speed and accuracy of bug diagnosis and resolution estimates, and reduce the time to produce supporting documentation.

Access, of course, remains least privileged, role-based, project based, with data boundaries and guardrails defined, with any resulting recommendations remaining subject to human review before action is taken.

AI-assisted quality assurance

Our QA team has AI powered testing workflows to help us identify issues, regressions, and deviations from acceptance criteria more quickly. These can be used alongside existing automated browser, accessibility, security, performance and static-analysis testing, which can shorten the feedback loops and help teams focus their time on higher-value exploratory and risk-based testing.

AI-assisted findings are not treated as final evidence. They must be reviewed, reproduced and approved through Zoocha’s established QA process.

Safer AI-enabled Drupal features

We are also contributing to and implementing AI-enabled Drupal capabilities such as automated image alt-text generation, article summarisation, personalisation and automated page building. These features can reduce repetitive content-management effort and support more accessible, efficient editorial workflows. Any public facing generated content would be subject to mandatory human review and editor approval before publication by default. This human-in-the-loop control is enforced through the Drupal content workflow, helping clients benefit from AI without handing over editorial accountability to an automated system.

A whole-team achievement

Certification was only possible because of contributions from people across Zoocha.

Colleagues from across Zoocha helped assess systems, document data flows, review supplier terms, complete impact assessments, update delivery processes, strengthen technical controls, undertake internal audits, contribute evidence and complete new training.

The successful audit reflects that collective effort and the willingness of our team to engage thoughtfully with both the opportunities and risks created by AI.

The audit confirmed that:

“The management system documentation included the necessary policies, procedures, process descriptions etc, required by the standard.”

It also recognised that:

“Staff are empowered to utilise AI tools to improve productivity, whilst remaining accountable for validating all AI outputs prior to commitment.”

These statements capture the balance we set out to achieve: enabling innovation without weakening accountability, quality, security or trust.

What comes next?

Certification is not the end of the work. ISO management systems are built around continual improvement, and our AIMS will continue to evolve as AI tools, threats, regulations and client needs change.

Our priorities include continuing to improve AI-assisted development workflows so that our teams can deliver Drupal services more efficiently without weakening quality, accountability or human oversight, and further embedding AI considerations into our secure Software Development Life Cycle (SDLC). We are also strengthening how we identify and respond to the security risks introduced by AI, including prompt injection, data leakage, insecure integrations, malicious or misleading outputs, supply-chain risk and attempts to manipulate AI-enabled systems. This includes hardening technical controls, improving secure configuration, reviewing access boundaries, and building AI-specific threats into our wider security testing, SDLC processes, and incident-management frameworks.

Alongside this, we are expanding automated testing assurance across the full range of testing activities, including functional, regression, accessibility, security, performance, compatibility and end-to-end testing. The aim is to use AI to shorten feedback loops and improve coverage while ensuring that findings are reproducible, evidence-based and subject to appropriate human review.

Our wider certification programme is also progressing. Zoocha is already in the advanced stages of implementing ISO 27017, which strengthens information-security controls for cloud services, and ISO 27018, which focuses on protecting PII in cloud environments. These standards naturally complement ISO 42001 by reinforcing the cloud security, privacy and supplier-governance controls that support responsible AI use.

Looking further ahead, we are considering achieving certification to ISO 56001, which is the standard for Innovation Management. This would be a natural extension to our management system and would help bridge the gap between responsible AI usage/devolopment and effective innovation management. ISO 56001 would add more structured experimentation, improved evidence-based decision-making, and a more disciplined approach to turning ideas into sustainable value.

For now, we are proud to celebrate this important milestone and the assurance it provides to our clients, partners, and team.

By embedding responsible AI into our established Business Management System, we can continue exploring the benefits of AI while protecting the qualities our clients rely on: security, privacy, transparency, accountability, and high-quality digital delivery.

How can we help?

If you are looking for a digital partner with robust AI management processes, get in touch. We would love to help!
How can we help?