I help UK businesses put AI & Automation to work – and keep it defensible.
AI is speeding everything up, including the things that go wrong. So I do two things – build compliant AI Management Systems (ISO 42001), and build the automation that runs the day job on Office 365 and Azure.
Evidence over assertion
Fixed fee over open-ended
Audit-ready over audit-hopeful
BSI-certified ISO/IEC 42001:2023 Lead Implementer · 25 years in UK outsourcing & tech · Microsoft 365 & Azure · Complex technical project management
Recent work
Logistics
Client reporting, unattended
A monthly manual process replaced end to end: branded reports generated and sent without human involvement.
Microsoft 365 + Power Automate + SQL
Public Sector
Single dashboard to identify anomalies in a £100m contract
Data visualisation of contract expenditure by service and by location.
Python
SME
Defensible Sales Commission Reporting
A sales process that still allows flexibility to reward stellar performance and reduce human error.
Azure Web App + SQL
Two things I do
- based on an SME with up to 500 staff ↩︎
I run these systems myself, so I know what an auditor needs to see.

Nick Marfleet – I have over 25 years of experience helping legal, professional services, and enterprise clients align technology with business strategy. I’ve led multi-million-pound projects across digital communications, workflow automation, and document management, consistently delivering high-value outcomes for clients.
I’m passionate about practical innovation and have contributed thought leadership to publications including the Financial Times. I currently hold certifications in ECM, AI, and project management.
What does preparing for ISO 42001 look like?
Most organisations are looking to align with ISO/IEC 42001 because either a client or a prospect’s procurement team have asked. Procurement teams, insurers, regulators and existing clients are seeking greater comfort in how organisations are using AI in their day to day operations.
Preparing for ISO/IEC 42001 can take as little as 12 weeks, however this all depends on the availability of the internal teams, what policies/procedures already in place (ISO 27001 for example) and the size and scale of the platforms currently in use. The discovery phase is usually the most revealing stage in terms of how much AI is used in an organisation. Even more revealing is probably the amount of data that is being leaked to vendors and personal chat accounts.
We define the scope of your AI management system, set out roles and accountability, carry out and document a risk assessment, and put in place the policies and controls the standard expects – proportionate to your size and risk. Alongside that, we build the evidence trail that an auditor will ask to see, and make sure your people understand the parts that apply to them.
Writing
Current series
Preparing for an AIMS
Twelve parts on what to do before anyone mentions policies, controls or certification. Four published so far, collected here as they go.
-
One image, five models: what an auditor would ask about image-blaster
image-blaster turns one photo into a 3D scene using five generative models. Seven questions an ISO/IEC 42001 auditor would ask about it, and how to bring a tool like this inside your AI management system.
-
1,766 attempts to get into my website. None got in.
Twelve days of WordPress security logs: 1,766 attempts to get in, a botnet that came looking for me by name, and why 2FA did the heavy lifting.
-
The JCHR’s AI blueprint and the accountability gap
The Joint Committee on Human Rights called for an AI Bill and a single statutory regulator. The government kept oversight distributed across sectoral watchdogs.
