I help UK businesses put AI to work – and keep it defensible.

AI is speeding everything up, including the things that go wrong. So I do two things – build compliant AI Management Systems (ISO 42001), and build the automation that runs the day job on Office 365 and Azure.

Evidence over assertion

Fixed fee over open ended

Audit-ready over audit-hopeful

BSI-certified ISO/IEC 42001:2023 Lead Implementer · 25 years in UK outsourcing & tech · Microsoft 365 & Azure · Complex technical project management

  • Testimonial

    “You’ve managed to achieve in two weeks what others have been trying to solve for over a year”
    Logistics
    Managing Director
  • Testimonial

    “You bring to the table way more than an ordinary consultant, you bring the bells and whistles”
    Procurement
    Senior Procurement Consultant
  • Testimonial

    “What you’ve built here is fantastic, exactly what we needed”
    SME
    Managing Director

Recent work

Logistics

Client reporting, unattended

A monthly manual process replaced end to end: branded reports generated and sent without human involvement.

Microsoft 365 + Power Automate + SQL

Public Sector

One page to identify £100m contract anomalies

Data visualisation of contract expenditure by service and by location

Python

SME

Defensible Sales Commission Reporting

A sales process that still allows flexibility to reward stellar performance and reduce human error

Azure Web App + SQL

Two things I do

01

AI governance (ISO/IEC 42001)

  • Gap assessment against ISO/IEC 42001:2023
  • AI management system built with your team
  • Internal audit and Stage 1 readiness
  • Fixed fee, ~12 weeks to Stage 1, timeline in writing1

Fixed fee – please enquire

02

Automation & data on Microsoft 365 / Azure

  • Client and management reporting that runs itself
  • Sales commission and contract data analysis
  • Python, Power Automate, Azure SQL, Power BI – with minimal premium licensing
  • Built properly, documented, and handed over

Fixed fee – please enquire

I don’t: create generic “AI strategy” decks, generic tool-picking, or governance theatre. If you don’t need ISO 42001, or you need something different, I’ll say so.

I run these systems myself, so I know what an auditor needs to see.

Nick Marfleet

Nick Marfleet – I have over 25 years of experience helping legal, professional services, and enterprise clients align technology with business strategy. I’ve led multi-million-pound projects across digital communications, workflow automation, and document management, consistently delivering high-value outcomes for clients.

I’m passionate about practical innovation and has contributed thought leadership to publications including the Financial Times. I currently hold certifications in ECM, AI, and project management.

What does preparing for ISO 42001 look like?

Most organisations are looking to align with ISO/IEC 42001 because either a client or a prospects procurement team have asked. Procurement teams, Insurers, regulators and existing clients are seeking greater comfort in how organisations are using AI in their day to day operations.

Preparing for ISO/IEC 42001 can take as little as 8 weeks, however this all depends on the availability of the internal teams, what policies/procedures already in place (ISO 27001 for example) and the size and scale of the platforms currently in use. The discovery phase is usually the most revealing stage in terms of how much AI is used in an organisation. Even more revealing is probably the amount of data that is being leaked to vendors and personal chat accounts.

We define the scope of your AI management system, set out roles and accountability, carry out and document a risk assessment, and put in place the policies and controls the standard expects – proportionate to your size and risk. Alongside that, we build the evidence trail that an auditor will ask to see, and make sure your people understand the parts that apply to them.

01


30 mins

Do you need 42001, and is now the time? If not, I’ll tell you.

02


weeks 1–2

Where your AI use actually is versus what the standard expects. Written report, no surprises later.

03


weeks 3–6

Policies, risk assessment, impact assessment, controls — written with your people so they own it.

04


week 7

We run the audit before BSI does.

05


week 8

Certification body audit. You have a timeline in writing from day one.

Writing

  1. *based on SME with up to 500 staff ↩︎