DRAFT — REQUIRES REVIEW BY EXTERNAL ISO 27001 CONSULTANT AND SIGN-OFF BY BRITIAI CTO BEFORE USE IN BID OR AUDIT.
ISO/IEC 27001:2022 — Certification Roadmap
Document ID: ISO06 Version: 0.1 (Draft) Date: 15 June 2026 Owner: BritiAI CTO Target outcome: UKAS-accredited ISO/IEC 27001:2022 certification awarded by Q3 2027.
1. Roadmap summary
BritiAI commits to a transparent, date-stamped path to UKAS-accredited ISO/IEC 27001:2022 certification. The plan reflects realistic SME timelines and is sequenced to ensure that the NHS SBS Healthcare AI Solutions Framework (SBS10523) submission (due 12:00 noon, 21 July 2026) is supported by demonstrable in-flight progress and that Stage 2 certification is achieved within the framework’s first call-off year.
This de-risks BritiAI’s ISO position decisively. Per the official NHS SBS Q&A, a bidder Passes if it holds OR has formally commenced the process of obtaining the required ISO accreditations (or equivalents), with evidence required at framework award and verified during the certification & accreditation due-diligence window of 5 April – 19 May 2027 (via SAP Ariba), ahead of the Framework Start Date of 26 May 2027. BritiAI’s formally commenced, Board-approved ISO/IEC 27001 programme therefore satisfies the Pass criterion at submission. The same in-flight ISO/IEC 27001 programme is expressly accepted by NHS SBS as the equivalent route to Cyber Essentials Plus, giving BritiAI a single coherent information-security assurance position across both requirements.
2. Phased timeline
Phase 0 — Foundation (15 June 2026 → 31 July 2026)
- Milestones:
- 15 Jun: Roadmap and scope ratified by CTO.
- 30 Jun: Engage external ISO 27001 consultant (statement of work signed).
- 15 Jul: Information Security Policy drafted and submitted to Board.
- 31 Jul: Scope statement (ISO01), SoA v0.1 (ISO02), Risk Register v0.1 (ISO04), Policy Framework outline (ISO05) approved by CTO. Stage 1 evidence pack baseline complete.
Phase 1 — SBS bid submission and policy ratification (21 Jul 2026 bid deadline → ongoing)
- Note on sequencing: The SBS bid is submitted on 21 July 2026 with the Stage 1 evidence pack at v0.1 and the declaration in §6 below. Under the NHS SBS Q&A, the formally commenced ISO programme is sufficient to Pass at submission; full certification/accreditation evidence is verified later at the 5 Apr – 19 May 2027 due-diligence stage. Policy ratification continues in parallel.
- Milestones:
- 21 Jul: NHS SBS SBS10523 submission lodged.
- 31 Aug: Board ratifies Information Security Policy and ISMS scope; first Management Review scheduled.
- 30 Sep: First Management Review held; risk treatment plan linked to SoA; threat intelligence subscription live; awareness training tracking operational.
Phase 2 — Certification body selection (1 Sep 2026 → 31 Oct 2026)
- Decision point: Select a UKAS-accredited certification body. Shortlist three (BSI, LRQA, NQA or equivalent), evaluate on (a) UKAS accreditation status for ISO/IEC 27001:2022, (b) healthcare sector experience, (c) auditor availability for Q1–Q2 2027, (d) commercial terms, (e) flexibility for combined ISO 42001 audit in 2028.
- Milestone: 31 Oct 2026 — Certification body contract executed; Stage 1 audit window booked for February 2027.
Phase 3 — Remediation sprint (1 Sep 2026 → 31 Dec 2026)
- Workstreams (from ISO03 Gap Analysis): supplier security overhaul (Votee/Beever DPAs and flow-down), vulnerability management with enforced SLAs, NHS data segregation (A.8.22, A.8.33, A.8.11), incident management lifecycle, logging and monitoring uplift, DLP and data deletion, cryptography uplift (CMK), secure SDLC rollout, BPSS-equivalent screening, document control consolidation.
- Milestone: 31 Dec 2026 — All Critical-priority gaps closed; all Annex A controls at minimum Partial with evidence.
Phase 4 — Internal audit and DR test (1 Jan 2027 → 31 Jan 2027)
- Milestones:
- 15 Jan: First end-to-end internal audit completed by independent auditor (external consultant or trained internal resource not involved in implementation).
- 25 Jan: First tested DR failover completed; lessons captured.
- 31 Jan: Nonconformities from internal audit closed or accepted; second Management Review held.
Phase 5 — Stage 1 audit (1 Feb 2027 → 28 Feb 2027)
- Activities: Documentation audit by certification body. Auditors examine ISMS scope, policies, SoA, risk methodology, internal audit records, and Management Review minutes.
- Milestone: 28 Feb 2027 — Stage 1 report received. Findings categorised as major/minor nonconformities or observations.
Phase 6 — Post-Stage 1 remediation (1 Mar 2027 → 31 Mar 2027)
- Activities: Close all major nonconformities and as many minor nonconformities as feasible. Update SoA, risk register, and policies to reflect Stage 1 feedback.
- Milestone: 31 Mar 2027 — Stage 2 readiness confirmed by CTO and external consultant.
Phase 7 — Stage 2 audit (1 Apr 2027 → 31 May 2027)
- Activities: Implementation audit. Auditors sample evidence to verify the ISMS is operating effectively. Interviews, control walkthroughs, and technical evidence sampling across A.5–A.8.
- Milestone: 31 May 2027 — Stage 2 report received.
Phase 8 — Certificate issue (1 Jun 2027 → 31 Jul 2027)
- Activities: Close any Stage 2 nonconformities. Certification body issues UKAS-accredited certificate.
- Milestone: 31 Jul 2027 — ISO/IEC 27001:2022 certification awarded.
Phase 9 — Surveillance and continual improvement (ongoing from Q3 2027)
- Annual surveillance audits in 2028 and 2029; recertification audit in 2030. ISO/IEC 42001 AIMS certification pursued in parallel from Q4 2027.
3. Critical path and dependencies
The critical path runs through: certification body selection (Oct 2026) → internal audit (Jan 2027) → Stage 1 (Feb 2027) → Stage 2 (Apr–May 2027). The principal dependencies are:
- Availability of certification body auditors in Q1–Q2 2027 (book early).
- Completion of supplier security overhaul with Votee/Beever (legal lead time).
- Engagement of a fractional CISO or external consultant for sustained remediation capacity.
- Board commitment to recurring ISMS resourcing (budget approved in Aug 2026 Board meeting).
4. Resourcing and budget envelope
- External ISO 27001 consultant: ~£35k–£55k across the programme.
- Certification body fees (Stage 1 + Stage 2 + first surveillance): ~£15k–£25k.
- Fractional CISO (1–2 days/week, 12 months): ~£60k–£90k.
- Tooling uplift (SIEM tuning, DLP, threat intel, SBOM): ~£25k–£40k annually.
- Total Year 1 programme: ~£135k–£210k.
5. Governance
The CTO is the executive accountable owner. The Board receives a quarterly update against this roadmap, with material slippage flagged within 10 working days. Management Review minutes form the formal record.
6. NHS SBS bid declaration wording
The following declaration is intended for inclusion in the BritiAI response to SBS10523 in support of the information security assurance requirement. It is conservative, defensible, and consistent with this roadmap.
“BritiAI Limited operates an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022, the scope of which covers BritiAI’s UK operations, personnel, and cloud infrastructure supporting NHS and other UK public-sector customers. As at the date of this submission, BritiAI’s ISMS is in-flight toward UKAS-accredited ISO/IEC 27001:2022 certification, with a Board-approved roadmap targeting Stage 1 audit in February 2027 and Stage 2 certification award by 31 July 2027. BritiAI has formally commenced the process of obtaining ISO/IEC 27001 certification and will provide certification/accreditation evidence at framework award, for verification during the NHS SBS certification & accreditation due-diligence window (5 April – 19 May 2027). The Stage 1 documentation pack — comprising the ISMS Scope Statement, Statement of Applicability against all 93 Annex A controls, Gap Analysis with prioritised remediation backlog, Information Security Risk Register, and Policy Framework — is complete and available on request under non-disclosure. BritiAI’s UK-incorporated parent legal entity holds the ISMS, with sub-processor relationships to Votee Limited (Hong Kong) and Beever (Toronto) governed by ISO 27001-aligned supplier security schedules and UK GDPR Article 28 data processing agreements that contractually prohibit the processing of NHS data outside BritiAI’s UK-controlled environments. BritiAI commits to providing certification body contact details upon selection in October 2026 and to sharing Stage 1 audit outcomes with NHS SBS within 10 working days of receipt.”
7. Document control
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 15 Jun 2026 | CTO (with external consultant pending) | Initial draft for review |
This roadmap is reviewed at each Management Review and updated upon material change.
End of document.
