From AI ambition to AI accountability

Why ISO/IEC 42001 now belongs on the board agenda in Jersey, Guernsey and the Isle of Man.

Management-consulting-team-collaboration

The landscape: AI is already inside your business

Most boards in the Islands have approved an AI policy. Far fewer have seen an AI inventory. The gap between them is where the risk sits, because AI arrives through three doors at once: tools staff adopt themselves, features switched on by default in software you licence, and AI deployed by outsourced providers whose regulatory risk still rests with you. 

The local regulatory position has moved decisively in twelve months.  

  • JerseyThe JFSC’s July 2026 guidance creates no new requirements. It applies existing obligations to AI on five principles of governance and accountability, cyber security, privacy and data quality, regulatory compliance, consumer protection and fair treatment and transparency and explainability. It is proportionate in that it is light-touch for low-impact tools, materially more for onboarding, lending or advice, with material use cases expected in the business risk assessment.
  • GuernseyThe GFSC issued a policy statement on AI in January 2026 and has encouraged firms to adopt AI tooling. The ODPA has published AI-specific guidance and helped coordinate a statement by 61 data protection authorities on AI-generated imagery. The States of Guernsey have asked for options on Bailiwick-wide AI coordination, including a dedicated AI office, by December 2026.
  • Isle of ManA £1m National AI Office launched in January 2026 within Digital Isle of Man, building on‘Activate AI’, with a National AI Strategy due by the end of 2026.
  • Beyond the IslandsThe EU AI Act reaches organisations outside the EU where AI output is used there. June 2026’s Digital Omnibus deferred most high-risk obligations to December 2027 and August 2028, but Article 50 transparency obligations apply from 2 August 2026. The UK stays on a regulator-led route, with a statutory ICO code on AI and automated decision-making due this summer.


The direction of travel is identical in each: No separate AI rulebook, existing obligations applied to AI and an expectation that you can evidence how. Groups with UK or Cayman entities will see the same pattern. 

Where AI governance actually breaks

The exposure here is rarely an exotic model behaving unpredictably. It is ordinary people using ordinary tools with no control around them. 

You own the output. In Ayinde v London Borough of Haringey [2025] EWHC 1383 (Admin), fictitious authorities were put before the High Court and those responsible referred to their regulators; dozens of similar UK cases have followed. Substitute “regulatory filing” or “trustee minute” for “court submission” and it lands on a Jersey trust company. 

Confidentiality is lost at ‘the moment of paste’. In [2026] UKUT 81 (IAC), the Upper Tribunal held that uploading confidential documents into a public AI tool placed that information in the public domain, breaching confidentiality and waiving privilege and noted the risk is not confined to lawyers. For businesses built on fiduciary duty, there is no remedy after the fact. 

AI is used against you, too. In 2024 the consultancy Arup confirmed a loss of around US$25.6m after an employee made 15 transfers following a video call on which every other participant was a deepfake. Voice cloning now bears directly on client verification and payment authorisation. 

You cannot govern what you have not counted.  

Shadow AI, default-on vendor features and AI inside outsourced processes are where a first inventory produces the biggest surprises. 

Underneath all four sits one gap. Almost every organisation can produce a policy. Very few can produce the inventory, risk assessments, approvals, human-oversight records, testing results and monitoring evidence a supervisor or a client’s auditor will ask to see. 

The options and why boards should land on ISO/IEC 42001

There is more than one credible route, and the choice is a board decision, not a technical one. 


Four things make ISO/IEC 42001 the right answer for most organisations here.  

  1. It is certifiable, giving independent evidence to clients who will never read your internal policy. 
  2. It shares a management system structure with ISO 27001 and 9001, so it extends what you run rather than duplicating it. 
  3. It is jurisdiction-neutral, covering Jersey, Guernsey, Isle of Man and UK entities in one system. 
  4. And it maps onto the JFSC’s five principles.
a pale charcoal background
MCS-team-meeting

Be equally clear about what it is not.

ISO/IEC 42001 is not a harmonised standard under the EU AI Act and confers no presumption of conformity. 


Certification evidences that a management system works. It does not certify the output of any model. Treat it as assurance, not immunity. 


Only a few hundred organisations worldwide are thought to have held certificates by spring 2026. In jurisdictions competing on trust and regulatory credibility, that is a real differentiator and a short-lived one. 

What the standard requires and the route to it

ISO/IEC 42001 is a ‘plan–do–check–act’ management system for AI: scope, accountability, risk and impact assessment, controls, competence, lifecycle operation, monitoring, internal audit and continual improvement. A typical route runs six to twelve months: 

  • Scope and inventory (4–6 weeks). Every use case, including embedded and third-party, rated for materiality. This alone usually changes the board conversation.
  • Gap assessment. Against ISO/IEC 42001 and, in parallel, JFSC, GFSC, ODPA, JOIC and Isle of Man Information Commissioner expectations.
  • Build. Policy, roles and committee terms of reference, risk and impact assessment methodology(ISO/IEC 42005 is the companion guidance), lifecycle controls, vendor duediligence and board reporting.
  • Operate and evidence(3–6 months). The system has to run before it can be audited.
  • Internal audit and management review.
  • Certification. Stage 1 (documentation), Stage 2 (effectiveness), then annual surveillance.

The board's call

AI adoption will keep accelerating, and the Islands are right to encourage it. But the organisations that benefit most will be those that can show their work to a regulator, to a client running due diligence and to their own audit committee.

A focused readiness assessment is the sensible first step: What AI you run, what is material, where the gaps are and a proportionate roadmap.

Most boards start with a readiness assessment: What AI you’re running, what’s material, and where the gaps are. From there we support AI inventories and materiality models; policy and committee terms of reference, impact assessments, vendor AI risk reviews, control design and assurance mapping' board reporting,  ISO/IEC 42001 readiness and board training.

If you’re thinking about the governance surrounding AI in your business, please contact Arthur Mainja, Principal, BDO Jersey at amainja@bdo.je.


Arthur Mainja

Arthur Mainja

Principal Consultant
View bio