Case Study: How Epocha got AI assurance without the overhead.

QualitaX built a lightweight, ISO/IEC 42001-aligned framework without certification for Epocha. It surfaced missing controls early, brought AI, privacy, security and regulatory risk into one view, and gave Epocha evidence-backed AI assurance to use in sales.

3 min read
OrganisationEpocha (https://epocha.world/)
IndustryEducation, EdTech
Download the case study (PDF)

The Challenge

Epocha was rebuilding its business around AI and wanted to keep growing and sell more aggressively. Its founders saw ISO/IEC 42001-aligned governance as a brake on both. The challenge was to prove that lightweight governance, with no certification programme, would support growth and meet its rising stakeholders' expectations for AI assurance.

The Solution

QualitaX worked with Epocha's founders to put a lightweight governance framework in place, aligned with ISO/IEC 42001 but without certification. The work ran in two phases, so Epocha could see value early and stay in control of its commitment. Phase one: set the baseline. We built a clear, evidenced picture of where AI lives in the business, what Epocha is responsible for governing, and where the gaps are. Phase two: build the core foundations. We then put the controls, records and evidence in place so Epocha could answer its stakeholders' AI-assurance questions and show it governs its AI use ethically and responsibly.

Outcomes

Epocha now has a clear view of where AI sits in its business. A register of its AI tools and systems, together with a determination of its role in the AI supply chain, tells the founders which obligations apply to them. AI, privacy, regulatory and information-security risk are now managed in a single, integrated view. A control framework aligned to ISO/IEC 42001 and ISO/IEC 27001 is sized for a business of Epocha's scale. Its AI policy is built around its own regulatory position, business objectives, AI tools, data and services. And Epocha owns a sequenced roadmap for what comes next, which it is already putting into practice. AI-assurance questionnaires are starting to appear in procurement and funding processes, especially in sectors like education, and Epocha can now answer them with real evidence.

2 phases
Baseline, Then Build
Stop-after-phase-one option; the phase-one fee is credited to the build
AI × Privacy × InfoSec
Integrated Risk Register
One register that surfaced missing critical controls

An AI-first company that saw ISO-42001 implementation as a brake

The client describes itself as an "AI-first company". It is re-designing its entire business model around AI capabilities, and its new core offering would not exist without AI. When we first raised AI governance aligned with ISO/IEC 42001, the reaction was skeptical, and the priorities were stated plainly: keep building, and run a more aggressive go-to-market.

Reframing: governance as an accelerant, not a brake

The task was to show that a lightweight, ISO/IEC 42001-aligned governance baseline - with no certification - implemented now would support those two priorities rather than compete with them. Two arguments carried the case.

1. It surfaces failure modes and risks faster while you build

For an AI-first company, AI risk is business risk. You don’t want to accumulate it.

2. It helps you scale better and sell faster

So we went looking for the client’s peers and compiled a list of ISO/IEC 42001-certified organisations. In all transparency, they were very few — and the research did not surface ISO 42001-aligned-but-not-certified organisations either. The signal is clear: it is still rare enough to be a differentiator.

If you market or position yourself as an AI-first company, providing assurance around the responsible use and governance of your AI systems is not an optional consideration. It is part of your offer.

The engagement: a two-phased approach

We structured the work in two phases. First, we set the baseline: a clear, evidenced picture of where AI lives in the organisation, what is to be governed or not, where the gaps are, and what fixing them will involve.

01 · Setting the baseline with the organisation’s AI Footprint Map

The goal was for the business to know exactly where AI lives in their organisation, what’s theirs to govern, where the gaps are, and what fixing them will involve.

What Was DeliveredWhat It Included
AI-footprint process mapA visual document capturing all processes, identifying and showing where AI is used in those processes, by whom, how and why.
AI & systems registerThe operational inventory and single source of truth of the organisation’s AI assets. Referenced in organisational policies (e.g. the list of authorised AI tools in the AI policy).
Supply-chain role determinationClarify which roles (AI producer, AI deployer, AI customer, AI subject) our client serves in the supply chain, to target controls that are actually relevant to them.
Draft build scope + fixed-price proposalAn evidence-based, fixed-price plan to take the findings of the first phase and implement actionable, compliant and auditable AI governance controls.

02 · Implementing core foundations: AI Governance Build (aligned with ISO/IEC 42001)

Put the controls, records, and evidence in place so our client can answer their buyers’ AI-assurance questions and prove their organisation governs AI safely and responsibly.

What We DeliveredWhat It Included
Integrated risk register (AI × Privacy × InfoSec)One register that covers AI, privacy and security risk so our client stops unknowingly stockpiling business risk.
Controls implementationImplementation of the risk treatment plan and key controls.

The takeaway

A lightweight, ISO/IEC 42001 baseline did not slow the build or the go-to-market motion. It de-risked both by surfacing missing critical controls before they became incidents, and turning AI assurance into a sales asset in a competitive market where it is still rare enough to stand out. For a company whose offering would not exist without AI, governing that AI is not overhead. It is part of the product.