Neil Jones

Neil Jones

Senior Consultant at URM

Neil is a Senior Consultant at URM, with over 20 years of ‘real world’ information security knowledge and experience, having worked in complex telecommunications, (multinational) financial services and professional services environments, with both regional and global responsibilities.  Neil has considerable experience encompassing internal audit and a wide range of technical platforms, security standards, SOX, and risk and control supported by a strong background in compliance, development and consultancy.  With URM, Neil has worked closely with a global organisation to review and align its control framework, establishing an effective auditing and testing regime and transition to ISO 27001:2022.  He has also worked with a variety of clients to establish their conformance to ISO 27001, conducting ISO 27001 internal audits, and providing consultancy advice and guidance on achieving an effective governance approach.

InfoSec Insider
Season
2
, Episode
8

AIIAs in ISO 42001

In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, explores artificial intelligence impact assessments (AIIAs), a key conformance activity required by ISO 42001, the International Standard for AI Management Systems (AIMS).  Neil leverages over 20 years of experience working with risk and information security-related standards to discuss:

  • What an AIIA is under ISO 42001, and how it differs from a typical risk assessment
  • The role of ISO 42005 and how it relates to AIIAs
  • The seven sections of an AIIA and what each section covers
  • When in the AI lifecycle you need to conduct an AIIA
  • How organisations should balance AIIAs with risk assessments in the context of ISO 42001.
Learn more about this topic
InfoSec Insider
Season
1
, Episode
15

ISO 42001 and AI Perspectives

In this episode of InfoSec Insider, Neil Jones, Senior Consultant at URM, breaks down the purpose and structure of the recently released ISO 42001, the International Standard for Artificial Intelligence Management Systems (AIMS), as well as explaining the Standard’s use of AI ‘perspectives’.  Neil leverages his 20+ years’ working with a range of risk and information security-related standards to discuss:  

  • What ISO 42001 is intended for, and what it is not
  • How ISO 42001 is structured, and how it compares to other standards written in the ‘Harmonised Structure’
  • What an AIMS is
  • How you can establish the ‘trustworthiness’ of an AI system and how this concept is articulated through ‘AI perspectives’ in ISO 42001.
Learn more about this topic