Blog · AI · AI Policy · AI Strategy · Best Practice · ISO 42001

Five things every business should do before deploying an AI agent

Rob May · 15 August 2026
There are 5 things to do before you deploy any AI agentic work
There are 5 things to do before you deploy any AI agentic work

Five principles from ISO 42001 you should apply before deploying an AI agent or workflow.

Businesses are building AI agents and workflows faster than they're thinking about what could go wrong. That's not a criticism; it's an observation about where most organisations are right now. The tools are accessible, the use cases are obvious, and the pressure to move quickly is real. Governance tends to come later, usually after something has gone wrong.

ISO 42001 is the world's first international standard for AI management systems, and it was published in December 2023. It represents the considered thinking of a lot of serious people about what responsible AI governance actually requires, covering everything from leadership accountability and risk assessment to data management, transparency and ongoing monitoring.

For most small and medium-sized businesses, formal certification isn't a realistic ambition right now. The investment in time, documentation and audit preparation is significant, and for a business building its first AI workflow, that's not where the energy should go. But the fact that you shouldn't pursue the certificate doesn't mean there's nothing to learn from the standard.

Here are five principles from ISO 42001 that every business should apply before deploying an AI agent or workflow, regardless of whether certification is ever on the agenda.

1. Know exactly what you're deploying and what it touches

One of the foundational requirements of ISO 42001 is that organisations understand the context in which they're deploying AI. What systems are in use? What decisions are they influencing? Who is affected by those decisions? What are the risks if something goes wrong?

For most businesses deploying AI agents and workflows right now, this level of clarity doesn't exist. Tools get adopted because someone found them useful, workflows get built because they saved time, and the cumulative picture of what AI is doing inside the organisation, and what it has access to, isn't documented anywhere.

The principle worth borrowing here is simple: before you build or deploy, be able to answer the basic questions. What does this AI tool do? What data does it touch? What happens if it produces a wrong output? Who is accountable for the result? You don't need a management system to ask those questions. You just need to ask them.

2. Name someone who owns AI governance

ISO 42001 requires top management commitment, including establishing an AI policy, defining organisational roles and responsibilities, and ensuring adequate resources. In plain English: someone needs to own this. Not own the tools, not own the IT budget, but own the question of how AI is being used in the organisation and whether it's being used well.

In most SMEs, that ownership is genuinely unclear. AI adoption is happening in pockets, driven by enthusiastic individuals, with no one person holding a view of the whole picture. That's fine as a starting point. It's not fine as a permanent state, particularly as AI workflows start touching customer data, financial processes, or anything with regulatory implications.

The practical takeaway is to name someone. It doesn't need to be a full-time role or a new hire. It needs to be a person who is responsible for maintaining awareness of what AI is being used for, what the policies are, and what the risks look like. Without that, governance is nobody's job, which means it gets done by nobody.

3. Ask what goes wrong before you build, not after

The ISO 42001 standard requires organisations to identify and assess risks before deploying AI systems. This is not as burdensome as it sounds when you strip it back to its essentials.

The question every business should ask before building an AI agent or workflow is: what's the worst realistic outcome if this doesn't work as intended? If the answer is that a customer gets a slightly unhelpful email draft, the risk is low and the governance required is minimal. If the answer is that a client receives incorrect financial or legal information, the risk is significant and the safeguards need to reflect that.

Most AI governance failures in business don't happen because organisations ignored exotic edge cases. They happen because nobody asked the obvious question before deployment and nobody tested what happened when the AI encountered something it wasn't designed for. A five-minute conversation before you build is worth considerably more than a post-incident review after something goes wrong.

4. Be transparent, with customers and with yourself

Transparency is a core principle running through ISO 42001, and it shows up in practical ways: being clear with customers and employees when AI is involved in a process or decision, documenting how AI systems work so the organisation isn't dependent on one person's knowledge, and being honest about the limitations of the tools in use.

For businesses building customer-facing AI workflows, the transparency question is increasingly one of trust. Customers are becoming more sophisticated about AI, and the ones who feel misled about whether they're dealing with a human or a machine, or who discover that a recommendation was AI-generated without being told, are not forgiving about it. Being upfront is not just an ethical position. It's a commercial one.

Internally, transparency matters for a different reason. AI workflows that exist only in the head of the person who built them are a single point of failure. Document what your AI tools do, how they're configured, what data they use, and what the manual override process is. That documentation doesn't need to be formal or lengthy. It needs to exist.

5. Build review in from the start

ISO 42001 treats AI governance as an ongoing programme, not a one-time project. AI systems change. The models underlying the tools you use are updated. The data they work with shifts. The context in which they operate evolves. A workflow that works well today may produce different outputs in six months without anyone having touched it.

The businesses that manage AI well over time are the ones that build review into their process from the start. Not complex audits or formal assessments, just a regular habit of checking that the tools are still doing what they're supposed to do, that the outputs still meet the standard expected, and that nothing has changed in the environment that would affect how the AI behaves.

This is particularly important for AI agents that operate with some degree of autonomy, making decisions or taking actions without a human reviewing every step. The more autonomous the system, the more important it is to have a monitoring process that would catch a problem before it compounds.

You don't need a certificate to apply this thinking

These five principles share a common thread: AI governance should be deliberate, documented, and continuously improving. You don't need a certificate to apply that idea. You need the discipline to treat AI governance as a real organisational responsibility rather than something that happens informally in the background while everyone is focused on getting things done.

The failures are almost always the same: unclear ownership, insufficient risk assessment before deployment, no transparency about what AI is doing, and no process for catching problems once systems are live. None of those failures require a sophisticated AI system to occur. They happen in businesses using off-the-shelf tools to automate straightforward processes. And they're entirely preventable with a modest amount of structured thinking.

It just requires someone to take it seriously.


Frequently asked questions

Do small and medium-sized businesses need formal ISO 42001 certification?

Formal ISO 42001 certification is rarely a realistic ambition for small and medium-sized businesses building their first AI workflow. The required investment in time, documentation, and audit preparation is significant. However, organisations can still apply the core principles of the standard, such as risk assessment and transparency, without pursuing formal certification.

What is ISO 42001 and when was it published?

ISO 42001 is the world's first international standard for AI management systems, published in December 2023. It outlines key requirements for responsible AI governance, covering areas such as leadership accountability, risk assessment, data management, transparency, and ongoing monitoring to help organisations manage AI effectively.

Who should be responsible for AI governance in an organisation?

A named individual should own AI governance, though it does not require a new hire or a full-time role. This person is responsible for maintaining awareness of how AI is used across the business, ensuring policies are followed, and understanding associated risks, preventing governance from being ignored as AI adoption grows.

How should a business evaluate risk before deploying an AI agent?

Businesses should evaluate risk by asking what the worst realistic outcome is if the AI system fails. Low-risk tools, such as basic email draft generators, need minimal governance. Conversely, high-risk tools that output financial or legal information demand strict safeguards and thorough pre-deployment testing.

Why is continuous monitoring important for AI workflows?

Continuous monitoring is essential because AI systems, underlying models, data, and contexts change over time. A workflow that functions correctly today may produce inaccurate outputs in six months without any direct changes. Regular reviews ensure outputs consistently meet organisational standards and prevent minor errors from compounding.

Never miss an article

Get new articles by email

Whenever I publish something new on AI, cybersecurity and cyber resilience, I'll send you a link. No newsletters, no selling, and one click to stop at any time.

Your address is used only to send you new articles. See the privacy notice.