Exploring Standards with Assent

Assent Risk Management

Assent Risk Management is a progressive Risk and Resilience Consultancy built for the digital age. We pride ourselves on Championing International Standards and in this podcast we will be talking to experts from the consultancy industry, discussing standards, ISO’s, consulting and everything in between, to bring you industry knowledge and updates.

  1. APR 8

    How to build a security culture using ISO 27001 with Tobias Mielke

    In this episode of Exploring Standards, host Jess sits down with Tobias Mielke, Global Product Manager at TÜV Nord, to explore one of the most overlooked dimensions of information security - culture. While many organisations treat ISO 27001 as a compliance checkbox, Tobias makes the case that the standard is actually a powerful framework for embedding security into the DNA of your organisation. From phishing emails to access controls, real security starts with how people think and behave when no one is watching.   What You'll Learn What ISO 27001 is and why every organisation, regardless of size or sector,  needs to take information security seriously The difference between having security policies and actually having a security culture Why leadership buy-in isn't just helpful,  it's essential for any ISMS to succeed How the risk assessment process helps employees understand their personal role in protecting information Which Annex A controls typically require the biggest cultural shift (and why access management and incident reporting top the list) How to embed security controls into daily habits rather than treating them as annual compliance exercises The real-world external benefits of a strong security culture, from customer trust to commercial advantage How to measure whether your security culture is genuinely improving, not just audit-ready The single most important first step any organisation can take tomorrow to start building a real security culture   Key Takeaway Security culture isn't built through policy documents,  it's built through people. When leadership visibly champions information security as a business priority, and when employees understand the why behind the controls, ISO 27001 transforms from a compliance label into a practical roadmap for lasting organisational change.   About Tobias Tobias Mielke is Global Product Manager at TÜV Nord Group, based in Germany, where he oversees the technical development and ongoing support of a portfolio of management system standards, including ISO 27001 (Information Security Management Systems), ISO 27701 (Privacy Information Management), ISO 22301 (Business Continuity Management), and ISO 42001 (AI Management Systems). In addition to his product management role, Tobias works as an ISO Lead Auditor for information security and related standards, with hands-on experience certifying organisations across multiple sectors, including critical infrastructure.   Connect with Tobias: Website: https://www.tuv-nord.com/uk/en/ LinkedIn: www.linkedin.com/in/tobiasmielke Connect with Assent: LinkedIn: https://www.linkedin.com/company/associate-enterprises-ltd-t-a-assent/ Facebook: https://www.facebook.com/assentuk Youtube: https://www.youtube.com/channel/UCWw6ny-YyfkxdGm7ig4yFoQ Instagram: @assentriskmanagement Subscribe for more episodes exploring standards, compliance, and governance topics!

    30 min
  2. MAR 25

    ISO 7101 Explained: Enhancing Healthcare Quality and Compliance with Cornelia Campbell-Swart

    In this episode of Exploring Standards, host Jess sits down with Cornelia Campbell-Swart, a healthcare compliance and safety professional with over 15 years of experience, to break down ISO 7101, the first ISO standard written specifically for healthcare organisations.   What You'll Learn What ISO 7101 is and why it's a landmark standard for global healthcare Which healthcare organisations benefit most, from large hospitals to small doctors' rooms The biggest mistakes to avoid when starting implementation (spoiler: don't start with policies!) The key processes and structures needed to meet ISO 7101 requirements How ISO 7101 compares to, and can replace, ISO 9001, 14001, and 45001 What to monitor, including patient satisfaction and incident tracking How to build a system that works for your organisation, not against it   Key Takeaway Start where you are. ISO 7101 isn't about adding extra work or ticking boxes; most organisations are already doing much of what's required, just without structure. Build on what you have, involve your people, and let the system work for you.   About Cornelia Campbell-Swart Cornelia is a healthcare compliance and safety professional based in South Africa with over 15 years of experience. She works with standards including ISO 14001, ISO 9001, ISO 45001, and ISO 7101, and is passionate about improving health, safety, and quality across healthcare facilities of all sizes. A nurse by heart, Cornelia brings a practical, people-first approach to quality management.   Contact Cornelia Campbell-Swart LinkedIn: https://www.linkedin.com/in/cornelia-campbell-swart-a98b1b137/ Website: www.optimalsolve.com Mobile: 071 803 9532 Telephone: 011 513 4141 Email: health@optimalsolve.com   Connect with Assent: LinkedIn: https://www.linkedin.com/company/associate-enterprises-ltd-t-a-assent/ Facebook: https://www.facebook.com/assentuk Youtube: https://www.youtube.com/channel/UCWw6ny-YyfkxdGm7ig4yFoQ Instagram: @assentriskmanagement Subscribe for more episodes exploring standards, compliance, and governance topics!

    15 min
  3. MAR 11

    Understanding IATF 16949: The Automotive Quality Standard Explained with Gary Beales

    In this episode, host Jess sits down with Gary Beales from UTAC, an expert in management systems and certification implementation for the automotive sector, to explore IATF 16949, the international quality management standard designed specifically for the automotive industry. What You'll Learn: What IATF 16949 is and why it matters for organisations in the automotive supply chain How the standard builds on ISO 9001 and the key differences between the two The commercial and operational benefits of implementing IATF 16949 How certification can help organisations access global automotive markets and win tenders Where companies typically see return on investment from implementing the standard The process for organisations looking to upgrade from ISO 9001 to IATF 16949 Whether businesses should run ISO 9001 and IATF 16949 in parallel The role of accreditation bodies and how global recognition works for certification Key Takeaway: IATF 16949 is more than just an upgrade from ISO 9001 - it’s a specialised automotive quality framework that helps organisations strengthen processes, improve efficiency, and unlock opportunities within the global automotive supply chain.   About Gary: Gary Beales is an Account Manager at UTAC. With extensive experience in management systems and certification since 2012, Gary supports organisations looking to implement and maintain certification frameworks, particularly within the automotive sector. His expertise helps businesses understand the value of management systems and navigate the certification process effectively.   Connect with UTAC: UTAC Certification | ISO & IATF for Automotive Suppliers UTAC: Posts | LinkedIn   Connect with Gary: LinkedIn: https://www.linkedin.com/in/gbeales/ Phone: 07974 068 768 Email: gary.beales@utac.com   Connect with Assent: LinkedIn: https://www.linkedin.com/company/associate-enterprises-ltd-t-a-assent/ Facebook: https://www.facebook.com/assentuk Youtube: https://www.youtube.com/channel/UCWw6ny-YyfkxdGm7ig4yFoQ Instagram: @assentriskmanagement Subscribe for more episodes exploring standards, compliance, and governance topics!

    29 min
  4. FEB 25

    Plain Language Standard ISO 24495 with Frances Gordon: Making Communication Clear in the Age of AI

    In this episode of Exploring Standards, host Jess sits down with Frances Gordon, a content strategist and plain language expert who has been a contributor to ISO 24495 - the international plain language standard. With nearly three decades of experience, Frances shares insights from the recent Brussels Plain Language Experience and breaks down what plain language truly means beyond just "simple words." We explore: The comprehensive definition of plain language (wording, structure, AND design) How plain language is more than a checklist and addresses how AND what you communicate The upcoming requirements standard in development Plain language's critical role in the age of generative AI How ISO 24495 helps financial services meet consumer duty requirements Why terms and conditions deserve special attention Real-world case studies showing business benefits Frances offers practical guidance on using AI tools responsibly for plain language work, emphasising that while AI can help scale processes, it cannot replace human expertise in understanding audiences, context, and regulatory requirements. She also discusses the ethical dimensions of plain language and why it's essential for vulnerable populations.   Guest: Frances Gordon, Content Strategist at Narratology and ISO Plain Language Standards Expert Resources mentioned: ISO 24495 Plain Language Standard Plain Language Association International (plain language organisation) "Writing for Dollars, Writing to Please" by Joseph Kimble Cooley Law School plain language resources Clarity International (plain legal language organisation) Contact Frances: Frances Gordon - Narratology www.narratology.co.uk Plain language assessment tool | Narratology   Connect with Assent: LinkedIn: https://www.linkedin.com/company/associate-enterprises-ltd-t-a-assent/ Facebook: https://www.facebook.com/assentuk Youtube: https://www.youtube.com/channel/UCWw6ny-YyfkxdGm7ig4yFoQ Instagram: @assentriskmanagement

    39 min
  5. FEB 11

    Exploring ISO 22000: The Global Food Safety Standard Explained with Sandra Chalhoub

    In this episode, host Jess sits down with Sandra Chalhoub, a food safety expert specialising in ISO 22000, to explore the international standard for food safety management systems. What You'll Learn: What ISO 22000 is and why it matters in today's global food supply chain How climate change and globalisation are creating new food safety challenges The difference between ISO 22000, FSSC 22000, BRC, and SALSA standards How small businesses vs. large manufacturers implement the standard differently Why ISO 22000 is the foundation for FSSC 22000 certification How the standard integrates HACCP principles into a complete management system Common implementation mistakes and how to avoid them Practical first steps for organisations starting their ISO 22000 journey Key Takeaway: ISO 22000 is flexible, scalable, and internationally recognised, making it ideal for organisations of all sizes across the entire food supply chain, from farming to catering. Whether you're in food manufacturing, catering, logistics, or quality management, this episode offers valuable insights into building a robust food safety culture. About Sandra: Sandra is a quality and food safety professional specialising in ISO 22000, HACCP, and Food Safety Management Systems. With extensive experience working as a QA/QC professional across different types of food businesses, Sandra transitioned into consulting to help organisations implement effective food safety standards. She currently works as a self-employed ISO 22000 consultant in the UK, bringing her practical expertise to businesses of all sizes across the food supply chain.  Connect with Sandra: LinkedIn - https://www.linkedin.com/in/sandra-chalhoub-40726874 Email - schalhoubrouhana88@gmail.com   Connect with Assent: LinkedIn: https://www.linkedin.com/company/associate-enterprises-ltd-t-a-assent/ Facebook: https://www.facebook.com/assentuk Youtube: https://www.youtube.com/channel/UCWw6ny-YyfkxdGm7ig4yFoQ Instagram: @assentriskmanagement   Subscribe for more episodes exploring standards, compliance, and governance topics!

    21 min
  6. JAN 28

    ISO 27001 vs ISO 42001: AI Governance & Information Security Explained with Dan Sampson

    Welcome to Exploring Standards! In this episode, host Jess sits down with Dan Sampson, a GRC consultant and certified lead auditor specialising in ISO 27001 and ISO 42001, to explore the intersection of information security and AI governance.   What You'll Learn: The key differences between ISO 27001 (information security) and ISO 42001 (AI governance) How these two standards complement each other and where they overlap Critical gaps that ISO 42001 fills that ISO 27001 doesn't address Which standard should your organisation implement first When ISO 42001 is necessary vs. when ISO 27001 alone is sufficient Common misconceptions about AI security and governance Practical advice for organisations considering certification Key Takeaway: ISO 27001 prevents your data from being stolen, while ISO 42001 prevents your data from being used unfairly or unpredictably by AI systems. Together, they provide comprehensive protection for organisations deploying AI.   About Dan Sampson: Dan is a GRC consultant specialising in information security and responsible AI governance through his company, Sampson ISO Audit and Consult Limited. With extensive experience at the University of Sheffield and now as an independent consultant, Dan helps organisations align their information security practices with responsible AI deployment.   Connect with Dan: LinkedIn - www.linkedin.com/in/daniel-s-31775b205   Website - www.sampsoniso.co.uk   Connect with Assent: LinkedIn: https://www.linkedin.com/company/associate-enterprises-ltd-t-a-assent/ Facebook: https://www.facebook.com/assentuk Youtube: https://www.youtube.com/channel/UCWw6ny-YyfkxdGm7ig4yFoQ Instagram: @assentriskmanagement   Subscribe for more episodes exploring standards, compliance, and governance topics! #ISO27001 #ISO42001 #AIGovernance #InformationSecurity #Compliance #CyberSecurity #AIEthics #DataProtection #GRC #Standards

    24 min
  7. 09/17/2025

    Artificial Intelligence & ISO 42001 with ISOQAR

    In the final episode of Season 3 of Exploring Standards, host Jess is joined by two special guests: Kirsty Wakefield, Information Security Sector Manager at ISOQAR, and Rob Clements, CEO & Director of Assent. Together, they explore one of the most talked-about topics in today’s business world, Artificial Intelligence (AI), and the emerging international standard ISO 42001. Kirsty Wakefield is the Information Security Manager at ISOQAR, where she leads on strengthening information security practices and ensuring compliance with international standards. With expertise in frameworks such as ISO 27001 and emerging standards like ISO 42001, Kirsty supports organisations in building robust governance, risk, and compliance strategies. She plays a key role in helping businesses achieve certification, embedding a culture of trust, accountability, and resilience in their operations. The discussion begins with an introduction to ISO 42001, why it was created, and how it differs from other well-known standards like ISO 27001 and ISO 9001. Kirsty and Rob explain why AI governance and ethical use are becoming critical for organisations across all sectors, not just tech-heavy industries. They also highlight the main risks of unmanaged AI that the standard helps to address, from transparency and fairness to accountability and compliance. Listeners will also gain insight into the value of ISO 42001 certification, including how it builds trust with customers and regulators, integrates with existing management systems, and ensures that AI remains ethical and effective. The episode wraps up with practical advice on how organisations can prepare internally for an ISO 42001 audit, and what the process involves from a certification body perspective.   Contact Assent: Website: www.assent1.com Email: desk@assent1.com Connect with Assent: LinkedIn: https://www.linkedin.com/company/associate-enterprises-ltd-t-a-assent/ Facebook: https://www.facebook.com/assentuk Youtube: https://www.youtube.com/channel/UCWw6ny-YyfkxdGm7ig4yFoQ Instagram: @assentriskmanagement   Contact ISOQAR LinkedIn: https://www.linkedin.com/company/isoqar/ Instagram: ISOQAR_UK Facebook: ISOQAR UK Email: certification_sales@alcumus.com Explore ISOQAR’s dedicated ISO 42001 campaign page to access a free AI eBook, expert blogs, gap analysis tool, and more resources to guide your AI governance journey: http://bit.ly/4mRhYmt

    40 min

About

Assent Risk Management is a progressive Risk and Resilience Consultancy built for the digital age. We pride ourselves on Championing International Standards and in this podcast we will be talking to experts from the consultancy industry, discussing standards, ISO’s, consulting and everything in between, to bring you industry knowledge and updates.