top of page
Search

ISO 27001 & ISO 42001 for Clinical AI: What the MHRA's 2026 Report Means

  • Jun 16
  • 7 min read

GxP got you this far. ISO 27001 and 42001 are what keep you trading.


On 11 June 2026, the MHRA published two reports with a great many quotation marks. It's our job to read them so you don't have to.


The headline act was the National Commission's Call for Evidence summary of findings, a document built from the views of 761 people and organisations who voluntarily spent their evenings telling the government how AI in healthcare ought to be regulated, not how I would spend my evening, but there you go, someone has to do it.


Jokes aside, these documents matter. They are the clearest signal yet of where UK regulation of clinical AI is heading, and they quietly expose a gap that traditional GxP compliance will not fill on its own. The National Commission's actual recommendations are due in the summer of 2026, and the MHRA has been refreshingly honest that these findings will shape them, so this is less a leak and more a polite warning.


What the report actually says

The Call for Evidence drew responses from patients, the public, clinicians, providers, academics and industry. A few themes should make anyone with an AI product in the clinical market sit up and pay attention. The ones that drew my attention were:


  • The current framework is widely seen as not built for AI. 

Across every respondent group, a majority wanted at least significant reform. The rules were designed for medical devices that sit still and behave themselves; AI does neither. As one industry respondent put it, the framework "was not designed for AI systems that are adaptive, probabilistic, multi-use," and capable of changing after deployment. Which is a tactful way of saying we built a cage for a tortoise, then released a swarm of learning software products into it, and expected them to behave. See what we did there about the buzz around AI? No... well, I try to make compliance interesting.


  • Data governance is the flashpoint. 

Asked whether the framework is sufficient on data governance and privacy, 82% of patients and the public said it was not. The public has noticed that "we'll handle your most sensitive data responsibly" is a sentence, not a control.


  • One-off approval is over; lifecycle monitoring is in. 

There was strong consensus that AI performance can't be judged by a single pre-market tick box, and that products need continuous, real-world post-market surveillance to detect performance drift. The model you certified in January isn't necessarily the one you're running in June, and everyone has finally said so out loud. From what we've seen with our early-adopter clients and AI developers, the version they wrote and pushed to production this morning isn't behaving the way we expected by lunchtime, and by the evening, it's broken into the employees' fridge and stolen someone's sandwich.


  • Accountability must be structured, not improvised. 

Respondents rejected the idea of quietly dumping liability onto the nearest clinician, calling instead for robust governance structures, clear organisational responsibility, and explicit duties shared among manufacturers, providers, and clinicians. They went so far as to suggest that saying "Someone will own this" is not a governance model. Which is something we see so much of; it's painful. We recently ended our engagement with a client, for the first time ever, after they automated everything to the point that during an audit, they couldn't even name one of their top three risks, the AI had generated them for them... that's not governance, it's barely even compliance theatre, it's a fine waiting to happen.


  • Human oversight, transparency and AI literacy run throughout.

The report stresses retained clinical judgement, plain-English explainability, and trained governance teams who understand AI-specific risks, noting that without that literacy, automation bias becomes a genuine patient-safety problem. Translation, a human "checking" an output they don't understand is not oversight. Do your current QA and QC teams understand what they are approving?


Why GxP alone no longer covers you

GxP, GCP, GMP, GVP and the rest of the alphabet remain essential, and nothing here says otherwise. It governs how trials are run, how products are made, and how safety signals are handled. But GxP was designed for medicines and comparatively well-behaved devices. It was not designed to govern an algorithm that learns, drifts, and develops opinions in the field that it didn't have at the time of approval.


Hold the MHRA's findings up against your GxP framework, and the gaps are not subtle. GxP doesn't provide a structured information-security regime for patient data that the public is so visibly nervous about. It doesn't provide a management system to govern an AI model throughout its lifecycle, monitor drift, or document algorithmic risk and human-oversight controls. And it does not, by itself, evidence the "robust governance structures" the report says providers now expect. You can be flawlessly GxP-compliant and still have no defensible answer to "how is your model governed?" which is awkward, because that is now the question everyone is asking, and from experience, don't just point to your CTO or IT team and expect them to have the answer.


This is where two certifiable ISO standards earn their keep, and, mercifully, they bolt onto your existing quality system rather than forming a rival empire beside it, and yes, it just so happens that's what we specialise in at TQC, I mean, you didn't think I followed and read these reports for fun? There was not even one dragon in either of them.


Where ISO 27001 fits

ISO/IEC 27001 is the international standard for an information security management system, and it maps almost embarrassingly neatly onto the data concerns the MHRA raised: access control, encryption, data classification, and, crucially for clinical AI, control over the third parties and processors handling patient data. If the strongest public objection is to how commercial entities handle NHS data, a certified ISMS is the auditable answer to "how do we know the vendor did their homework?"


Where ISO 42001 fits

ISO/IEC 42001 is the world's first certifiable AI management system standard, and it reads almost as if someone wrote it after attending the same meetings the MHRA did. It requires organisations to assess AI impacts, govern systems across their lifecycle, define clear roles and accountability, build in human oversight, and monitor performance after deployment. In other words, it turns the report's wish list, lifecycle surveillance, distributed accountability, transparency, and AI literacy into a system that the auditor can actually certify, rather than a values statement on a website.


It also stacks cleanly with what you already run. ISO 42001 shares the Annex SL structure with ISO 27001 and ISO 9001. One integrated management system, not three standards in a trench coat pretending to be a strategy. Please tell me you spent some time picturing this? I know I did... the hat and fake moustache were a nice touch.


Compliance vs a new Moss Wall?

Right now, ISO 42001 isn't mandatory, and the MHRA's framework is still being drafted. The temptation is to wait, on the time-honoured principle that compliance is tomorrow's problem. We know you have a limited runway, but spending it on compliance rather than a fancy moss wall for the office could make or break you, and here's why:


  • First, procurement is already running ahead of regulation; the NHS routes increasingly expect demonstrable AI governance before a product gets near a patient, regardless of what the final rules say.


  • Second, the penalties coming over the hill are not gentle. Under the EU AI Act, Article 99 sets administrative fines of up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% of turnover for breaching provider and deployer obligations, the tier that most health AI products fall into.


Any UK firm placing AI on the EU market is in scope, Brexit notwithstanding. And while the headline figures are designed to terrify multinationals, the Act flips the maths for SMEs and start-ups so the lower of the fixed sum or the percentage applies, which sounds merciful until you realise a six-figure penalty can still quietly end an early-stage company. I know a six-figure fine would kill TQC dead. Would your start-up recover from that?


To be clear, certification doesn't make you immune to enforcement. What it does is evidence that you took reasonable, structured, auditable steps to manage the risk, which is the difference between a defensible position and a very expensive conversation with a regulator who has already read your incident log and decided you're guilty. Saying we planned to implement that later or that we didn't have the funds isn't a defence. And that pretty moss wall... well, most of that has dried up or been picked off by your employees already, and that money could have kept you trading. I'm not here to tell you how to run your business, but I can make satirical observations and hope you make the right choice...


The takeaway

The MHRA report doesn't mandate ISO 27001 or 42001. What it does is describe, in the words of 761 people who clearly care, precisely the risks these standards were built to manage: data governance, lifecycle monitoring, accountability, transparency and oversight. GxP remains necessary. It is simply no longer sufficient. We honestly believe that the organisations that treat AI governance as something to certify now, rather than retrofitting it after the first complaint or fines, will be the ones still selling into healthcare in three years' time.


If you're building or deploying AI in the clinical space and want to understand how ISO 27001 and ISO 42001 sit alongside your existing GxP and quality systems, that's precisely the gap Tiller Quality Consulting was built to close, ideally before the regulator helps you find it. Go on, let's have a chat, what do you have to lose?


References

European Parliament & Council of the European Union. (2024). Regulation (EU) 2024/1689, 13 June 2024, laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). https://artificialintelligenceact.eu/article/99/


Medicines and Healthcare products Regulatory Agency. (2026a, June 11). MHRA landmark report reveals public views on AI in healthcare. GOV.UK. https://www.gov.uk/government/news/mhra-landmark-report-reveals-public-views-on-ai-in-healthcare


Medicines and Healthcare products Regulatory Agency. (2026b). National Commission into the Regulation of AI in Healthcare: Call for evidence summary of findings. GOV.UK. https://www.gov.uk/government/publications/national-commission-into-the-regulation-of-ai-in-healthcare-research-engagement-and-call-for-evidence-findings

 
 
 

Comments


Copyright © 2026 Tiller Quality Consulting. All rights reserved. TQC is a company registered England and Wales Company No.15546928.
167-169 Great Portland Street
5th Floor
London
W1W 5PF

VAT registration number 481548273

bottom of page