Product
ISO 27001
Industry
Sustainability Technology, Digital Product Passports, Life Cycle Assessment
Engagement Length
10 Months
Location
Manchester, United Kingdom
Outcome
Successful ISO 27001 certification for both entities, with Drata at 100% control compliance
At a Glance
ISO 42001 certified, maintained through two surveillance cycles, with 15 days of consulting time across the full audit lifecycle.
Every nonconformity logged in a structured NC register from the first audit.
Corrective actions closed within the required three-month windows.
- Challenge: Lucidya wanted to align with ISO 42001 but had no clear picture of where its AI Management System stood or which gaps separated it from certification.
- Solution: Axipro ran a readiness-aligned audit to log every nonconformity, then guided Lucidya through Stage 1, corrective actions, Stage 2, and two surveillance cycles.
- Results: ISO 42001 certification with continuity across surveillance cycles, full gap visibility through a structured NC log, and remediation that runs on predictable timelines.
The Company
Lucidya is an AI-native customer experience management platform headquartered in Riyadh.
The platform captures customer conversations across social media, support channels, and surveys and turns them into insights, with Arabic sentiment analysis covering more than a dozen dialects. Its customers include enterprises and government organizations across the GCC.
For Lucidya, AI governance isn’t a box to tick. AI is the product. The company raised a $30 million Series B in 2025 and launched an Enterprise AI Agent platform in 2026, putting autonomous agents into customer service operations for clients in regulated markets.
When your software makes decisions on behalf of government entities and large enterprises, those customers want evidence that the AI behind it is properly governed. ISO 42001, the international standard for AI management systems, is how you show them.
01- THE CHALLENGE
No Clear Path to ISO 42001 Certification
Lucidya knew where it wanted to end up. What it couldn’t see was the distance. The team had no structured way to tell which clauses of its AI Management System (AIMS) were already compliant, which needed improvement, and what a realistic path to certification looked like.
Most companies wait until they believe they’re ready before letting an auditor in. Lucidya took the opposite approach: go through an official audit before full readiness, on purpose, and use it to log every nonconformity. That turns the audit from a pass-fail exam into a diagnostic. It’s a smart move, but it only works with a guide who has run the full lifecycle before and can convert an NC log into a working corrective action plan. That’s where Axipro came in.
- Conducted an official audit before full readiness.
- Used the audit to identify every nonconformity (NC).
- Treated the audit as a gap assessment rather than a final exam.
- Created a clear roadmap for compliance improvements.
- Converted the NC log into a practical corrective action plan.
- Guided Lucidya through the full path to certification.
02- THE ENGAGEMENT
From Readiness Audit to Ongoing Compliance
● An audit before readiness
Axipro started with a readiness-aligned audit built to surface and log every nonconformity in Lucidya’s AIMS, giving the team a clear compliance baseline. From there, Axipro guided Lucidya through the Stage 1 audit even though the company wasn’t yet fully ready.
The immediate payoff was visibility. Instead of a vague sense that gaps existed somewhere, Lucidya had a structured NC log showing exactly which clauses were compliant and which needed corrective action, in priority order.
● Closing gaps on the clock
Certification audits come with deadlines. Corrective actions had to be executed within the required three-month windows, so Axipro worked with Lucidya to plan and close them inside those windows, then supported the team through Stage 2 to make sure the remaining gaps were addressed.
Corrective action planning, previously the murkiest part of the process, became faster and more organized. The team knew what to fix, in what order, and by when.
● Keeping the certificate alive
An ISO 42001 certificate isn’t a one-time achievement. Surveillance audits follow, and a lapse can cost you the certificate. Axipro provided ongoing compliance oversight through Surveillance One and Surveillance Two, helping Lucidya maintain its AIMS clauses and validate corrective actions along the way. Once Lucidya reached full compliance, Axipro made sure the certificate carried through without interruption.
03- THE RESULTS
From Uncertainty to Audit Confidence
The clearest change is that Lucidya now knows exactly where it stands. Gap visibility improved dramatically once the structured NC log replaced guesswork, and AIMS maintenance now runs systematically against ISO 42001 expectations rather than ad hoc.
Audit readiness is significantly higher, with predictable timelines and clear remediation workflows the team can repeat. Because surveillance cycles follow an established rhythm, keeping the certificate current is a manageable routine instead of a scramble.