Home/Customer cases/Glims.ai

ISO 27001Glims.ai

Glims.ai and ISO 27001: how an AI startup got compliance right

ISO 27001 certified within months, without slowing down product development

As an AI company delivering audit automation and intelligence to accounting firms and auditors, trust isn't a nice-to-have, it's an absolute prerequisite. Clients entrust Glims.ai with their most sensitive data. That means you need to demonstrate that your information security is organised at the highest level.

In January 2026, Glims.ai successfully achieved their ISO 27001 certification. A remarkable achievement for a young company. In this article, we share the story behind the journey: the challenges, the approach, and the lessons for other tech and AI companies.

About Glims.ai

Glims.ai is an AI platform that automates audit processes end-to-end. The company helps accountants and auditors work more efficiently and more accurately by deploying audit-specific AI technology.

The market in which Glims.ai operates, the accounting and audit sector, is precisely an environment where information security and compliance are non-negotiable. Clients expect the tooling they use to maintain at least the same security standards they must adhere to themselves.

“Our clients work with confidential data every day. When we use that data or apply AI to that data, the security of our platform must be beyond question. ISO 27001 certification wasn't a choice for us, it was a necessity.”

Evanthia Valera, Glims.ai

The challenge: a young company, a high bar

Implementing ISO 27001 at a startup brings unique challenges. Where established organisations have built up years of process history and documentation, Glims.ai largely started with a clean slate.

That might sound like an advantage, no legacy, no outdated processes, but it also means there is little demonstrable evidence. And that's exactly what ISO 27001 demands: not just that you do things well, but that you can prove you do them well.

For a young company in full development, this means:

  • Formalising processes that were previously implicit. "That's how we do things here" must be documented in policies and procedures.
  • Building up and organising evidence: logs, review reports, risk assessments, everything must be documented.
  • Maintaining speed: a startup cannot afford to stand still for months for compliance.
  • Addressing AI-specific risks: how do you handle the privacy of client data processed by AI systems?

The approach: pragmatic and focused

Glims.ai's compliance journey was guided by Stephan Brinkhuis from uComply.cloud. The approach was deliberately pragmatic: no unnecessary bureaucracy, but focus on what truly adds value and is needed for certification.

Step 1: Baseline assessment and gap analysis

First, we mapped where Glims.ai stood relative to the ISO 27001 requirements. Which processes were already (implicitly) in place? Where were the gaps? And which risks had the highest priority?

Step 2: Setting up the ISMS

The Information Security Management System (ISMS) was set up with a scope that matched the size and type of organisation. Not an oversized framework, but a lean system that grows with the company.

Step 3: Risk assessment

The risk assessment specifically focused on the context of an AI platform: data processing, cloud infrastructure, access management, and the security of AI models. This is where the journey differs from a traditional implementation.

Step 4: Policies and procedures

All necessary policies and procedures were drafted, from information security policy to incident management, from access control to supplier management. Always with the question: is this workable for a small, fast-moving team?

Step 5: Implementation and evidence gathering

The most challenging part for a young company: demonstrating that processes don't just exist on paper but are actually followed. This required discipline and a structured approach to documentation and logging.

Step 6: Internal audit and certification audit

After the internal audit, in which we identified the final improvement points, the external certification audit followed. Successfully.

Why this achievement is remarkable

Achieving ISO 27001 certification as a young company is impressive. The standard demands demonstrable evidence that normally grows organically over years of business operations. Glims.ai had to build this in a short time, parallel to daily operations and product development.

That they succeeded says a lot about the organisation:

  • Commitment from leadership: the entire team supported the journey.
  • Willingness to formalise processes, even when it sometimes clashes with the startup mentality of rapid iteration.
  • Technical maturity: the underlying architecture and security measures were already solid; they just needed to be formally documented.

“The certification process didn't just give us a certificate, it also gave us much better insight into our own processes. We now work in a more structured way.”

Evanthia Valera, Glims.ai

Lessons for other AI and tech companies

From the journey with Glims.ai, we distil several lessons relevant to any tech or AI company considering ISO 27001 implementation:

  1. 1Start earlier than you think. The sooner you start formalising processes, the easier it becomes to build evidence. Don't wait until a major client asks for it, because then you're under time pressure.
  2. 2It doesn't have to be a bureaucratic monster. ISO 27001 has an image problem. Many entrepreneurs think of thick binders and endless spreadsheets. The reality is that a pragmatic implementation, tailored to your organisation's scale, can be workable and even valuable.
  3. 3AI-specific risks require specific attention. Standard ISO 27001 templates don't always cover the unique risks of AI systems. Think about training data security, model governance, and the privacy implications of AI processing. Also consider ISO/IEC 42001 as a supplementary standard specifically for AI management systems.
  4. 4Choose a consultant who understands your business. Compliance advice from someone who doesn't understand how a tech startup works leads to a paper tiger. Find someone who knows the balance between what the standard requires and what's workable in your context.
  5. 5See it as an investment, not a cost. ISO 27001 opens doors. Enterprise clients, government organisations, and regulated sectors increasingly require certification. It's a competitive advantage that pays for itself.

The next step

With ISO 27001 as a foundation, Glims.ai has a solid basis for further growth. The logical next step for an AI company is ISO/IEC 42001, the international standard specifically for AI management systems. This standard addresses the ethical, transparency, and governance aspects of AI that are becoming increasingly important, especially with the EU AI Act now in effect.

Back to customers