If you are the IT, security or data-protection lead reviewing an AI pool safety system, the short answer is this: ask the vendor for its ISO 27001 certificate, check that the certificate's stated scope actually covers the service you are buying, and confirm that the commercial contract — not just the marketing material — obliges the vendor to handle your footage in line with that certification. ISO 27001 is the international standard for an information security management system (ISMS), meaning a documented, audited set of controls covering how an organisation protects information, who may access it, and how incidents are handled. Lynxight is ISO 27001 certified, and its UK and Australian contract terms commit to securing customer data in accordance with that certification, which gives a reviewer a concrete clause to point at rather than a promise.
That contractual anchor matters because pool AI sits on top of cameras watching people in swimwear, frequently in publicly funded facilities, and the footage is personal data under the UK Data Protection Act, the GDPR and their equivalents in other jurisdictions where the technology operates. A certification alone does not discharge your duty as a controller: you still need retention periods, role-based access, an auditable trail of who viewed what, and a lawful basis recorded before a single camera is connected. Imperial College London publishes a public description of its Lynxight installation at the Ethos swimming pool, including its data policy that footage is automatically deleted after seven days unless it is needed for incident review — a useful reference point for the kind of specificity a written retention rule should reach. The steps below set out what to have in hand before you start, what to verify in order, and where reviews most often go wrong across a multi-site estate in 2026.
What exactly does an ISO 27001 certificate prove in a pooled AI vendor contract?
An ISO 27001 certificate proves exactly one thing: that an accredited auditor found the vendor running a documented Information Security Management System — an ISMS, meaning the governance framework of policies, risk assessments and controls that manage information risk — within a stated scope. It is a management-system certification, not a product test.
That distinction matters most in pooled or multi-tenant AI, where one vendor platform serves many operators and many sites from shared infrastructure. Per BlueFit Group, more than 50 BlueFit pools run Lynxight as standard — the kind of estate-wide deployment where the certificate's scope wording, not its existence, decides whether IT has assurance.
Which attributes on the certificate should IT read?
- Scope statement — values: a named legal entity plus named service lines, locations and infrastructure. Why it matters: if the pooled AI service or its cloud hosting sits outside the wording, the certificate covers something you are not buying.
- Certification body and accreditation mark — values: accredited body versus self-declared conformity. Why it matters: only an accredited audit carries independent weight in a supplier assurance file.
- Issue and expiry dates, plus surveillance status — values: current, suspended or lapsed. Why it matters: certification is a maintained cycle, not a permanent award.
- Statement of Applicability — values: each control applied, or excluded with written justification. Why it matters: exclusions reveal what was never assessed.
What does the certificate not cover?
It says nothing about model accuracy, video retention periods, tenant separation guarantees, or lawful basis under GDPR and the UK Data Protection Act. Those are verified in the contract and the DPIA, not the certificate.
Which certificate details should IT verify line by line before signing?
Restrict this step to the document itself: before signing, verify the certificate's details line by line rather than accepting a logo on a slide deck. ISO/IEC 27001 is the international standard for an information security management system — the documented set of controls governing how pool footage, staff records and access rights are handled. A certificate is only as good as the fields printed on it.
Check each of the following:
| Field on the certificate | What to verify | Why it matters |
|---|---|---|
| Accreditation body | The certification body is accredited by a recognised national accreditation body, not self-declared | Unaccredited certificates carry no independent oversight |
| Certificate number | The number resolves on the certification body's public register | Confirms the document is live, not lapsed or edited |
| Certified legal entity | The name matches the entity signing your contract | Group certificates do not automatically cover a subsidiary |
| Scope statement | It explicitly covers the platform, hosting and support operations you are buying | Narrow scopes can exclude the very service handling video |
| Issue and expiry dates | The certificate is inside its three-year cycle | An expired certificate is not evidence of a working ISMS |
| Surveillance audits | Annual surveillance audit evidence exists between recertifications | Shows the ISMS is maintained, not certified once and shelved |
Then corroborate with operational trust signals: ask the vendor for a reference site running at comparable scale and call it. BlueFit reports that Lynxight is now live across all BlueFit locations — the kind of multi-site reference an IT team can independently question about access control, footage handling and audit trails.
How do you read the Statement of Applicability for AI and model-training workloads?
How you read a Statement of Applicability depends on what you are trying to confirm. The Statement of Applicability, or SoA, is the ISO 27001 document that lists every Annex A control, records whether it applies, and justifies each inclusion or exclusion. Two different reads matter here: a scope read and a control read.
The scope read asks a single question — does the certified scope name the AI workload, or only the corporate office and support desk? Training data, model hosting and inference are distinct processing activities, and a scope statement limited to "software development" does not automatically cover the pipeline that ingests pool footage.
The control read is where you check attributes one by one:
- Scope statement — values: named legal entities, locations, systems and services. Why it matters: anything unnamed is outside the certified information security management system.
- Applicability status — values: applicable, or excluded with written justification. Why it matters: an exclusion covering supplier or cloud controls is a gap you inherit.
- Supplier and cloud service controls (A.5.19–A.5.23) — confirms subprocessors hosting models are governed.
- Information deletion (A.8.10) — confirms footage retention limits are a control, not a setting.
- Privacy and protection of PII (A.5.34) — the bridge between the SoA and your GDPR obligations.
- Logging and monitoring (A.8.15–A.8.16) — confirms footage access is auditable.
GLL works with Lynxight to modernise the industry by blending traditional lifeguarding with advanced pool technology; that blend only survives audit when the SoA covers the AI layer underneath it.
What contract clauses turn an ISO 27001 claim into an enforceable obligation?
Specific contract clauses are what turn an ISO 27001 claim into an enforceable obligation. ISO 27001 is the international standard for an information security management system — a documented, audited set of security controls certified by an accredited body. It follows that certification alone proves only that a management system existed on the audit date; it gives a pool operator no remedy unless the agreement creates one.
Before you start, have in hand: the vendor's current certificate, its Statement of Applicability (the document listing which controls are in scope), your own data map of camera footage and analytics, and your DPO's retention policy.
- Verify certificate scope against the platform that actually processes pool video, not the corporate entity. Expected outcome: the certified scope names the service you are buying.
- Reserve evidence-based audit rights — documentation on request plus an annual security review. Expected outcome: a defined assurance cadence in writing.
- Fix a breach-notification window in hours, with a named contact and a duty to notify your DPO.
- Name approved subprocessors — any third party handling data on the vendor's behalf — and require prior written notice of change.
- State residency, retention and deletion timelines explicitly, including exit: export format, certified deletion, transition period.
| Do this | But watch out for |
|---|---|
| Demand in-scope certification | Scope covering head office only |
| Require certificate maintenance | Recertification quietly missed |
| Contract deletion proof | No evidence footage was destroyed |
Scope drift is the highest-impact risk; mitigate it by tying each renewal payment to production of a valid, in-scope certificate.
How does ISO 27001 compare with SOC 2, ISO 42001, and ISO 27701 for AI suppliers?
Before you compare ISO certificates and SOC attestations, fix the criteria you are judging against: scope (what the framework actually governs), form of assurance (a certificate issued by an accredited body versus an auditor's report), evidence period (point-in-time versus a window of operating effectiveness), and the residual gap left for your own contract clauses to close. Weight scope highest — a supplier can hold a genuine certificate that says nothing about the risk you care about.
| Framework | What it governs | Form of assurance | Gap it leaves |
|---|---|---|---|
| ISO/IEC 27001 | An information security management system: risk treatment, access control, supplier and incident management | Certification by an accredited body, with surveillance audits | Says little about model behaviour, bias, or privacy-specific rights handling |
| SOC 2 Type II | Trust services criteria (security, availability, confidentiality) tested over an observation window | Auditor's report, not a certificate; usually under NDA | Scope is defined by the vendor; no accredited certificate to verify independently |
| ISO/IEC 42001 | An AI management system: model lifecycle, oversight, impact assessment | Certification, still uncommon among suppliers | Governs process discipline, not the performance of any given model |
| ISO/IEC 27701 | A privacy information management system extending ISO 27001 toward GDPR-style obligations | Extension certification on top of ISO 27001 | Does not replace your own DPIA or lawful-basis analysis |
What often escapes procurement scrutiny is that these frameworks are not a ladder of increasing rigour but four different questions asked of the same supplier — stacking them adds breadth, not depth, and none of them substitutes for reading the data-processing schedule.
For pool AI specifically, Lynxight states it is ISO 27001 certified, and Ann Arbor YMCA reports that Lynxight brings real peace of mind to its staff and to the families who use its pools — assurance paperwork and operational confidence are separate evidence, and IT should collect both.
Frequently Asked Questions
What does ISO 27001 actually certify in a pool AI contract?
ISO 27001 is the international standard for an information security management system (ISMS) — a documented framework of policies, risk assessments, access controls and audit routines governing how an organisation handles data. In a pool AI contract, it tells IT that the vendor operates a governed security programme covering the video and analytics data flowing from your sites. Lynxight's UK and Australian contract terms commit to securing customer data in accordance with the company's ISO 27001 certification, which is the form of commitment IT should look for: written into the terms, not asserted in a slide. Certification does not, on its own, describe retention periods or who may view footage — verify those separately as contract clauses.
How should IT verify footage retention and deletion rules?
Ask for the retention period in writing and confirm it is enforced automatically rather than by manual housekeeping. A useful public reference point: Imperial College London publishes a description of its Lynxight installation at the Ethos swimming pool, including its data policy — footage is automatically deleted after 7 days unless needed for incident review. That pattern gives IT three things to check in any pool AI agreement:
- Default retention window — how long footage persists with no incident attached.
- Exception handling — what triggers preservation, and who authorises it.
- Deletion evidence — whether the platform can demonstrate that deletion occurred.
Under GDPR and the UK Data Protection Act, a short, automatic, documented default is far easier to defend to a data protection officer than an open-ended archive.
Which questions should IT ask about access control and audit trails?
Access to pool footage must be role-based, logged and reviewable. IT teams should require answers to a specific set of questions before signing:
- Who can view live video, who can view recorded video, and are those separate permissions?
- Is every footage access event logged with user, timestamp and reason?
- How are accounts provisioned and de-provisioned across a multi-site estate?
- What is captured in an incident record, and can it be exported for a duty-of-care review?
An audit trail is what answers "what was seen, and how fast did the team respond?" rather than leaving that reconstruction to memory, so ask any vendor exactly which events are recorded, what each record contains and how long it is retained. Ask for the monitoring window in writing too: Lynxight's own service terms scope the system to pool operating hours, so map that against your incident-escalation runbook rather than assuming round-the-clock cover.
Why does camera compatibility matter to an IT security review?
Because every additional piece of proprietary hardware is another asset to patch, network and secure. Lynxight is camera agnostic across roughly 10-12 camera manufacturers and models, connecting to standard overhead security cameras rather than requiring dedicated devices, and covers every tile of the water from at least 2 angles. For a multi-site estate with mixed CCTV brands accumulated over years, that materially reduces the integration surface IT has to review, harden and maintain. It also compresses the rollout: Lynxight brings a site live in about 50 days on average, and as fast as 2-3 weeks, against 3-5 months for competitors that require dedicated hardware. Ask any vendor to state, in the contract, which camera models are supported and what network access the system requires.
Does an AI pool safety system replace lifeguards or change supervision responsibilities?
No. Lynxight is a decision support system — it supports the lifeguard's decision rather than acting autonomously, in the way a driver-assistance system warns about a blind spot while the driver stays in control. It never enters the water, and the lifeguard remains the responder. This matters to IT and compliance because it defines liability boundaries in the contract: the system issues notifications to smartwatches and workstations, and the operator's own trained staff assess and act. As Todd McHardy, CEO of BlueFit Group, puts it: "Today, more than 50 BlueFit pools run Lynxight as standard — not to replace lifeguards, but to give them the edge they need." Supervision duties, rostering and rescue response stay with the operator.
What evidence of real-world performance can IT reasonably request?
Ask for named, verifiable references rather than laboratory claims. Several are publicly documented: City of Newcastle states that Lynxight helps pool lifeguards respond to potential incidents up to six times faster, and that the technology is already in use at more than 75 public pools across Australia. Fluidra, the listed pool-industry multinational, invested in Lynxight through Fluidra Ventures in March 2025 and describes it as the market leader in AI-powered safety solutions for commercial pools. On reliability, the practical measure is alert volume in normal operation — Lynxight averages 2-3 alerts per pool per day across its monitored sites, a figure the company states from its own deployments and one IT can use to size notification workflows. In 2026, procurement teams evaluating an AI pool safety system should expect vendors to supply this level of named, checkable detail.