Skip to main content

Analysis

ISO 42001 and AI Vendors: What the Certificate Actually Covers

Which vendors publish ISO/IEC 42001 evidence, what the AI management system certificate actually scopes, and what to ask before you rely on it.

Solomon AmosPublished 25 Sep 20269 min read

ISO/IEC 42001 is the first management system standard built specifically for artificial intelligence, and a small but growing number of software vendors now list it on their trust centres next to SOC 2 reports and ISO 27001 certificates. For a buyer evaluating an AI feature, the badge looks reassuring, but it answers a narrower question than most people assume. It confirms that a vendor runs a documented process for governing AI risk across the system's lifecycle, not that any specific model output is safe, accurate or free of bias. This piece sets out what an ISO/IEC 42001 certificate actually scopes, what the CertReports index shows about who publishes it, and what to ask a vendor before you treat the badge as a substitute for reading the certificate itself.

What ISO/IEC 42001 actually certifies

ISO/IEC 42001:2023 was published in December 2023 by ISO/IEC JTC 1/SC 42, the joint technical committee that also writes ISO's other AI standards. It follows the same Annex SL high level structure as ISO 27001, ISO 22301 and ISO 9001, so an organisation that already runs one of those management systems can often extend the same governance machinery to cover AI. The standard requires an organisation to identify AI specific risks, run impact assessments for the context each system is used in, document data provenance and model lifecycle decisions, and show ongoing management review rather than a one off assessment. That matters for buyers because a management system certificate says nothing about whether a particular model was trained fairly, tested for bias, or performs accurately on your data; it says the organisation has a repeatable process for managing those questions and can show evidence of having followed it.

2023
Year ISO/IEC 42001 was published
Released by ISO/IEC JTC 1/SC 42, the same committee behind ISO's other AI standards
3 year cycle
Typical certification cycle
An initial audit followed by annual surveillance visits before recertification, the same pattern used for ISO 27001
Voluntary
Legal status of ISO 42001
Not mandated by the EU AI Act or any other current law; vendors pursue it to evidence AI governance to buyers and regulators
Diagram showing the boundary of an ISO/IEC 42001 certificate scope against a vendor's full AI product line
An ISO/IEC 42001 certificate covers the AI management system inside its stated scope, not every AI feature a vendor ships.

Why buyers are asking for it now

Demand for this evidence has grown alongside the number of vendors shipping AI features inside existing products. Some buyers ask for it because the EU AI Act places obligations on providers and deployers of certain AI systems, and a documented AI management system is one way a vendor can show it has the governance in place to meet those obligations, even though ISO/IEC 42001 itself is not a legal requirement anywhere. Procurement teams also ask for it simply because it is the closest thing to a recognised, third party audited standard for AI governance that currently exists. Where a vendor cannot produce it, that is not unusual yet. Where a vendor claims it without a certificate to show, that is worth pushing on.

What the index shows today

Adoption is still early. ISO 27001 and SOC 2 have decades of audit history behind them; ISO/IEC 42001 has had less than two years, and the pool of certification bodies accredited to issue it is smaller than the pool that issues ISO 27001. You can see the current list of vendors with public ISO/IEC 42001 evidence on the ISO/IEC 42001 framework page, which updates as the index picks up new certificates and expiries rather than relying on a vendor's own claims page. The same caution that applies to older certificates applies here: check the edition and the date. A vendor whose ISO 27001 evidence still cites the 2013 edition, which lapsed on 31 October 2025, is a useful signal to check the rest of its trust centre carefully too. The same is true across the index generally: vendors add and drop frameworks as their audit programmes mature, which is why a framework page reflects a point in time rather than a permanent state.

FrameworkWhat it certifiesWho accredits the auditorTypical audit cycle
ISO/IEC 42001An AI management system: how AI risk is identified, assessed and governed across its lifecycleNational accreditation bodies under IAF, for example UKAS or ANABThree year cycle with annual surveillance audits
ISO/IEC 27001An information security management system: confidentiality, integrity and availability controlsNational accreditation bodies under IAFThree year cycle with annual surveillance audits
SOC 2 Type IIWhether controls operated effectively over a review period, reported as a CPA firm's opinion, not a certificateAICPA member firms, state licensed CPAsReport covers a period, typically six to twelve months, reissued each cycle
EU AI Act conformity assessmentA regulatory obligation for certain high risk AI systems, not a voluntary certificateNotified bodies designated under the Act, where requiredOngoing, tied to the system remaining in scope

How ISO/IEC 42001 compares with the certificates and reports buyers already see on vendor trust centres.

Diagram comparing ISO/IEC 42001, ISO/IEC 27001 and SOC 2 Type II by what each one actually evidences
Three different evidence types answer three different buyer questions.

How to read the scope statement

The single most useful thing a buyer can do with an ISO/IEC 42001 certificate is read the scope statement rather than the badge. Two vendors can both display the same logo while one has certified its entire AI product line and the other has certified a single internal chatbot used by its support team.

  1. 1

    Get the scope statement, not just the badge

    Ask for the certificate PDF or the scope annex. A badge on a trust centre page rarely states what is inside the certified boundary.

  2. 2

    Check the certification body's accreditation

    Confirm the body that issued the certificate is itself accredited to certify ISO/IEC 42001, since not every ISO 27001 auditor has extended into AI management systems yet.

  3. 3

    Match the scope to the feature you are buying

    A certificate can cover one AI feature, one business unit or the whole company. If your contract depends on a specific feature, check it sits inside the stated boundary.

  4. 4

    Confirm the validity window

    Management system certificates run on a cycle with surveillance audits in between. Check the certificate has not lapsed and ask what the most recent surveillance visit found.

One vendor's evidence, read start to finish

Miro's trust centre is one of the few in the index that states ISO/IEC 42001 alongside its longer running SOC 2 Type II and ISO 27001 evidence. The card below renders whatever Miro currently publishes, so look at the scope wording next to the ISO/IEC 42001 row and whether the certificate number resolves on the issuing body's public register, rather than reading the badge as a blanket AI safety statement.

Miro logo

Miro · Trust report

Collaboration · Public evidence as of 29 Sep 2026

1Documents and agreements

Legal and review documents Miro publishes or offers, as of 29 Sep 2026.

12Subprocessors

Named on Miro's public subprocessor list, last seen 29 Sep 2026.

Miro's trust centre showing where ISO/IEC 42001 sits next to its other stated evidence. Every line is a dated public record from the Data Privacy Framework list and Miro's trust centre. A framework not shown means no public evidence was found, not that Miro lacks it.CertReports

ISO 42001 versus ISO 27001

The two standards are often confused because they share a structure and, in many organisations, the same internal audit team. ISO 27001 certifies an information security management system: confidentiality, integrity and availability controls over data and systems generally. ISO/IEC 42001 certifies an AI management system: how the organisation governs AI specific risks such as model drift, training data provenance, human oversight and the way an AI system is used in its declared context. A vendor can hold one without the other. Most vendors that currently hold ISO/IEC 42001 already had ISO 27001 first, since the AI standard assumes a security baseline is already in place underneath it. If you are deciding which certificate to ask for when a vendor offers a choice, treat them as answering different questions rather than one replacing the other.

ISO/IEC 42001:2023 specifies the requirements for establishing, implementing, maintaining and continually improving an AI management system within organisations.

Questions to put to a vendor with an ISO 42001 badge

A badge is a prompt to ask questions, not an answer in itself. None of the following require specialist knowledge to ask, and a vendor that has genuinely gone through the certification process should be able to answer all of them without hesitation.

  • Ask for the certificate PDF and the scope annex, not just a logo on the trust centre page.
  • Confirm the issuing body appears on a national accreditation register; the accredited certification bodies that audit management systems are listed publicly, and not every ISO 27001 auditor has extended into ISO/IEC 42001 yet.
  • Check whether the AI feature you are buying sits inside the certified scope, or outside it in a part of the product that was not audited.
  • Ask how the vendor's AI risk assessment process maps to any obligations you have under the EU AI Act or a sector specific regulation.
  • Ask when the last surveillance audit ran and whether it raised any nonconformities.

Where this sits in a wider vendor review

Treat ISO/IEC 42001 as one line in a longer review, not a review on its own. It sits alongside SOC 2 reports, ISO 27001 certificates, DPF listings and any HIPAA or PCI DSS evidence a vendor publishes, and the same rules apply: check the date, check the scope, check who issued it. If you have not done this systematically before, the guide on how to read a trust centre in ten minutes covers the same checks across every framework a vendor lists, not just this one. None of this replaces reading the certificate yourself, but it narrows down what to look for before the call with the vendor's security team.

People also ask

What is ISO 42001?

ISO/IEC 42001:2023 is a management system standard for artificial intelligence, published by ISO/IEC JTC 1/SC 42. It sets requirements for how an organisation governs AI risk across its lifecycle: data provenance, model testing, human oversight and incident response. A certificate confirms an organisation runs a documented AI management system audited against those requirements, not that any specific AI feature or output has been independently verified as safe or accurate.

Which companies are ISO 42001 certified?

Adoption is still early because the standard only published in December 2023 and the accredited audit ecosystem is younger than the one behind ISO 27001 or SOC 2. A small number of vendors, mostly ones already running mature AI features, currently list it on their trust centres. Check the ISO/IEC 42001 framework page in the CertReports index for the current list rather than relying on a vendor's own claims page, since it tracks what is publicly evidenced.

Does ISO 42001 replace ISO 27001?

No. The two standards share the same Annex SL high level structure but cover different scopes. ISO 27001 certifies an information security management system: how an organisation protects data confidentiality, integrity and availability. ISO 42001 certifies an AI management system: how it governs AI risk, model lifecycle decisions and human oversight. A vendor can hold one without the other, and most vendors with ISO 42001 also hold ISO 27001 as the security baseline underneath it.

How do I verify an ISO 42001 certificate?

Ask the vendor for the certificate PDF and scope statement, then check the certificate number against the issuing certification body's public register, since not every body is accredited to issue this standard. Read the scope wording closely: some certificates cover a single AI feature rather than the whole product. Confirm the certificate is still within its validity window, and compare the scope to the specific feature you plan to buy.

ISO 42001AI governanceAI management systemvendor risk reviewEU AI Act
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

Read next on CertReports

You might also like