ISO/IEC 42001 is the first management system standard built specifically for artificial intelligence, and a small but growing number of software vendors now list it on their trust centres next to SOC 2 reports and ISO 27001 certificates. For a buyer evaluating an AI feature, the badge looks reassuring, but it answers a narrower question than most people assume. It confirms that a vendor runs a documented process for governing AI risk across the system's lifecycle, not that any specific model output is safe, accurate or free of bias. This piece sets out what an ISO/IEC 42001 certificate actually scopes, what the CertReports index shows about who publishes it, and what to ask a vendor before you treat the badge as a substitute for reading the certificate itself.
What ISO/IEC 42001 actually certifies
ISO/IEC 42001:2023 was published in December 2023 by ISO/IEC JTC 1/SC 42, the joint technical committee that also writes ISO's other AI standards. It follows the same Annex SL high level structure as ISO 27001, ISO 22301 and ISO 9001, so an organisation that already runs one of those management systems can often extend the same governance machinery to cover AI. The standard requires an organisation to identify AI specific risks, run impact assessments for the context each system is used in, document data provenance and model lifecycle decisions, and show ongoing management review rather than a one off assessment. That matters for buyers because a management system certificate says nothing about whether a particular model was trained fairly, tested for bias, or performs accurately on your data; it says the organisation has a repeatable process for managing those questions and can show evidence of having followed it.
- 2023
- Year ISO/IEC 42001 was published
- Released by ISO/IEC JTC 1/SC 42, the same committee behind ISO's other AI standards
- 3 year cycle
- Typical certification cycle
- An initial audit followed by annual surveillance visits before recertification, the same pattern used for ISO 27001
- Voluntary
- Legal status of ISO 42001
- Not mandated by the EU AI Act or any other current law; vendors pursue it to evidence AI governance to buyers and regulators
Why buyers are asking for it now
Demand for this evidence has grown alongside the number of vendors shipping AI features inside existing products. Some buyers ask for it because the EU AI Act places obligations on providers and deployers of certain AI systems, and a documented AI management system is one way a vendor can show it has the governance in place to meet those obligations, even though ISO/IEC 42001 itself is not a legal requirement anywhere. Procurement teams also ask for it simply because it is the closest thing to a recognised, third party audited standard for AI governance that currently exists. Where a vendor cannot produce it, that is not unusual yet. Where a vendor claims it without a certificate to show, that is worth pushing on.
What the index shows today
Adoption is still early. ISO 27001 and SOC 2 have decades of audit history behind them; ISO/IEC 42001 has had less than two years, and the pool of certification bodies accredited to issue it is smaller than the pool that issues ISO 27001. You can see the current list of vendors with public ISO/IEC 42001 evidence on the ISO/IEC 42001 framework page, which updates as the index picks up new certificates and expiries rather than relying on a vendor's own claims page. The same caution that applies to older certificates applies here: check the edition and the date. A vendor whose ISO 27001 evidence still cites the 2013 edition, which lapsed on 31 October 2025, is a useful signal to check the rest of its trust centre carefully too. The same is true across the index generally: vendors add and drop frameworks as their audit programmes mature, which is why a framework page reflects a point in time rather than a permanent state.
| Framework | What it certifies | Who accredits the auditor | Typical audit cycle |
|---|---|---|---|
| ISO/IEC 42001 | An AI management system: how AI risk is identified, assessed and governed across its lifecycle | National accreditation bodies under IAF, for example UKAS or ANAB | Three year cycle with annual surveillance audits |
| ISO/IEC 27001 | An information security management system: confidentiality, integrity and availability controls | National accreditation bodies under IAF | Three year cycle with annual surveillance audits |
| SOC 2 Type II | Whether controls operated effectively over a review period, reported as a CPA firm's opinion, not a certificate | AICPA member firms, state licensed CPAs | Report covers a period, typically six to twelve months, reissued each cycle |
| EU AI Act conformity assessment | A regulatory obligation for certain high risk AI systems, not a voluntary certificate | Notified bodies designated under the Act, where required | Ongoing, tied to the system remaining in scope |
How ISO/IEC 42001 compares with the certificates and reports buyers already see on vendor trust centres.
How to read the scope statement
The single most useful thing a buyer can do with an ISO/IEC 42001 certificate is read the scope statement rather than the badge. Two vendors can both display the same logo while one has certified its entire AI product line and the other has certified a single internal chatbot used by its support team.
- 1
Get the scope statement, not just the badge
Ask for the certificate PDF or the scope annex. A badge on a trust centre page rarely states what is inside the certified boundary.
- 2
Check the certification body's accreditation
Confirm the body that issued the certificate is itself accredited to certify ISO/IEC 42001, since not every ISO 27001 auditor has extended into AI management systems yet.
- 3
Match the scope to the feature you are buying
A certificate can cover one AI feature, one business unit or the whole company. If your contract depends on a specific feature, check it sits inside the stated boundary.
- 4
Confirm the validity window
Management system certificates run on a cycle with surveillance audits in between. Check the certificate has not lapsed and ask what the most recent surveillance visit found.
One vendor's evidence, read start to finish
Miro's trust centre is one of the few in the index that states ISO/IEC 42001 alongside its longer running SOC 2 Type II and ISO 27001 evidence. The card below renders whatever Miro currently publishes, so look at the scope wording next to the ISO/IEC 42001 row and whether the certificate number resolves on the issuing body's public register, rather than reading the badge as a blanket AI safety statement.

Miro · Trust report
Collaboration · Public evidence as of 29 Sep 2026
Framework overview
CertReports state for each framework with public evidence: 1 verified, 8 vendor-stated.
ISO 42001Vendor-statedTrust centre · 29 Sep 2026
DPFVerifiedValid to 27 Jul 2027
SOC 2Vendor-statedType II reportGDPRVendor-statedTrust centre · 29 Sep 2026
ISO 27001Vendor-statedTrust centre · 29 Sep 2026
Cyber EssentialsVendor-statedTrust centre · 29 Sep 2026CCPAVendor-statedTrust centre · 29 Sep 2026
TISAXVendor-statedTrust centre · 29 Sep 2026
IRAPVendor-statedTrust centre · 29 Sep 2026
1Documents and agreements
Legal and review documents Miro publishes or offers, as of 29 Sep 2026.
- Subprocessor list · Public
12Subprocessors
Named on Miro's public subprocessor list, last seen 29 Sep 2026.
ISO 42001 versus ISO 27001
The two standards are often confused because they share a structure and, in many organisations, the same internal audit team. ISO 27001 certifies an information security management system: confidentiality, integrity and availability controls over data and systems generally. ISO/IEC 42001 certifies an AI management system: how the organisation governs AI specific risks such as model drift, training data provenance, human oversight and the way an AI system is used in its declared context. A vendor can hold one without the other. Most vendors that currently hold ISO/IEC 42001 already had ISO 27001 first, since the AI standard assumes a security baseline is already in place underneath it. If you are deciding which certificate to ask for when a vendor offers a choice, treat them as answering different questions rather than one replacing the other.
ISO/IEC 42001:2023 specifies the requirements for establishing, implementing, maintaining and continually improving an AI management system within organisations.
Questions to put to a vendor with an ISO 42001 badge
A badge is a prompt to ask questions, not an answer in itself. None of the following require specialist knowledge to ask, and a vendor that has genuinely gone through the certification process should be able to answer all of them without hesitation.
- Ask for the certificate PDF and the scope annex, not just a logo on the trust centre page.
- Confirm the issuing body appears on a national accreditation register; the accredited certification bodies that audit management systems are listed publicly, and not every ISO 27001 auditor has extended into ISO/IEC 42001 yet.
- Check whether the AI feature you are buying sits inside the certified scope, or outside it in a part of the product that was not audited.
- Ask how the vendor's AI risk assessment process maps to any obligations you have under the EU AI Act or a sector specific regulation.
- Ask when the last surveillance audit ran and whether it raised any nonconformities.
Where this sits in a wider vendor review
Treat ISO/IEC 42001 as one line in a longer review, not a review on its own. It sits alongside SOC 2 reports, ISO 27001 certificates, DPF listings and any HIPAA or PCI DSS evidence a vendor publishes, and the same rules apply: check the date, check the scope, check who issued it. If you have not done this systematically before, the guide on how to read a trust centre in ten minutes covers the same checks across every framework a vendor lists, not just this one. None of this replaces reading the certificate yourself, but it narrows down what to look for before the call with the vendor's security team.
People also ask
What is ISO 42001?
ISO/IEC 42001:2023 is a management system standard for artificial intelligence, published by ISO/IEC JTC 1/SC 42. It sets requirements for how an organisation governs AI risk across its lifecycle: data provenance, model testing, human oversight and incident response. A certificate confirms an organisation runs a documented AI management system audited against those requirements, not that any specific AI feature or output has been independently verified as safe or accurate.
Which companies are ISO 42001 certified?
Adoption is still early because the standard only published in December 2023 and the accredited audit ecosystem is younger than the one behind ISO 27001 or SOC 2. A small number of vendors, mostly ones already running mature AI features, currently list it on their trust centres. Check the ISO/IEC 42001 framework page in the CertReports index for the current list rather than relying on a vendor's own claims page, since it tracks what is publicly evidenced.
Does ISO 42001 replace ISO 27001?
No. The two standards share the same Annex SL high level structure but cover different scopes. ISO 27001 certifies an information security management system: how an organisation protects data confidentiality, integrity and availability. ISO 42001 certifies an AI management system: how it governs AI risk, model lifecycle decisions and human oversight. A vendor can hold one without the other, and most vendors with ISO 42001 also hold ISO 27001 as the security baseline underneath it.
How do I verify an ISO 42001 certificate?
Ask the vendor for the certificate PDF and scope statement, then check the certificate number against the issuing certification body's public register, since not every body is accredited to issue this standard. Read the scope wording closely: some certificates cover a single AI feature rather than the whole product. Confirm the certificate is still within its validity window, and compare the scope to the specific feature you plan to buy.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
The state of public compliance evidence in 2026: what 3,000 vendors actually publish
CertReports Research · 18 Sep 2026 · 12 min read
Three quarters of the Visa registry is not a PCI DSS validation
CertReports Research · 17 Sep 2026 · 10 min read
ISO 27001:2013 lapsed on 31 October 2025. Vendor pages have not caught up.
CertReports Research · 16 Sep 2026 · 9 min read