BlueprintBlueprint
Buying an AI Agent means sorting through a long list of certifications. Here's how to tell which ones actually matter.
A vendor's certification list can look like a wall of acronyms. But around 90% of it is ground you already know how to evaluate – data handling, identity and access management, the usual controls.
The other 10% is specific to AI: new threats like prompt injection and hallucinations that come from a nondeterministic system. This is a fast-growing area of regulation you’re right to scrutinize. Those standards are unfamiliar to everyone, but if you’ve evaluated software before, you’re not starting from scratch.
Once you can tell the two apart, the whole list gets easier to judge. You'll know when a missing certification points to a real problem and when it just reflects a standard that’s still emerging.
Here's what each of these certifications actually means.
These are the certifications that come up most often when you're buying an AI Agent. What each one actually covers ranges from the vendor’s whole organization down to a specific system, service, or even a single AI product. It’s worth checking that a certification covers the AI, not just the vendor’s wider operation.
| Credential | What it covers | How much is AI-specific | What it applies to |
|---|---|---|---|
| SOC 2 | Independent attestation covering security, availability, and confidentiality controls | None – the same baseline review any vendor goes through, AI or not | A defined system/service, not the whole company by default |
| ISO 27001 | A documented, audited system of security policies and controls | None – the same underlying security program regardless of AI | The organization’s security program |
| ISO 27701 | Previously an extension of ISO 27001, now a standalone system for managing personal data | Mostly unchanged – plus a new requirement to assess the privacy risks that AI processing poses to the people whose personal data is involved | The organization’s privacy program |
| ISO 27018 | Protection of personally identifiable information (PII) handled by a cloud provider on your behalf | None – standard cloud-data protection still applies | The organization, but only in its role as the data processor for your company |
| ISO 42001 | Governance and lifecycle management of AI systems across how an organization develops, provides, and uses AI | Entirely – it only exists because AI systems needed a governance standard of their own | The organization’s AI program |
| AIUC-1 | Tested resistance to jailbreak and prompt injection, with mandatory quarterly adversarial testing | Entirely – there’s no non-AI version of this certification to compare it to | A specific AI product or Agent configuration |
Most of this list covers the controls you would apply to any software vendor.
A baseline security credential, SOC 2 or ISO 27001, is the minimum every serious vendor should hold. Without one, a vendor can't show a real security program exists.
Data handling is the next non-negotiable, and it's not a new discipline for AI. You'd put any software vendor that touches your data through the same review. Is it kept separate from other customers' data, deleted on request, and processed in a region that meets your requirements, with access limited to the people who need it? The more PII the Agent handles, the more weight those questions carry.
For an AI Agent, add one more question: is your data used to train or fine-tune a model? That one holds no matter what you're using the Agent for.
Credentials are how a vendor backs those answers up.
Not every vendor holds these, so weigh them against how sensitive your use case is.
Auditability is another control you'd expect from any vendor. Can they log and trace what the Agent did after the fact? Their ISO certification often covers it.
The new part is smaller in scope, but it’s what regulators and CISOs are watching closely. It comes in two forms. One is the Agent’s own behavior, where risks like hallucination and prompt injection come from. The other is what the Agent can reach once it starts taking action.
Two certifications have emerged to help you evaluate a vendor.
ISO 42001 covers the entity. AIUC-1 covers the thing you're actually buying.
Both are worth looking for, but the strongest evidence here is testing cadence. A vendor running frequent adversarial testing, with a red team of outside specialists attacking the Agent several times a year, tells you more than a one-off audit ever could.
Once the Agent can update a record or reach into a CRM, two questions matter:
The first is familiar – the Agent connects with credentials you set up, like any integration.
Security teams address the second with an approach called the “shared responsibility model.” It splits the work in two. The vendor secures its own system and the Agent. Your half is configuring what each action can reach, so the Agent pulls only the data a task needs. If it looks up a customer's order, it shouldn't be able to see their whole account.
If you’re using Fin, that configuration lives in Data Connectors and Procedures. Connectors define which systems your Agent can reach and what data each one exposes. Procedures set the rules, in plain language plus deterministic logic, for when Fin uses them and what it's allowed to do at each step.

That's the technical picture. Walking your CISO through it is a different skill – our guide on talking to your CISO covers how to prepare for that conversation.
GDPR, the EU's data privacy law, is a legal framework a vendor complies with, or doesn't. There’s no audit to pass and no certificate to collect. The EU AI Act is moving the same way – it's new legislation for AI systems. It’s still phasing in, and set to become another compliance obligation rather than a certification.
HIPAA works the same way in US healthcare. Compliance runs through a signed Business Associate Agreement (BAA), the contract that sets out how a vendor handles protected health data. Without one, you can’t legally route real health data through the system, even in a trial. Not every vendor will sign a BAA, since it commits them to HIPAA’s obligations. If you're in healthcare, start on the BAA early, because it has its own sign-off cycle that can add weeks to your timeline.
Which of these you need depends on your data and your industry. GDPR if you handle EU personal data, HIPAA if you handle US health data. For the ones that apply to you, the proof is what a vendor will put in writing – a GDPR-compliant data agreement, or a BAA they’ll sign.
If you're in a heavily regulated field like finance, insurance, healthcare, or gambling, you’ll lean on formal certification. These fields are compliance-first, and rely on recognized standards. An ISO certification meets that expectation, because an independent body has audited the vendor against an established standard.
But how far regulation has caught up with AI varies by field. Some regulators have issued AI-specific guidance; others, like the UK's Financial Conduct Authority (FCA), have deliberately chosen not to write new AI rules, applying their existing frameworks instead. Check what your regulator has published before deciding what "secure" means for you.
The skill here is telling the 90% from the 10%.
Insist on the baseline. A vendor that can't show SOC 2 or ISO 27001 and sound data handling hasn't cleared the fundamentals, whatever its AI looks like. For the AI-specific standards, the strongest evidence is often how regularly the vendor tests the Agent for weaknesses.
Do that, and the wall of acronyms becomes a manageable list – the ones you insist on, and the ones you weigh.
Thibault Candebat is Chief Information Security Officer at Fin. Connect with him on LinkedIn.
Follow Fin for the latest research, guides, and product updates on AI customer service.