ISO 42001
ISO/IEC 42001 is the first international standard for AI management systems. It certifies that a company has documented processes for governing how it builds, deploys, and monitors AI, covering risk assessment, transparency, and incident response, rather than certifying any single AI product's behavior.
Most AI vendors talk about responsible AI in a paragraph on their website. ISO 42001 asks for something more specific: a documented, auditable management system covering how AI actually gets built, deployed, and monitored inside the company.
What is ISO 42001?
ISO/IEC 42001:2023 is a standard published by the International Organization for Standardization that specifies requirements for an AI Management System (AIMS). It's the AI-specific counterpart to ISO 27001's information security approach: instead of certifying a single model or product, it certifies that a company has structured governance covering AI risk assessment, data quality, transparency to users, and incident response across its AI initiatives.
Certification is granted by an accredited third party. Intercom's ISO 42001 certification, for example, was audited by Schellman under ANAB (ANSI National Accreditation Board) accreditation.
Why ISO 42001 Matters
As more customer-facing products embed AI, buyers need a way to distinguish vendors with real governance from vendors that added a "responsible AI" section to their marketing site after the fact.
- Company-wide scope: the certification applies to how AI is governed across the business, not just one feature
- Structured risk management: covers categories similar to the OWASP Top 10 for LLM applications, including prompt injection, hallucination, and data leakage
- Independent audit: a company can't self-certify; an accredited body reviews the actual management system
How ISO 42001 Works
An ISO 42001 audit examines whether a company has documented, followed, and can evidence its AI governance processes: how it assesses risk before deploying a new AI capability, how it monitors AI systems in production, how it handles incidents, and how it communicates AI use to customers. As with ISO 27001, certification requires an initial audit followed by ongoing surveillance.
One honest caveat worth stating plainly: ISO 42001 assesses the company's AI management system, not the live behavior of any specific AI agent. A vendor can hold ISO 42001 and still ship an agent that hasn't been rigorously tested for its own accuracy or safety. That's the gap a product-specific certification like AIUC-1 is designed to close.
ISO 42001 vs AIUC-1
| ISO 42001 | AIUC-1 | |
|---|---|---|
| What it certifies | The company's AI governance program | The AI agent's own behavior and safety |
| Testing method | Documentation and process review | Adversarial testing across risk scenarios |
| Scope | Organization-wide | Specific to a given AI agent |
Fin holds both: ISO 42001 for its parent company's AI governance, and AIUC-1 as a separate, agent-specific certification. Neither substitutes for the other.
Frequently Asked Questions
Does ISO 42001 mean an AI agent is safe to deploy?
Not on its own. It certifies that a company manages AI risk systematically at the organizational level. For assurance about a specific agent's real-world behavior, look for a product-specific certification such as AIUC-1 alongside it.
Is ISO 42001 required by any AI regulation?
No current regulation mandates ISO 42001 specifically, but it's increasingly used as evidence of a mature AI governance program during vendor security reviews and, in some cases, regulatory inquiries.