ISO 42001

Updated 2026-09-09 based on Microsoft’s 2026 Responsible AI Transparency Report ISO 42001 certification claim [S-2026-09-01-microsoft-rai-transparency-report-2026]

Updated 2026-08-25 based on Theta Lake “baseline for AI vendor trust” positioning [S-2026-08-18-thetalake-iso42001-baseline]

Category: framework (international management-system standard) Maturity: adopted (published December 2023; certification market forming) First seen: 2026-05-06 Last updated: 2026-09-09

Updated 2026-09-09 (daily AI-governance vendor-intelligence scan) — a supplier-side datum from the largest AI platform vendor FS firms consume: Microsoft’s 2026 Responsible AI Transparency Report (1 Sep 2026, reached via SecurityBrief UK relay) states Microsoft “is certified against ISO 42001 across products including Microsoft 365 Copilot, Foundry and GitHub Copilot” and has “streamlined the internal processes supporting that certification over the past year” [S-2026-09-01-microsoft-rai-transparency-report-2026]. The due-diligence gap recurs a fourth time: the certifying body and the certificate’s scope (legal entities, sites, which AI systems) are not stated in the retrieved text ⚠️ vendor assertion. Read for Paul’s practice: this is the claim an FS deployer would need to convert into a scoped certificate on file for DORA third-party / outsourcing evidence and for AIMS boundary-setting where Copilot or Foundry sits inside the firm’s own AIMS scope — the certificate, not the transparency-report sentence, is the evidence [inference]. Contradictions: none. Added as this banner, a “How it’s used” bullet and a Source entry.

Updated 2026-08-25 (daily AI-governance vendor-intelligence scan) — a procurement-side datum joins the certifier-side momentum thread: Theta Lake (communications compliance/security vendor for FS), relayed by FinTech Global on 18 Aug 2026, argues ISO/IEC 42001 plus CSA STAR for AI Level 2 (the Cloud Security Alliance’s AI Controls Matrix layered on a 42001 foundation, adding controls for bias mitigation, model risk management and explainability) are becoming the baseline for AI vendor trust in FS due diligence, supplementing — not replacing — SOC 2 Type II and PCI DSS [S-2026-08-18-thetalake-iso42001-baseline]. Two claims to hold loosely: that banks and asset managers are embedding these criteria “directly into RFP language”, and that more than half of vendors promoting AI functionality “within the Gartner Magic Quadrant” lack ISO 42001 certification — both are ⚠️ vendor assertions with no methodology, named MQ, or examples, from a source whose product narrative the certifications-matter framing serves. The unnamed-”analysts” prediction of a SOC 2-like trajectory (optional differentiator → contractual requirement) is preserved as speculation [speculative — S-2026-08-18-thetalake-iso42001-baseline]. Read for Paul’s practice: if 42001 moves into FS RFP language, demand shifts from certification alone toward the independent verification the piece itself says buyers want — the same evidence-over-badges thesis recorded on AI Governance Platforms from the EU-Startups landscape editorial [inference]. Contradictions: none. Added as this banner, a Detail bullet and a Source entry.

Updated 2026-08-21 (daily AI-governance vendor-intelligence scan) — the certification market extends into a crypto-asset exchange, not a bank, insurer or industrial firm: KuCoin (global cryptocurrency exchange; MiCA-licensed in the EU, AUSTRAC-registered in Australia) announced on 20 Aug 2026 that it has achieved ISO/IEC 42001:2023 certification for its AI Management System, covering AI used in risk management, AML/fraud detection, market surveillance, customer service, product intelligence and operational automation, alongside its existing ISO/IEC 27001, ISO 22301 and SOC 2 Type II certifications [S-2026-08-20-kucoin-iso42001]. Read against Paul’s FS-led scope: KuCoin is not core banking/insurance/asset-management, but as a MiCA-regulated financial-adjacent entity certifying AIMS specifically for AML/fraud/market-surveillance AI, it is a relevant read-across for how the certification market is moving in regulated-financial-adjacent spaces [inference]. The same due-diligence gap recurs a third time: the certifying body is not named anywhere in the release (no badge, no text reference — a gap even TechnipFMC’s page-badge disclosure and Outseer’s named Intertek certifier did not have), and the certificate’s scope (legal entities, systems covered) is again unstated [S-2026-08-20-kucoin-iso42001]. Contradictions: none. Added as this banner, a Detail update and a Source entry.

What it is

ISO/IEC 42001:2023 — the international standard for an Artificial Intelligence Management System (AIMS). It specifies requirements for establishing, implementing, maintaining, and continually improving a management system for the responsible development, provision, and use of AI, using the Annex SL harmonised clause structure (clauses 4–10) [S-2026-07-18-pecb-42001-la-exam-prep].

How it’s used

  • Clauses 4–10 cover context, leadership, planning (including AI risk assessment, AI risk treatment, and the distinctive AI system impact assessment), support, operation, performance evaluation, and improvement [S-2026-07-18-pecb-42001-la-exam-prep].
  • Annex A defines 9 control objectives with 38 controls (A.2 policies; A.3 internal organization; A.4 resources; A.5 impact assessment; A.6 AI system life cycle; A.7 data; A.8 information for interested parties; A.9 use of AI systems; A.10 third-party and customer relationships), selectable via a Statement of Applicability; Annex B gives per-control implementation guidance; Annex C lists potential AI objectives and risk sources; Annex D covers domain applicability and integration with other management-system standards [S-2026-07-18-pecb-42001-la-exam-prep].
  • Supporting standards ecosystem: ISO/IEC 22989 (concepts/terminology), ISO/IEC 23894 (AI risk management), ISO/IEC 42005 (AI system impact assessment), ISO/IEC 42006:2025 (requirements for bodies auditing/certifying AIMS) [S-2026-07-18-pecb-42001-la-exam-prep].
  • In Paul’s practice: the AIMS Statement of Applicability is a named artefact of the AI and Data Assurance Pathway [S-2026-05-06-paul-ai-data-pathway]; the IGA Toolkit build plan anchors its methodology to ISO/IEC 42001/42006 [S-2026-07-17-iga-toolkit-build-plan]; the PECB Lead Auditor certification project targets personal certification against it [S-2026-07-18-pecb-42001-la-exam-prep].
  • Certification against the standard follows the ISO/IEC 17021-1 model: Stage 1 + Stage 2 initial audit, annual surveillance, recertification at 3 years [S-2026-07-18-pecb-42001-la-exam-prep].
  • Supplier-side certification claim (Sept 2026): Microsoft states ISO 42001 certification across Microsoft 365 Copilot, Foundry and GitHub Copilot in its 2026 Responsible AI Transparency Report; certifier and scope unstated in the retrieved coverage ⚠️ [S-2026-09-01-microsoft-rai-transparency-report-2026].
  • Procurement-side positioning (Aug 2026): Theta Lake argues 42001 (with CSA STAR for AI Level 2 layered on top) is becoming the baseline FS buyers demand of AI-bearing vendors, with banks/asset managers said to be embedding 42001 / NIST AI RMF criteria into RFP language, and claims >half of AI-promoting vendors “within the Gartner Magic Quadrant” lack 42001 certification — all ⚠️ vendor-asserted, unverified (which MQ is unspecified); the piece explicitly warns against “AI-washing” and self-declared claims, favouring independent verification [S-2026-08-18-thetalake-iso42001-baseline].
  • Certification market momentum (2026): beyond FS-sector early movers such as Outseer (certified by Intertek, Jul 2026) [S-2026-07-08-outseer-iso42001], the standard is now being certified enterprise-wide by large listed non-FS corporates — TechnipFMC (UK-registered, NYSE-listed energy technology) announced certification on 29 July 2026, with Schellman indicated as certifier via the page’s verification badge [S-2026-07-29-technipfmc-iso42001] — and, most recently, by a MiCA-regulated crypto-asset exchange: KuCoin announced certification on 20 August 2026, covering AI used in AML/fraud detection, market surveillance and risk management, with no certifying body named [S-2026-08-20-kucoin-iso42001]. A recurring due-diligence gap across these announcements: none of the three releases states the certificate’s scope (entities, products, AI systems covered), and two of the three (Outseer, KuCoin) name no verifiable certifying body in the release text itself [S-2026-07-08-outseer-iso42001][S-2026-07-29-technipfmc-iso42001][S-2026-08-20-kucoin-iso42001].

Theoretical basis

  • relates-to → EU AI Act — AIMS adoption is driven by (but not equivalent to) AI Act readiness; the Act shapes interested-party requirements in clause 4. [inference]
  • relates-to → PECB — personnel certification body for 42001 auditor/implementer credentials [S-2026-07-18-pecb-42001-la-exam-prep].
  • relates-to → AI Governance Platforms — platform vendors position against 42001 conformity evidence. [inference]
  • implemented-by → PECB ISO 42001 Lead Auditor Certification — Paul’s certification project against this standard [S-2026-07-18-pecb-42001-la-exam-prep].
  • implemented-by → AI and Data Assurance Pathway — pathway artefacts (e.g. AIMS SoA) operationalise the standard [S-2026-05-06-paul-ai-data-pathway].
  • depends-on → ISO 22989 — AI Concepts and Terminology — 22989 supplies the concepts/terminology layer of the 42001 ecosystem; its full text was ingested 2026-08-17 (see Map: ISO Standards) [S-2026-07-18-pecb-42001-la-exam-prep][S-2022-07-iso-iec-22989].

Strengths / weaknesses

Not yet synthesised — the corpus references the standard as a method anchor and certification target; a critical source on the standard’s strengths/weaknesses has not been ingested.

Tensions

None surfaced.

Sources