Theta Lake / FinTech Global — ISO 42001 becomes new baseline for AI vendor trust
Tag: S-2026-08-18-thetalake-iso42001-baseline Type: article (trade-press relay of a vendor blog post) Author(s): FinTech Global (“dwillis”), relaying Theta Lake Date of source: 2026-08-18 Date ingested: 2026-08-25 Authority weight: low — editorial relay of a self-interested vendor position piece; headline statistical claim unattributed and unverifiable Raw file: S-2026-08-18-thetalake-iso42001-baseline.md
What it claims
FS vendor due diligence has historically run on SOC 2 Type II and PCI DSS; Theta Lake argues these remain necessary but are no longer sufficient for AI-bearing products. Customers now want to know how a vendor’s AI reaches decisions, what data trained it, whether a human can intervene, and whether the system can be shut down quickly — and they want independent verification rather than vendor self-declaration, because the market “has already seen its share of AI-washing”. The piece positions ISO/IEC 42001 as the emerging accountability standard (first certifiable international AI-management-system standard, third-party audited across the AI lifecycle) and CSA STAR for AI Level 2 as the next layer (Cloud Security Alliance’s AI Controls Matrix on a 42001 foundation, adding controls around bias mitigation, model risk management and explainability). It claims regulatory pressure (EU AI Act globally, NIST AI RMF in the US) is pushing banks and asset managers to embed these criteria directly into RFP language, and asserts that more than half of vendors promoting AI functionality “within the Gartner Magic Quadrant” lack ISO 42001 certification. It predicts a SOC 2-like trajectory: optional differentiator today, contractual requirement tomorrow, and advises compliance leaders to demand model cards and human-in-the-loop evidence rather than marketing assurances.
Notable quotes
- “more than half of vendors promoting AI functionality within the Gartner Magic Quadrant lack ISO 42001 certification” (article body — which MQ unspecified)
- “The market has already seen its share of AI-washing, where vendors talk up capabilities without evidence to support them.” (article body)
- “an optional differentiator today, a contractual requirement tomorrow” (article body, attributed to unnamed “analysts”)
What’s speculative vs. asserted
- Asserted: ISO 42001 is certifiable and third-party audited; CSA STAR for AI Level 2 layers the AI Controls Matrix on 42001. (Consistent with standards facts already in the vault.)
- Asserted but unverified: the “>half of MQ vendors lack ISO 42001” statistic — no methodology, no named MQ; treat as vendor assertion. Banks/asset managers embedding criteria “directly into RFP language” — no named examples.
- Speculative (source’s own): the SOC 2-trajectory prediction (“analysts expect” — unnamed).
Topics this feeds
- ISO 42001 — procurement/RFP-baseline thread and certification-market momentum.
- AI Governance Platforms — certification status as a vendor-selection discriminator (not folded in this run; see ISO 42001 page).
Open questions raised
- Which Gartner MQ does the >50% claim refer to, and is it verifiable from public certification registries?
- Are there documented FS RFPs requiring ISO 42001 / CSA STAR for AI Level 2, or is this anticipatory positioning?