ISO 42001: What It Actually Certifies, and Whether You Need It
ISO 42001 went from obscure standard to procurement line item in about eighteen months. It does not certify that your model is safe, and the certificate scope is where buyers consistently misread it.

A prospect's security team asks whether you hold ISO 42001. Eighteen months ago almost nobody asked. Now it shows up in procurement checklists next to SOC 2, and the people asking frequently cannot say what a yes would actually tell them.
That gap is the interesting part. ISO/IEC 42001 does not certify that your model is safe, accurate, or unbiased. It certifies that you run a management system for AI governance, and that an auditor checked that system against a scope you defined. Those are very different claims, and the second one is worth considerably less than buyers assume unless you read the scope.
Verified as of 8 September 2026. Certification claims below are sourced to each vendor's own announcement or compliance page. Where I could not confirm something against a primary source, I say so rather than repeating it.
What the standard actually is
ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System, built on the same Plan-Do-Check-Act structure as the rest of the ISO management-system family.
That family resemblance is the clearest way to understand what a certificate means. ISO 27001 does not certify that a company cannot be breached. It certifies that the company runs a documented information security management process, and that an auditor sampled it. ISO 42001 sits in the same genus. It attests to process, not to model behavior.
I want to be precise about the basis for that reading. I could not retrieve a verbatim statement from ISO explicitly disclaiming model-safety assurance, because iso.org blocks automated access. The interpretation follows from the standard's category, which is management systems, and it is consistent with how every other ISO management-system standard works. Treat it as a well-founded reading rather than a quotation.
The scope trap, using a real certificate
An ISO certificate covers a stated scope. The scope is written on the certificate. Almost nobody in a procurement conversation reads it, and the announcement blog post is not the same document.
Salesforce is the cleanest illustration I found. Its public announcement names three things: Agentforce, Einstein, and Slack AI. A buyer reading that would reasonably describe Salesforce as "ISO 42001 certified for Agentforce and Einstein."
The actual certificate on Salesforce's own compliance site lists considerably more. Six Agentforce sub-products named individually, the Einstein Platform, Slack, and five Marketing Cloud editions. Then Data Cloud, B2C Commerce and Commerce Cloud, MuleSoft including Government Cloud, core Salesforce Services, Tableau Cloud, Tableau Next, and Own by Salesforce.
The press release and the certificate are two documents at two levels of granularity, and the buyer relying on the press release will describe the coverage wrongly in both directions. That is the practical lesson: ask for the certificate, not the announcement.
Who actually holds it
All checked 8 September 2026 against each vendor's own materials.
| Vendor | Confirmed | Scope as stated |
|---|---|---|
| AWS | Yes, November 2024 | Amazon Bedrock, Amazon Q Business, Amazon Textract, Amazon Transcribe. Four named services, not "AWS" |
| Anthropic | Yes, certified January 2025, valid to January 2028 | Commercial products including the Claude API and Claude apps, plus AI R&D |
| Snowflake | Yes, announced June 2025 | "Limited to the artificial intelligence management system (AIMS) supporting the Snowflake AI Data Cloud Services" |
| Salesforce | Yes, September 2025 to September 2028 | See above. Much broader than the announcement implies |
| OpenAI | Certificate listed on the trust portal | Could not extract a 42001-specific scope statement. Do not assume it matches AWS-style service naming |
| ServiceNow | Not confirmed | Its compliance page refused automated access. I found no first-party scope statement, so I am not going to state one |
Two of the six could not be pinned down to a first-party scope statement. That is not an accusation of anything. It is a demonstration of how hard this is to verify from the outside, which is exactly the position your buyer is in when they ask you the same question.
On auditors: AWS and Anthropic both used Schellman, an ANAB-accredited body. Snowflake says only "an accredited certification body." Salesforce's announcement quotes a BDO partner, which is not the same as confirming BDO issued the certificate, so I will not claim it did.
What it costs and how long it takes
Published pricing barely exists in this market, because certification bodies quote per engagement. Schellman is the exception and publishes numbers in its own FAQ, which makes it a usable primary source rather than a consultancy estimate.
For the year-one Stage 1 and Stage 2 audit, Schellman puts the cost in the twenty thousands up to the forty thousands, with surveillance audits in years two and three at roughly 13,000 to 20,000 dollars a year. Certification runs on a three-year cycle with annual surveillance.
Timeline from a standing start is roughly six to twelve months, dropping to something closer to three to six months if you already run ISO 27001, since the management-system scaffolding, risk process, and audit muscle are already there.
You will see a wider figure quoted, often 45,000 to 130,000 dollars. That number bundles the audit fee with internal implementation, gap remediation, tooling, and consultants. It may well be a realistic total program cost, but it is not a certification body's published fee, and I could not source it to one. Treat the audit fee as the hard number and everything above it as your own implementation estimate.
One claim I want to explicitly retire: a widely repeated statistic says more than half of vendors promoting AI functionality in a Gartner Magic Quadrant lack the certification. I could not trace it to Gartner. Every path led back to compliance-vendor content with no citation, and Magic Quadrant reports are paywalled. I am not going to repeat it, and neither should your deck.
How it differs from what you already have
If you hold SOC 2, you have an attestation from a licensed CPA firm against the AICPA trust services criteria. It is a report about controls, mostly security-focused, and it is the North American default.
If you hold ISO 27001, you have a certification that you run an information security management system.
ISO 42001 adds the AI-specific layer neither of the others addresses: governance over AI risk, data governance for AI purposes, transparency about how systems are used, and human oversight of automated decisions. That is why holding SOC 2 does not answer an ISO 42001 question, and why the reverse is also true.
When a startup should pursue it
Pursue it when a named deal requires it, or when the same question has now appeared in three separate security reviews. Those are real signals with a revenue number attached.
Do not pursue it because it seems like the responsible thing to do. It is a management system, which means it generates ongoing obligations: internal audits, management reviews, documented risk treatment, and a surveillance audit every year. A certificate you cannot maintain is worse than no certificate, because the lapse is visible on a date the auditor already published.
If you have no ISO 27001 program, budget for building the management-system muscle first. Most of the cost of a first ISO certification is not the audit. It is discovering that your processes were tribal knowledge.
What to ask a vendor who claims it
Ask for the certificate itself, not the blog post. Read the scope statement on it, and check whether the product you are actually buying appears there.
Ask which accredited body issued it, and check that body's accreditation. ISO certification is only as strong as the accreditation behind it.
Ask for the expiry date and the date of the most recent surveillance audit. A three-year certificate in month 34 with no surveillance evidence is a different risk than one issued last quarter.
Then ask the question the certificate cannot answer: what specifically does your AI management system do when a model behaves unexpectedly in production. The standard requires them to have an answer. The certificate does not tell you whether the answer is any good.
What would your own answer to that last question be, if a buyer asked you this week?
More from Deepak Gupta
Every page on guptadeepak.com is hand-curated by Deepak Gupta. Pick a thread:
- About Deepak Gupta
Founder, cybersecurity architect, and writer at guptadeepak.com.
- My journey
From LoginRadius (2013, 1B+ users) to GrackerAI, in milestones.
- Publications & patents
Books, free e-books, a journal special issue, and five granted patents.
- Research Hub
Curated research, buyer's guides, vendor comparisons, and technical deep-dives.
Get the newsletter
New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.