For years, customer due diligence in financial services followed a predictable script. Procurement teams asked for SOC 2 Type II and PCI DSS certification, given how often payment data flows across digital channels and tools.
According to Theta Lake, these remain essential foundations, and no vendor should be trusted for security or compliance work without them. But they are no longer sufficient, and AI has fundamentally changed what vendors must prove to earn the confidence of customers and partners.
Theta Lake recently jumped into the Standards for AI trust in security and compliance, and why vendors must hold ISO 42001 and CSA STAR Level 2 for the AI systems they provide.
Buyers now need to understand how a vendor’s AI model reaches its decisions, what data trained it, how that data is protected, whether a human can step in, and whether the system can be shut down quickly.
Above all, they need independent verification rather than paper claims taken on trust. That shift is driving ISO/IEC 42001 towards becoming the new baseline for AI vendor accountability.
The distinction between independently audited and self-declared is the whole point, and should be treated as non-negotiable. The market has seen enough “AI-washing”, where vendors describe capabilities in glowing terms with nothing to substantiate them. Compliance teams are right to discount claims that can’t be verified. Read the full article.













