First, register and join us for our September 22, 2026 webinar, where experts from A-LIGN, one of the first accredited ISO 42001 assessors, and Theta Lake’s compliance technology leadership discuss the rise and importance of ISO 42001 for AI, and the imperative to have 3rd party audit of AI systems.
For deeper context, over many years, the customer due diligence playbook in financial services was predictable. Procurement teams asked for SOC 2 Type II, and a PCI DSS cert since payment data tends to show up across digital channels and tools. Those are all necessary foundations, and any vendor that can’t provide those shouldn’t be trusted for security or compliance use cases. Those are no longer enough, and AI has absolutely changed what vendors need to do to prove trust for their customers and partners.
The New AI-specific Assurance Needed
Beyond foundational certifications every vendor must have, their customers and partners now need to know how the vendor’s AI model makes decisions; what data trained it; how any and all data used or stored is protected; whether a human can intervene; can it be shut off quickly; and, perhaps most importantly, whether any of that can be independently verified rather than taken on faith that the vendor’s paper claims are true and proven. That shift is exactly what’s driving the rise of ISO/IEC 42001 as the new baseline for AI vendor accountability, and why Theta Lake went through the arduous process to achieve it.
That distinction, expertly, independently audited versus self-declared, is the whole point and should be non-negotiable. The security and compliance markets have already seen enough “AI-washing,” where vendors describe AI capabilities in glowing terms without anything to back it up. Compliance teams are right to discount unverified claims.
Any security or compliance vendor that wants a customer to POC their AI features and provides only their own documentation should be questioned hard. In the Gartner Magic Quadrant in which Theta Lake participates, more than half of the vendors promoting AI functionality have no ISO 42001 certification to prove the safety and validity of their AI implementations; a clear problem and gap that customers should focus on. Regardless of how thorough their documentation is, without independent validation of controls, the customer is trusting claims and positioning more than validated and verified facts. ISO 42001 gives the customer credible evidence: a standard they can point to in a board memo or a regulatory exam without having to take the vendor’s word for it.
Why ISO 42001 is becoming the reference point for AI Certification
ISO/IEC 42001 is the first certifiable international standard built specifically for AI management systems. Unlike a self-attested responsible-AI policy or a marketing claim about “explainable AI,” ISO 42001 requires an independent, third-party audit of how an organization governs AI across its entire lifecycle: design, development, deployment, and ongoing monitoring. Certified vendors have to produce auditable evidence covering governance and accountability structures, documented AI risk assessment and mitigation processes, data governance controls, and incident escalation frameworks.
Regulators are applying real pressure here, even without a single unified AI rulebook. The EU AI Act has set a global reference point for risk-tiered AI obligations. The NIST AI Risk Management Framework gives US institutions a voluntary but increasingly expected structure for identifying and mitigating AI risk. Internal risk and audit committees at banks and asset managers are translating these expectations into RFP language, and vendors who can’t answer pointed questions about model governance, training data provenance, and explainability are getting flagged earlier in the buying process than they used to be.
Where this is headed and CSA STAR for AI Level 2
The Cloud Security Alliance Security, Trust, Assurance, and Risk, or CSA STAR for AI Level 2, builds on this standard further by layering the Cloud Security Alliance’s AI Controls Matrix on top of an ISO 42001 foundation, adding more granular controls around bias mitigation, model risk management, algorithmic explainability, training data privacy, and additional continuous validation. Together, these two certifications are starting to function as a tightly paired tandem. ISO 42001 for management-system maturity, CSA STAR for AI for cloud-specific technical depth. Given their complement, the two should be used together for depth rather than seen as alternatives. That is why Theta Lake added CSA STAR Level 2 to its ISO 42001 certification this year, and is the only vendor in its segment to have both standards and the depth of certification and continuous validation for its AI systems.
A few things seem clear about the next 12 to 24 months. First, ISO 42001 is on a trajectory similar to where SOC 2 was a decade ago: optional differentiator today, contractual requirement tomorrow. Second, AI implementation in compliance processes will accelerate this timeline rather than slow it down. Third, the depth of using ISO 42001 and CSA STAR for AI should serve as core requirements for any AI implementation beyond a vendor’s explainability docs. When AI systems move from simple chatbots to key oversight and compliance tools, the cost of ungoverned AI failure rises sharply, and the frameworks built for “AI that recommends” will need to stretch to cover “AI that acts.” Vendors who already have AIMS governance in place will adapt faster than those scrambling to build it from scratch under regulatory pressure.
What financial services firms should do now
For compliance and risk leaders building or refreshing a vendor assessment scorecard, a few practical moves matter more than others. Treat ISO 42001 and SOC 2 as complementary, not redundant, since one covers AI-specific security and governance and the other covers general information security, and you need both. Push vendors for specifics, not assurances: ask for model cards, audit-ready explainability documentation, and evidence of human-in-the-loop controls, not just a slide that says “responsible AI” in the deck. And don’t wait for a mandate. The firms that update their vendor scorecards to include AI-specific governance criteria before it’s required will have a much easier time when it eventually is.
The next 90 days are a reasonable window to act. Pull your current AI vendor roster, ask each one directly whether they hold ISO 42001 or CSA STAR for AI Level 2 certification, and if they don’t, ask for a timeline. The answer you get back will tell you a lot about how seriously that vendor is taking AI governance, and whether they should still be on your roster a year from now.
Again, you can learn more about this topic in the Theta Lake Financial Services AI Governance Virtual Series. We’re excited to welcome Patrick Sullivan, VP of Strategy and Innovation at A-LIGN, and Andrew Vanderford, CPA, CISA, Director of Technology Compliance and Audit at Theta Lake, for the deep dive fireside chat. Register for “The Standard for Compliance AI Trust: Why Vendors Must Hold the ISO 42001 AI Certification When Servicing Financial Services Customers,” airing on September 22.
Save your spot.












