AI vendors with ISO 42001 certification

AI vendors certified to ISO/IEC 42001, the international standard for AI management systems published December 2023.

ISO/IEC 42001 is the first international standard for an AI Management System (AIMS), published December 2023. It is the AI-specific cousin of ISO 27001, certifiable through accredited bodies, with 38 controls in Annex A and the same management-system clauses (4-10) as the rest of the ISO 27000 family. Adoption is early but accelerating among mature AI vendors. Holding ISO 42001 is a strong signal that the vendor systematically governs AI lifecycle risk rather than treating AI safety as ad hoc.

Vendors with ISO 42001

Anthropic
HQ: United States
AI safety-focused company building the Claude model family. Founded by former OpenAI researchers with a mission to develop reliable, interpr…
Score 11.44 · low
IBM
HQ: United States
Enterprise technology company offering the watsonx AI platform with proprietary Granite foundation models. Combines own model development wi…
Score 14.11 · low
Microsoft
HQ: United States
Global technology conglomerate that both develops proprietary AI models (Phi series) and deeply integrates OpenAI models across its Copilot …
Score 14.68 · low
SAP
HQ: Germany
Global enterprise software company integrating AI through its Joule AI assistant across ERP, supply chain, and business applications. Combin…
Score 16.63 · low
Google DeepMind
HQ: United States
Google's unified AI research lab combining DeepMind and Google Brain, building the Gemini model family integrated across Google products and…
Score 18.85 · low
Nuance (Microsoft)
HQ: United States
Healthcare AI unit of Microsoft providing clinical speech recognition and ambient documentation through Dragon Medical One and DAX Copilot. …
Score 20.86 · moderate
Aleph Alpha
HQ: Germany
German AI company building sovereign European foundation models (Luminous series, Pharia) with a focus on data sovereignty, explainability, …
Score 24.29 · moderate
Vanta
HQ: United States
Automated security and compliance platform helping companies achieve SOC 2, ISO 27001, HIPAA, and GDPR compliance. Adds AI Agent for securit…
Score 27.24 · moderate

Buyer checklist

Compliance is necessary, not sufficient. Holding ISO 42001 is a meaningful baseline, but no certification covers AI-specific risk end-to-end. Layer this on top of vendor-specific diligence — sub-processor disclosure, training-data policy, model card transparency, dependency-chain mapping.