ISO 42001 becomes new baseline for AI vendor trust

For years, financial services due diligence followed a fixed script. Procurement teams asked for SOC 2 Type II and PCI DSS certification, given how often payment data flows across digital channels and tools.

According to Theta Lake, these remain essential foundations, and any vendor unable to produce them has no business competing for security or compliance contracts. But they are no longer sufficient. AI has fundamentally reshaped what vendors must demonstrate to earn the trust of customers and partners.

Theta Lake recently jumped into the Standards for AI trust in security and compliance, and why vendors must hold ISO 42001 and CSA STAR Level 2 for the AI systems they provide.

Beyond baseline certifications, customers now want to know how a vendor’s AI model reaches decisions, what data trained it, how that data is protected, whether a human can step in, and whether the system can be shut down quickly.

Crucially, they want independent verification rather than a vendor’s word alone. This shift explains the growing prominence of ISO/IEC 42001 as the emerging standard for AI vendor accountability.

The difference between independently audited and self-declared claims is the crux of the issue. The market has already seen its share of AI-washing, where vendors talk up capabilities without evidence to support them. Compliance teams are right to treat unverified claims with scepticism.

Notably, more than half of vendors promoting AI functionality within the Gartner Magic Quadrant lack ISO 42001 certification, exposing a significant gap that customers should scrutinise closely.

ISO 42001 is the first certifiable international standard built specifically for AI management systems, requiring third-party audits across an organisation’s entire AI lifecycle, from design through ongoing monitoring. Regulatory pressure is mounting too, with the EU AI Act setting a global benchmark and the NIST AI Risk Management Framework shaping expectations in the US, pushing banks and asset managers to embed these criteria directly into RFP language.

CSA STAR for AI Level 2 builds further on this, layering the Cloud Security Alliance’s AI Controls Matrix atop an ISO 42001 foundation to add granular controls around bias mitigation, model risk management and explainability. Analysts expect ISO 42001 to follow a trajectory similar to SOC 2 a decade ago: an optional differentiator today, a contractual requirement tomorrow.

For compliance and risk leaders refreshing vendor scorecards, the practical steps are clear: treat ISO 42001 and SOC 2 as complementary rather than redundant, demand specifics such as model cards and human-in-the-loop evidence rather than marketing assurances, and act before regulation forces the issue.

Reviewing the AI vendor roster now, and asking direct questions about certification timelines, will reveal which partners are serious about AI governance.

Read the full Theta Lake post here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.