Someone on your team has been asked whether an AI vendor is ISO 42001 certified. They search. They find a press release from 2024, a logo on a compliance page, and a LinkedIn post. None of it tells them the scope of the certificate, who issued it, who accredited the issuer, or whether any of it is valid today.
That is not a failing of the companies who got certified. They did hard work and published it, which is more than most of the market has done. It is a structural condition of a young standard: there is no single accredited register you can query, so buyers default to the only artifact they can reach. The announcement becomes the evidence.
GRC teams know that substitution well. It is the same move as accepting a screenshot because the system behind it is hard to get to. The artifact stands in for the state, everyone agrees to treat the two as the same thing, and it holds until something goes wrong.
This list does not fix that. What it does is refuse to paper over it. Below are 13 organizations with primary-source ISO 42001 certification announcements or certification pages, recorded across seven fields. Where a source does not disclose a field, the entry says so and leaves the blank visible. A blank is information.
Read it as a starting point for supplier research, not as a claim that every product a named company sells is certified, or that we independently confirmed every certificate is valid today.
How many companies are ISO 42001 certified worldwide? The sources reviewed for this article do not establish a reliable global total. Announcements, registers and historical counts cover different populations and different dates. The list below gives you named examples you can investigate, rather than a market count assembled from sources that do not agree on what they are counting.
How to read this list, and any list like it
Seven fields, each one a question you are actually asking when you ask “is this vendor certified?” Use them on any supplier, whether or not they appear here.
- Certifications. Which standards, at which edition. ISO/IEC 42001:2023 is not interchangeable with ISO/IEC 27001:2022 or ISO/IEC 27701:2025. One certificate never implies another.
- Certifying body. Who performed the assessment. Two certificates held by the same company often come from two different bodies.
- Accreditation body. Who accredited that certifying body, for this standard, as of this date. Certification and accreditation are separate checks.
- Announced. The date the claim was published. Not the date the certificate was issued, and not the date it expires.
- Scope. The defined boundary of the management system. Scope is set per certificate and often per product. It is rarely the whole company.
- Primary source. The document the claim traces back to. A directory entry citing another directory is not a source.
- Source review. When we last read that source, stated plainly, so you can judge how stale this page has become since.
Before you rely on any listing to choose a supplier, follow the source and obtain the current certificate. If you are planning your own program instead, how to get ISO 42001 certified covers that process.
{{ banner-image }}
ISO 42001 certified companies, grouped by what they do
Each entry identifies the company or certification body’s source. “All three” means the cited sources describe ISO 27001, ISO 27701 and ISO 42001. It does not mean the three certificates share a scope or an expiry date. An announcement records a certification claim at the time of publication. Current status, legal entity, covered services and validity dates should be checked in the certificate or the issuer’s register before you rely on any of it.
Cloud and AI platforms
Amazon Web Services (AWS): holds all three
- Certifications. ISO/IEC 42001, ISO/IEC 27001:2022, ISO/IEC 27701:2019.
- Certifying body. Schellman for ISO 42001; EY CertifyPoint for ISO 27001 and 27701. Two certificates, two different bodies — a reminder that “is this company certified?” is really a question about each certificate.
- Accreditation body. ANAB for the ISO 42001 certificate; the Dutch Accreditation Council (RvA) for ISO 27001 and 27701.
- Announced. ISO 42001 on November 25, 2024.
- Scope. Amazon Bedrock, Amazon Q Business, Amazon Textract and Amazon Transcribe among the covered services. The full list is in the certificate itself, available through AWS Artifact.
- Primary source. AWS’s ISO/IEC 42001 announcement, and its ISO 42001, ISO 27001 and ISO 27701 FAQs.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
Microsoft: holds all three
- Certifications. Microsoft publishes ISO/IEC 42001 and ISO/IEC 27701 information, and separately documents ISO/IEC 27001 certification. Check each certificate’s scope; one certification is not used here to infer another.
- Certifying body. Not published on Microsoft’s compliance pages.
- Accreditation body. Not published.
- Announced. Not published. The ISO 42001 compliance page was last updated September 1, 2026.
- Scope. Microsoft’s ISO 42001 page lists covered AI services, including GitHub Copilot, Microsoft 365 Copilot, Microsoft Copilot Studio, Microsoft Foundry and Microsoft Security Copilot. The current certificate and service list determine coverage.
- Primary source. Microsoft’s ISO 42001 and ISO 27701 compliance pages on Microsoft Learn.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
Google Cloud: holds all three
- Certifications. Google Cloud’s source describes accredited ISO/IEC 42001 certification. It separately publishes its ISO 27001 and ISO 27701 coverage. Read the product scope of each certificate independently.
- Certifying body. Not named in Google’s announcement.
- Accreditation body. Not named; Google states the ISO 42001 certification is accredited.
- Announced. ISO 42001 on December 19, 2024.
- Scope. Google notes that some features sit outside its ISO certifications, giving Antigravity in Gemini Enterprise as one example its ISO 27001 and ISO 42001 do not cover. Scope is defined per product, not per company — and naming an exclusion this precisely is the disclosure you want, not a warning sign.
- Primary source. Google Cloud’s ISO 42001 announcement and its Gemini Enterprise compliance documentation.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
Anthropic: holds ISO 42001 and ISO 27001
- Certifications. ISO/IEC 42001:2023 and ISO/IEC 27001:2022. The cited Anthropic certification page does not list ISO 27701; that absence does not establish that no such certificate exists.
- Certifying body. Schellman.
- Accreditation body. ANSI National Accreditation Board (ANAB).
- Announced. January 13, 2025.
- Scope. Described through the AI management system itself — policies, testing and monitoring, transparency, oversight — rather than a product list.
- Primary source. Anthropic’s ISO 42001 announcement and its certifications page.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
Snowflake: holds ISO 42001 and ISO 27001
- Certifications. ISO/IEC 42001 and ISO/IEC 27001, with ISO 27017 and ISO 27018 listed in the referenced material. ISO 27701 is not established by the sources used for this entry.
- Certifying body. Schellman Compliance, LLC, named on certificate 1698444-1.
- Accreditation body. Not published.
- Announced. ISO 42001 on June 12, 2025.
- Scope. The certificate covers the AIMS supporting Snowflake AI Data Cloud Services in AI-producer, developer, and product/service-provider roles. Its scope refers to Statement of Applicability version 2025.1.
- Primary source. Snowflake’s published ISO 42001 certificate, with the listed entity, scope and printed dates. This is the only entry on the list where the certificate itself is the source rather than an announcement about it, which is why the scope line here is specific enough to act on.
- Source review. September 11, 2026. The published certificate was read; current suspension status and completion of surveillance were not independently established.
Cybersecurity
Mimecast: holds all three
- Certifications. ISO/IEC 42001, ISO 27001 and ISO 27701, with ISO 22301.
- Certifying body. Schellman.
- Accreditation body. Not published.
- Announced. January 15, 2025.
- Scope. Not published separately for Mimecast.
- Primary source. Mimecast’s ISO 42001 press release.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
CrowdStrike: holds ISO 42001
- Certifications. ISO/IEC 42001:2023. Its ISO 27001 and 27701 status was not verified for this list.
- Certifying body. Not published; described as “an independent, accredited certification body.”
- Accreditation body. Not published.
- Announced. January 22, 2026.
- Scope. Core Falcon platform capabilities, including CrowdStrike Endpoint Security, Falcon Insight XDR and CrowdStrike Charlotte AI.
- Primary source. CrowdStrike’s ISO 42001 press release.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
GRC, trust and compliance platforms
Anecdotes: holds all three
- Certifications. ISO 27001, ISO 27701 and ISO 42001, alongside further attestations listed in our trust center.
- Certifying body. Mastermind.
- Accreditation body. Not stated for the specific Anecdotes certificates in the cited account. Verify the accreditation attached to the actual certificates rather than infer it from the issuer’s other work.
- Announced. October 2025.
- Scope. Not published.
- Primary source. The Anecdotes trust center, and our own account further down this page.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
That is a thinner record than the AWS entry above, and we are showing it as it is. A page that asks thirteen organizations for seven fields owes its readers the same blanks about itself.
Vanta: holds ISO 42001 and ISO 27001
- Certifications. ISO/IEC 42001 and ISO 27001 are described in the cited material. ISO 27701 is not established by the sources used for this entry.
- Certifying body. Not named; described as “an ANAB-accredited 42001 assessor.”
- Accreditation body. ANAB.
- Announced. April 24, 2025.
- Scope. The AI management system. No product list.
- Primary source. Vanta’s ISO 42001 announcement.
- Source review. September 11, 2026. The public source was reviewed; current certificate expiry and suspension status were not independently established.
Professional and IT services
KPMG Australia: holds ISO 42001
- Certifications. BS ISO/IEC 42001.
- Certifying body. BSI.
- Accreditation body. Not announced at the time of issue. BSI announced its own ISO/IEC 42001 accreditation from RvA on December 9, 2024, about two months after this certificate.
- Announced. October 16, 2024.
- Scope. Described through the standard; KPMG’s own units are not listed.
- Primary source. BSI’s announcement and KPMG Australia’s own release.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
Infosys: holds ISO 42001
- Certifications. ISO/IEC 42001:2023. Infosys’s ISO 27001 and 27701 status could not be verified for this list from a primary source.
- Certifying body. TÜV India, part of TÜV Nord Group.
- Accreditation body. Not named; the announcement does not use the word “accredited.”
- Announced. May 7, 2024, the earliest date on this list.
- Scope. The AI management system framework within the Infosys Topaz Responsible AI suite.
- Primary source. Infosys’s ISO 42001 announcement.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
Enterprise software and AI specialists
ORO Labs: ISO 42001 certification announced
- Certifications. ISO/IEC 42001, described by ORO Labs as the first accredited certificate in the world for an AI management system.
- Certifying body. Mastermind.
- Accreditation body. International Accreditation Service (IAS).
- Announced. Certified July 16, 2024.
- Scope. Artificial Intelligence Management System (AIMS).
- Primary source. ORO Labs’ account of the certification.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
Synthesia: holds ISO 42001
- Certifications. ISO/IEC 42001.
- Certifying body. A-LIGN.
- Accreditation body. Not announced at the time of issue. A-LIGN announced its ANAB accreditation for ISO 42001 on October 23, 2024, about a month after this certificate.
- Announced. September 25, 2024.
- Scope. Not published.
- Primary source. A-LIGN’s announcement of the Synthesia certificate.
- Source review. September 11, 2026. The linked public source was reviewed; current certificate expiry and suspension status were not independently established.
The list contains the 13 examples above. A new name belongs here only when a primary source can support it and its disclosed scope can be recorded. An update to an announcement is not automatically an update to a certificate, so future maintenance should check the record itself as well as the date on the article.
What the list shows about the state of the record
Read the 13 entries as a set and a few patterns come out. None of these are criticisms of the organizations involved. They are properties of a standard roughly two years into public adoption.
The record is uneven, and unevenly available. Four of the thirteen entries do not name the certifying body in their public source. Seven do not name an accreditation body. Three do not publish a scope. The companies with the fullest disclosure are not necessarily the most rigorously certified. They are the ones whose publishing conventions happen to include those fields. Absence of a field is absence of a field, nothing more.
Accreditation sometimes arrives after the certificate. KPMG Australia’s BSI-issued certificate was announced October 16, 2024; BSI announced its own ISO/IEC 42001 accreditation from RvA on December 9, 2024. Synthesia’s A-LIGN certificate was announced September 25, 2024; A-LIGN announced ANAB accreditation for ISO 42001 on October 23, 2024. That sequence is normal for an early standard, when certifying bodies and accreditation bodies are building capacity at the same time as their clients. It also means “accredited” is a question with a date attached, and the date matters.
Scope is defined per product, not per company. Google names a feature its ISO 27001 and ISO 42001 do not cover. AWS names four covered services and points to the certificate for the rest. Snowflake’s certificate cites a specific Statement of Applicability version. This is the standard working exactly as designed. It is also the single most common way a certification claim gets read wider than it was written.
A small number of bodies carry a large share of the work. Schellman appears on four of the thirteen entries. Mastermind appears on two. Concentration like that is expected in a young market, and it makes the accreditation question more important, not less.
Put those together and you get the condition the whole market is operating in: a growing number of real certificates, and no shared, current way to see them. So proof of AI governance circulates as announcements. And an announcement, by construction, records a moment.
Why a GRC company published this list
The distance between “was assessed” and “is operating today” is not a flaw in ISO 42001. It is what a management system certificate is designed to be: an independent assessment, against a defined scope, on a date. The standard does its job well. The strain shows up when the market treats that finding as a continuous state, because the finding is the only artifact it can reach.
We notice this because we run into the same substitution one level down.
Inside a compliance program, a screenshot of an admin console stands in for the configuration. It proves a moment, not a state, and it is stale the day it arrives. Across the supplier market, an announcement stands in for a management system. Same substitution, one level up. In neither case is the artifact dishonest. It is being asked to carry more than it was built to carry.
We have a name for the inside-the-program version: compliance theater, the habit of mistaking activity for assurance. Every organization on this list did the work and published it, which is more than the market asked of them. The problem is that the work and the proof of it have drifted apart, and nobody involved chose that.
Anecdotes exists to close that distance inside an enterprise program: normalized, audit-grade evidence collected from 230+ plugins, so a control is a signal your systems emit rather than an artifact someone goes and fetches.
Our entry is thinner than several others above it: our scope is not published, and accreditation is not stated for the specific certificates in the cited account. We left those blanks visible rather than filling them with language that sounds like an answer.
What we can say with a source behind it is below, in the words of the person who ran it: we recertified ISO 27001 and earned ISO 27701 and ISO 42001 in under six months, externally audited, running the program on our own platform. We publish it because the outcome is not the useful part. The mechanism is.
Questions and answers
How many companies are ISO 42001 certified?
The sources reviewed for this list do not establish a complete current global count. This article documents 13 named examples and does not extrapolate from them. A useful market count would need a defined population, a date, and a method for checking certificate validity and removing duplicates. No source we reviewed supplies all three.
Is there an official registry of ISO 42001 certified companies?
Certificate databases and certification-body registers can help verify a particular record, but coverage depends on which bodies and certificates they include. Search by legal entity and certificate number where available, then check scope, issuer and validity. The public sources in this list are announcements or certification pages. They are not a substitute for the underlying certificates.
Does ISO 42001 certification mean a vendor’s AI is safe to use?
It means an independent body assessed an AI management system against the standard, within a defined scope, on a date. That is a meaningful signal, but it is not a statement about any specific model’s behavior, a guarantee about outputs, or a claim about today. A certificate tells you a system for governing AI was assessed and found conforming. It cannot tell you whether the controls inside it are operating right now. Ask the supplier how they monitor that between audits. The answer usually tells you more than the certificate does.
What is the ISO trifecta?
The ISO trifecta means ISO 27001 for information security, ISO 27701 for privacy management and ISO/IEC 42001 for AI management. They are separate certifications and their scopes should be checked separately. ISO/IEC 27701:2025 is an independent management-system standard; describing it only as an extension of ISO 27001 is no longer correct for that edition. The first-person account below preserves Anecdotes’ record of its own certification project.
How can I verify a company’s ISO 42001 certification?
Start with the current certificate or the issuing body’s register: check the legal entity, certificate number, standard edition, scope and validity dates. Then check the certification body’s accreditation scope with the accreditation body, as of the date on the certificate. Finally, compare the covered services and locations with the product you intend to use. A press release can help you find the certificate. It cannot answer any of those three checks on its own.
Who was the first company to achieve ISO 42001 certification?
“First” claims need a defined scope. ORO Labs’ own account says it received the first accredited ISO 42001 certificate on July 16, 2024. Infosys announced certification on May 7, 2024, without naming accreditation in that announcement. Those are differently qualified primary-source claims, and this list does not declare a universal first.
Our journey to all three ISO certifications
This first-person account describes how our team implemented the standards. For guidance on preparing your organization for an audit, use the ISO 42001 certification guide; for tool evaluation, use ISO 42001 compliance software.
The account below was first published in October 2025 by Adeel Bakht, InfoSec Risk and Compliance Manager at Anecdotes, and is adapted here for clarity. A real external audit stands behind our three certifications, and that experience is what shaped how we recorded every other entry on this page.
When I joined Anecdotes in January 2025 as InfoSec Risk and Compliance Manager, the company already held ISO 27001. That was a strong foundation, but maintaining credibility and expanding trust required going further: privacy (ISO 27701) and AI governance (ISO 42001).
In less than six months, Anecdotes recertified ISO 27001 and earned ISO 27701 and ISO 42001. We did it running the program on our own enterprise GRC platform.
Here is why we pursued them, and how your organization can too.
Why these certifications?
Strengthening security foundations: ISO 27001
ISO 27001 has been the bedrock of information security management for decades. Anecdotes first achieved it in 2021, but as we scaled, governance fragmented. Recertification was never about ticking boxes. It required integrating our management system so information security was aligned with privacy and AI governance rather than siloed from them.
Building trust in privacy: ISO 27701
As an enterprise GRC platform, Anecdotes is trusted with sensitive data from some of the world’s largest enterprises. Achieving ISO 27701 sent a clear message: we do not just support customers in meeting privacy obligations, we hold ourselves to the same standard. For customers navigating GDPR, CCPA and other regulations, our certification shows that data privacy is embedded in how we operate.
Leading in AI governance: ISO 42001
Few standards have generated as much anticipation as ISO 42001, the first global benchmark for AI management systems. With AI embedded across the platform, we had to demonstrate that our use of AI is responsible, explainable and governed. Adopting the standard put us ahead of market demand and regulatory requirements, and reinforced our credibility as a leader in AI-driven GRC.
Five steps that got us there in six months
Managing three certifications in parallel means harmonizing requirements into one integrated system, not running three silos. Here are the five steps we took.
Step 1: Reuse what you already have
We mapped our existing controls and processes to the new standards so we would not duplicate work. With automated cross-mapping, adopting the framework in the platform meant all of our work and evidence was mapped to ISO 27001, 27701 and 42001 controls at once. Collect once, use many times. Even if you have to map manually, do it before you start on the frameworks. It saves you time down the road.
Step 2: Run a comprehensive readiness assessment
Once the controls were mapped, we ran an initial readiness assessment across all three frameworks to find what was missing. The platform continuously ingests data from our systems, so evidence stays fresh and audit-ready instead of being chased down as screenshots and spreadsheets. On that data we set our own custom rules, which produced automated alerts and triggered remediation playbooks. From those findings we implemented the missing technical and organizational controls.
Step 3: Build an integrated management system (IMS)
Going for all three meant eliminating redundant work. Instead of three separate management systems (ISMS, PIMS and AIMS) we combined them into one. We also made sure objectives were not static lists in documents but dynamic, monitored entities:
- Objectives from ISO 27001, 27701 and 42001 were defined in Confluence, tagged with unique prefixes (IS, PR, AI).
- Each objective was created as a Jira “IMS Objective” task.
- Evidence Lab lets you design your own evidence, which is then collected automatically like everything else. We designed evidence that pulls these tasks into custom evidence views in the platform.
- We created monitoring rules on that evidence, flagging objectives that stayed stagnant for more than 30 days.
- We created Playbooks that triggered Slack alerts to owners whenever objectives drifted, referencing linked controls and evidence.
That turned objectives from passive words into actively monitored entities. Drift became visible in days instead of months. Owners were accountable through Slack notifications. Auditors saw an IMS that was alive and measurable.
Step 4: Create a unified risk methodology
We built one risk methodology covering security, privacy and AI rather than three. On that basis we ran integrated risk assessments, established treatment plans, and documented relevant risks in Anecdotes Risk Manager.
Step 5: Implement continuous internal audits
Traditional internal audits are reactive snapshots of compliance health. We wanted an always-on audit environment, and by combining Anecdotes with Slack, Jira and Confluence we built one across all three ISO standards:
- Monitoring rules were applied to the evidence the platform collected automatically. If evidence went stale or a requirement was not met, the control status changed.
- That change triggered playbooks, which moved the related control and sent a real-time alert to the relevant Slack channels, giving us a chance to remediate before audits.
- Teams reviewed alerts in Slack. Where remediation was required, a Jira task was created and linked to Confluence, where it became part of a live internal audit report, all of which synced back into Anecdotes and was shared with our auditors.
Here is what David Forman, founder of Mastermind, our auditor, had to say:
“The Anecdotes team’s approach to achieving all three of these certifications should be adopted by every organization that values security and innovation. They leveraged the automation and AI capabilities of their own platform to both streamline and improve the quality of their audit, and the result was truly incredible.”
From fire drills to efficiency accelerators
With the right strategy, team and platform, ambitious compliance goals are not just possible, they are sustainable. Certifications do not have to be periodic fire drills. With automation and integration, even pursuing three at once becomes a natural outcome of how you operate every day.
My key takeaways:
Automation transforms compliance. From internal audit to IMS objectives, automation reduced human dependency, removed errors, and made compliance continuous.
Certifications are cultural, not just technical. Tools help, but success came from cross-functional ownership and a culture that embraces accountability.
Audits can increase efficiency. Faster sales cycles, earlier detection of issues, stronger differentiation. The certifications did not create bottlenecks. They created momentum.
Where to go next
If you are evaluating a supplier, get the certificate, not the announcement. Check legal entity, certificate number, standard edition, scope and validity dates. Confirm the certifying body’s accreditation covered ISO 42001 as of the date on the certificate. Then compare the covered services against the product you actually intend to buy. The seven fields at the top of this page work as an intake checklist.
If you are building your own AI management system, the ISO 42001 software hub covers the evidence workflow behind an AIMS, and Anecdotes AI governance sets out our current commitments. For the story behind doing all three together rather than the list, our on-demand ISO trifecta webinar walks through it with Jake Bernardes, CISO, and Adeel Bakht. For the security standard most readers arrive here for, our ISO 27001 framework page covers what it asks and how the evidence behind it is collected.
Either way, the principle is the same one we build on. Compliance is an audit outcome. Confidence is a security outcome. A certificate earns you the first. Knowing what your systems are doing right now is how you get the second.


.png)

