Navigating the new standards for AI trust in security and compliance

compliance

For many years, the customer due diligence playbook in financial services was predictable. Procurement teams asked for SOC 2 Type II and a PCI DSS certification, since payment data tends to surface across digital channels and tools.

According to Theta Lake, those remain necessary foundations and any vendor that cannot produce them has no business operating in security or compliance use cases. But they are no longer sufficient. AI has fundamentally changed what vendors must do to prove trust to their customers and partners.

The Emerging Need for AI-Specific Assurance

Beyond foundational certifications, customers and partners now need to understand how a vendor’s AI model makes decisions, what data trained it, how any data used or stored is protected, whether a human can intervene, and whether the system can be shut off quickly. Perhaps most critically: can any of that be independently verified, rather than taken on faith that the vendor’s paper claims are true?

That shift is exactly what is driving the rise of ISO/IEC 42001 as the new baseline for AI vendor accountability. The distinction between expertly, independently audited versus self-declared should be non-negotiable. The security and compliance markets have already seen enough vendors describing AI capabilities in glowing terms without anything substantive to back them up.

Security or compliance vendors that want a customer to evaluate their AI features while providing only their own documentation should be questioned. Regardless of how thorough a vendor’s internal documentation may be, without independent validation of controls, the customer is trusting marketing claims rather than verified facts. ISO 42001 gives procurement teams credible, auditable evidence and standards they can reference in a board memo or a regulatory exam without taking the vendor’s word for it.

Why ISO 42001 Is Becoming the Reference Point for AI Certification

ISO/IEC 42001 is the first certifiable international standard built specifically for AI management systems and requires an independent, third-party audit of how an organisation governs AI across its entire lifecycle: design, development, deployment, and ongoing monitoring. Certified vendors must produce auditable evidence covering governance and accountability structures, documented AI risk assessment and mitigation processes, data governance controls, and incident escalation frameworks.

Additionally, regulators are applying real pressure even without a single unified AI rulebook. The EU AI Act has established a global reference point for risk-tiered AI obligations. The NIST AI Risk Management Framework gives US institutions an increasingly expected structure for identifying and mitigating AI risk. Internal risk and audit committees at banks and asset managers are translating these expectations into RFP language, and vendors who cannot answer pointed questions about model governance, training data provenance, and explainability are getting flagged earlier in the buying process than ever before.

What Financial Services Firms Should Do Now

For compliance and risk leaders building or refreshing a vendor assessment scorecard, a few practical steps matter more than others.

Treat ISO 42001 and SOC 2 as complementary, not redundant. One covers AI-specific governance and the other covers general information security; both are necessary. Push vendors for specifics rather than assurances: ask for model cards, audit-ready explainability documentation, and evidence of human-in-the-loop controls — not a slide deck that says “responsible AI.” And do not wait for a mandate. Firms that update their vendor scorecards to include AI-specific governance criteria before it is required will have a considerably easier time when it eventually becomes mandatory.

The next 90 days are a reasonable window to act. Pull your current AI vendor roster, ask each vendor directly whether they hold ISO 42001 and if they do not, ask for a timeline. The answer will reveal how seriously that vendor takes AI governance.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.