AI-washing is over: why ISO 42001 now decides vendor trust

AI

For years, customer due diligence in financial services followed a predictable script. Procurement teams asked for SOC 2 Type II and PCI DSS certification, given how often payment data flows across digital channels and tools.

According to Theta Lake, these remain essential foundations, and no vendor should be trusted for security or compliance work without them. But they are no longer sufficient, and AI has fundamentally changed what vendors must prove to earn the confidence of customers and partners.

Theta Lake recently jumped into the Standards for AI trust in security and compliance, and why vendors must hold ISO 42001 and CSA STAR Level 2 for the AI systems they provide.

Buyers now need to understand how a vendor’s AI model reaches its decisions, what data trained it, how that data is protected, whether a human can step in, and whether the system can be shut down quickly.

Above all, they need independent verification rather than paper claims taken on trust. That shift is driving ISO/IEC 42001 towards becoming the new baseline for AI vendor accountability.

The distinction between independently audited and self-declared is the whole point, and should be treated as non-negotiable. The market has seen enough “AI-washing”, where vendors describe capabilities in glowing terms with nothing to substantiate them. Compliance teams are right to discount claims that can’t be verified.

Notably, more than half of vendors promoting AI functionality in a Gartner Magic Quadrant that Theta Lake participates in hold no ISO 42001 certification, a clear gap that buyers should scrutinise.

ISO/IEC 42001 is the first certifiable international standard built specifically for AI management systems. It requires independent, third-party audits of how an organisation governs AI across its entire lifecycle, covering governance structures, risk assessment, data governance and incident escalation.

Regulatory pressure is mounting too: the EU AI Act has set a global reference point for risk-tiered obligations, while the NIST AI Risk Management Framework is becoming an expected structure for US institutions.

CSA STAR for AI Level 2 builds on this by layering the Cloud Security Alliance’s AI Controls Matrix on top of an ISO 42001 foundation, adding controls around bias mitigation, model risk management and algorithmic explainability. Theta Lake added CSA STAR Level 2 to its ISO 42001 certification this year, positioning itself as the only vendor in its segment holding both standards.

Looking ahead, ISO 42001 appears to be following the trajectory SOC 2 took a decade ago: an optional differentiator today, a contractual requirement tomorrow. Compliance and risk leaders should treat ISO 42001 and SOC 2 as complementary rather than redundant, pushing vendors for model cards, explainability documentation and evidence of human-in-the-loop controls rather than marketing assurances.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.