Key takeaways:
A few years ago, when a customer asked us how we secured their data, the conversation was fairly contained: encryption, access controls, and compliance certifications. Today, that same question has a second half attached to it, and it's usually the harder one: “How do you govern the AI making decisions with that data?”
That shift isn't a fluke. AI has moved from being a feature bolted onto enterprise platforms to being embedded directly in how organizations plan, forecast, and decide. And wherever AI starts influencing real business outcomes, governance stops being a nice-to-have and becomes the price of entry.
The trust gap for enterprise AI
Every enterprise platform vendor is being asked some version of the same questions right now:
- Is the AI making recommendations explainable, or is it a black box?
- Who's accountable when it gets something wrong?
- Is there a human in the loop before consequential decisions get made?
These aren't hypothetical concerns from overly cautious IT departments. They are the direct result of AI capabilities outpacing traditional governance frameworks meant to keep everything in check. Most organizations today are deploying AI faster than they can govern it.
The problem is that ‘responsible AI’ has, until recently, been more of a set of aspirational principles than a set of provable practices. Every vendor can say they're transparent and accountable. Fewer can point to an independently audited system that actually proves those commitments, which is exactly what ISO/IEC 42001 certifies.
What is ISO/IEC 42001?
ISO/IEC 42001 is the world’s first international management system standard specifically for AI (or an AI management system or AIMS). Published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it provides a certifiable framework for managing AI development, deployment risk, and continuous oversight through independent, third-party audits.
Unlike voluntary ethical codes, ISO/IEC 42001 is a certifiable management system. An accredited third-party auditor evaluates an organization's actual operational processes for developing, deploying, and monitoring AI capabilities.
The scope of ISO/IEC 42001
- What it evaluates: Ethical use, mathematical accuracy, fairness, operational transparency, risk management, data privacy, human oversight, and continuous process optimization.
- What is doesn’t cover: It does not certify a single standalone product or software model. ISO 42001 certifies that the organization operating the AI has a robust, audited governance infrastructure in place.
It certifies that the organization behind the AI has a real, functioning system for managing it responsibly, the same way ISO 27001 certifies an information security management system rather than a single piece of software.
Why certification matters more than ever
Certifications can feel like routine paperwork, but the ISO/IEC 42001 certification is different. Because so few vendors have obtained it, early compliance creates a clear line between empty claims and true compliance.
Since ISO/IEC 42001 first launched, the list of organizations that have achieved certification includes major cloud and AI providers — AWS, Microsoft, and Anthropic among them — alongside enterprise software vendors like Snowflake, ServiceNow, and KPMG Australia. It's a meaningful list, but it's still a short one relative to the sheer number of companies that are releasing AI features today.
That gap represents a major trust dividend. When most vendors rely on verbal assurances about what their AI does with your data, pointing to an independently audited management system changes the conversation entirely from "just trust us" to "here's the proof, and here's who checked it."
What this looks like in practice
Achieving this kind of certification isn't a one-time milestone you pass and file away. It requires an active operating system for AI governance that includes:
- Documented risk assessments for how AI is built and deployed across enterprise data.
- Clear ownership over AI-related decisions with mechanisms for human oversight where it matters.
- An annual internal audit cycle to make sure the system doesn't quietly decay between the three-year external recertification periods.
It's the same discipline security teams have applied to information security for two decades, now extended to a category of risk that didn't exist in that form a few years ago.
For us, that discipline isn't new, but an extension of how Anaplan has always approached platform security. What's changed is that AI governance now needs its own explicit home within that program, with its own controls, rather than being treated as a subset of general data security.
Looking ahead: Building the future of trusted enterprise AI
This also isn't a finish line. As we build out AI-driven workflows, expose more AI capability through APIs, and give AI systems more autonomy to act on a customer's behalf, the governance bar must rise with it.
Enterprise AI agents are shifting from passive tools to active digital coworkers. How do you ensure they remain safe, compliant, and accurate? Here are five non-negotiable requirements for building trustworthy agents.
Every new capability we ship in the Agentic Enterprise — particularly anything approaching agentic "headless" action on a customer's data — gets built against the same question our AI management system is designed to keep asking:
- Can we explain the reasoning behind AI recommendations?
- Is the AI accurate and traceable?
- Is a human positioned to review AI actions and catch it if it's wrong?
The organizations that will earn enterprise trust in the next phase of AI won't be the ones with the flashiest models. They'll be the ones who can prove, independently and repeatedly, that they're managing AI responsibly. That's the conversation we intend to keep leading.
AUTHORS:
Jack McGivney