At minimum, ask an enterprise AI partner for SOC 2 Type II, which covers security, availability and confidentiality controls over a sustained period rather than a single point-in-time snapshot, and increasingly ISO 42001, the AI management system standard covering AI governance specifically. ISO 27001 is a reasonable substitute for or complement to SOC 2 depending on the vendor's location. If the project touches health data, ask about HIPAA compliance capability specifically; for payment data, ask about PCI DSS; for EU operations, ask about alignment with the EU AI Act, which has been in force since August 2024, with general-purpose AI model duties applying from August 2025 and most high-risk system duties phasing in from August 2026. Holding a certification does not by itself guarantee good practice, so ask to see the actual audit report or certificate rather than accepting a badge shown on a marketing page, and ask how recently it was renewed. Smaller or newer AI firms may not yet hold every certification but should be able to demonstrate equivalent practices and a credible path toward certification, which matters more than treating its absence as an automatic disqualifier. Nanobase AI documents its security and data-handling practices in writing for every enterprise client and discusses current certification status directly during vendor evaluation.
Why a badge on a website proves almost nothing
Any vendor can display a certification logo on a marketing page regardless of whether the underlying audit is current, applies to the specific service being sold, or exists at all. The only way to verify a certification claim is to ask for the actual audit report or certificate and check the scope and renewal date directly, rather than accepting a badge shown alongside a client logo carousel as sufficient evidence. This is one item on a longer list; see questions to ask an AI vendor before signing for the full due-diligence set certifications fit into.
Ask to see the actual audit report or certificate, not a badge displayed on a marketing page, and ask how recently it was renewed, since a lapsed certification from two years ago tells you very little about current practice.
What each certification actually covers
| Certification | What it covers | When to require it |
|---|---|---|
| SOC 2 Type II | Security, availability and confidentiality controls, audited over a sustained period rather than a single point in time | Baseline requirement for any AI vendor handling company data |
| ISO 27001 | Information security management system, common for internationally operating vendors | Reasonable substitute for or complement to SOC 2 depending on vendor's operating geography |
| ISO 42001 | AI management system standard covering governance of AI development and deployment specifically | Increasingly relevant as AI-specific governance questions grow, especially for generative AI vendors |
| HIPAA compliance capability | Handling of protected health information | Required if the project touches health data in any form |
| PCI DSS | Payment card data security | Required if the project touches payment data |
Why SOC 2 Type II specifically, not Type I
SOC 2 comes in two forms: Type I assesses whether controls are designed appropriately at a single point in time, while Type II assesses whether those controls actually operated effectively over a sustained period, typically six to twelve months. Type II is the more meaningful assurance for an ongoing vendor relationship, since it demonstrates the controls held up in practice rather than only existing on paper at the moment of a snapshot audit. A vendor offering only a Type I report should be asked directly when a Type II audit is planned.
Regional and regulatory considerations
For EU operations, ask about alignment with the EU AI Act, which has been in force since 1 August 2024, with general-purpose AI model duties applying from 2 August 2025 and most high-risk system duties phasing in from 2 August 2026 as of 2026. A vendor operating in or serving EU markets should be able to speak specifically to which category of the Act their offering falls under and what obligations that triggers, rather than giving a generic assurance of compliance; see the EU AI Act, GDPR and KVKK compliance checklist for the fuller regulatory picture beyond certifications alone.
A practical verification process
- Request the actual audit report or certificate for each claimed certification, not a summary or a marketing page reference.
- Check the scope statement within the report, since a certification can cover one part of a vendor's operations while excluding the specific service being purchased.
- Check the audit or certification date and confirm it is current, not several years lapsed.
- For newer or smaller vendors without full certification, ask for a written description of equivalent security practices and a stated timeline toward formal certification.
- Treat an absence of certification as a discussion point requiring more scrutiny elsewhere, not an automatic disqualifier, particularly for an otherwise strong technical candidate.
Frequently asked questions
Is it reasonable to disqualify a vendor with no certifications at all?
Not automatically, especially for a smaller or newer firm, but it should trigger deeper scrutiny of their actual security practices and a clear, credible plan toward certification. A vendor with strong technical delivery but no certifications yet may still be a reasonable choice for a lower-sensitivity use case, with certification becoming a firmer requirement as the relationship scales.
Does ISO 42001 replace the need for SOC 2 or ISO 27001?
No, they cover different things. ISO 42001 addresses governance of the AI development and deployment process itself, while SOC 2 and ISO 27001 address general information security controls. A vendor handling sensitive data through an AI system ideally holds both types of assurance rather than treating one as a substitute for the other.
How often should these certifications be re-verified during an ongoing engagement?
Annually is a reasonable minimum, since most of these certifications require periodic renewal audits on that cycle. Build a calendar reminder to request updated reports at renewal time rather than assuming a certification checked at contract signing remains valid indefinitely.
What about certifications specific to a regulated industry like insurance or healthcare?
Beyond the general certifications above, ask about industry-specific requirements directly relevant to the data involved, such as HIPAA capability for health data or state-specific insurance data handling rules, since general security certifications do not automatically cover industry-specific regulatory obligations.
How Nanobase AI helps
Nanobase AI, a Silicon Valley enterprise AI engineering company, documents its security and data-handling practices in writing for every enterprise client and discusses current certification status directly during vendor evaluation, including scope and renewal details rather than a marketing summary.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.