A vendor's trust page lists both "SOC 2 Type II" and "ISO/IEC 42001 certified" badges side by side, and a procurement lead checks both boxes and moves on, assuming they cover overlapping ground. They don't. One audits whether the vendor's systems are secure and available. The other audits whether the vendor governs its AI responsibly, its risk assessments, its human oversight, its training data handling, across the system's entire lifecycle. A vendor can pass one and fail the spirit of the other completely, and knowing which question each badge actually answers is what separates real due diligence from checkbox-collecting.
What does a SOC 2 report actually certify?
SOC 2 is a security and operations audit, not an AI-specific one. The AICPA's Trust Services Criteria evaluate a service organization's controls across up to five categories, security, availability, processing integrity, confidentiality, and privacy, and a SOC 2 Type II report attests that those controls were designed correctly and operated effectively over a defined period, typically six to twelve months.
Critically, SOC 2 was built years before agentic AI systems existed, and its criteria say nothing about algorithmic bias, model drift, training-data provenance, or whether a human actually reviews a model's high-stakes output. A vendor can hold a clean SOC 2 report and still have no formal process for catching a model that's silently degraded, or a training set nobody vetted for bias.
What does ISO/IEC 42001 actually require that SOC 2 doesn't touch?
ISO/IEC 42001, published in December 2023, is the first international standard for an AI management system, the structured, auditable process an organization uses to govern how it develops, provides, and uses AI. It requires a documented AI policy addressing ethical principles, transparency, and accountability, and it requires those commitments to be communicated inside the organization, not just written down for auditors.
- A systematic AI risk-assessment process: identifying risks tied to developing, providing, or using AI systems, analyzing likelihood and impact, and prioritizing what gets treated first, not a one-time checklist.
- 39 controls organized across nine categories, covering the AI lifecycle end to end, from data quality to third-party AI component management to incident response specific to AI failures.
- Human oversight requirements: a defined mechanism for a person to intervene in or override an AI system's output, exactly the gap a SOC 2-only vendor typically can't demonstrate, the same oversight layer that has to be designed into a RAG pipeline built for compliance documents from day one, not retrofitted.
- Certification takes six to twelve months and runs from roughly $5,000 to $30,000 or more for the initial audit, renewed via annual surveillance over a three-year certificate cycle, which is why a vendor holding it has made a real, ongoing investment, not a one-time badge purchase.
So which certification should an enterprise actually require, and when?
The dividing line is consequence, not company size. Any vendor whose AI materially influences a consequential decision, credit, hiring, healthcare, insurance, access to a service, should be expected to show ISO/IEC 42001 alignment or certification, because that's the standard built to audit exactly that kind of risk.
A vendor whose AI is purely assistive, drafting, summarization, internal search, where a human reviews every output before it reaches a customer, can reasonably be held to a lighter bar, though SOC 2 alone still leaves a governance blind spot worth asking about directly. Increasingly, enterprise buyers ask AI vendors for both, one for the infrastructure, one for the AI itself, and that combined bar is now part of what a real vendor due-diligence checklist should check for, alongside a live architecture walkthrough and outcome-tied pricing.
How AIBOOTSTRAPPER builds to this standard for ComplySpark
ComplySpark exists specifically to operationalize this kind of governance for clients: a drafting copilot, grounded in a company's own policy library, that generates and version-controls compliance documents with human-in-the-loop review built into the workflow rather than bolted on after the fact. That's the same human-oversight principle ISO/IEC 42001 requires, applied to the document layer instead of the model layer.
The build cut document drafting time by 10x while keeping every output traceable to a single source of policy truth, with zero off-policy language slip-ups, the kind of auditable outcome a governance-conscious buyer can actually verify, not just take on faith. If your organization needs to show this level of AI governance to your own customers or regulators, book a call or see the full case study.
Want this done for you?
Book a free strategy call and we'll show you how to build and market your business with AI.
