Yes — treat an accredited ISO/IEC 42001 (AIMS) certificate as a strong procurement checkpoint for how an AI hiring vendor governs AI across its lifecycle. No — do not treat it as a legal safe harbor, and do not drop independent bias audits, jurisdiction notice, or human final authority because a vendor waved a certificate. Fountain’s Responsible AI in hiring guide (published September 14, 2026) makes “ask whether the vendor holds ISO/IEC 42001 or an equivalent accredited certification” an explicit diligence step — and the same guide warns that certification is not a substitute for compliance.
Braintrust AIR is conversational AI interviewing software built as screening support: ranked evidence packs, no auto-reject, SOC 2 Type II, and a published third-party bias audit. Braintrust does not currently publish an ISO/IEC 42001 certification on its product or compliance pages — so this article stays honest about what buyers should demand category-wide, and what AIR *does* publish today. Teams can try AIR or book a demo.
Quick answers
Should you require 42001? Prefer yes as a checkpoint in RFPs for AI interviewing / agentic hiring vendors — then verify scope and pair it with bias-audit and notice evidence.
Does 42001 replace SOC 2 or LL144? No. Different artifacts answer different questions (governance vs security vs adverse-impact testing vs statutory notice).
Is Braintrust 42001-certified? Not on public AIR / compliance / pricing pages as of this research. Evaluate published SOC 2, bias-audit, and HITL claims instead — and ask for any AIMS roadmap in diligence.
---
What is ISO/IEC 42001 — and what is an AIMS?
ISO/IEC 42001:2023 is the first international management-system standard for artificial intelligence. Public ISO and standards-store summaries describe it as specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) for organizations that provide or use AI systems. In plain buyer language: it is to AI governance roughly what ISO/IEC 27001 is to information security — organizational machinery (policy, roles, risk and impact processes, lifecycle controls, monitoring, improvement), not a model-accuracy scorecard.
Important diligence facts that matter in procurement:
- ISO publishes the standard; ISO itself does not certify vendors. Accredited certification bodies perform the audits (Fountain’s guide emphasizes independent bodies under recognized accreditation — verify the specific accreditor on the certificate).
- Certification attests that a management system operates as described for a defined scope — not that every model output is fair for *your* applicant pool.
- Treat clause-level claims carefully. This page paraphrases public summaries only; it does not reproduce paywalled standard text.
If your counsel asks “what does the certificate prove?”, the accurate answer is: independent evidence that the vendor runs governed AI processes under recurring audit — not “this hire is legally safe.”
For adjacent trust framing (adoption vs confidence), see The AI hiring trust gap. For format definitions, see What is AI interview software?.
---
Why 42001 showed up on TA RFPs in 2026
Hiring AI moved from “pilot feature” to consequential workflow — and buyers started asking for governance evidence, not principles pages.
Four market signals landed close together:
Scroll to see all columns
| Signal | Date (source) | Why buyers care |
|---|---|---|
| Fountain — Responsible AI in hiring guide lists independent certification (ISO/IEC 42001 or equivalent) as a vendor-verification step | Sep 14, 2026 | Turns “responsible AI” from marketing into a checklist item next to bias testing, override logs, and contracts |
| PageUp — ISO/IEC 42001:2023 certification as an AI Producer; audit by Sustainable Certification Services; scope includes full suite / Clinch | Sep 8, 2026 | Recent peer certification in talent acquisition software |
| Greenhouse — ISO/IEC 42001 certification (Schellman audit); covers AI capabilities including Real Talent | Feb 25, 2026 | Large ATS/hiring platform normalizing AIMS as customer-facing proof |
| Fountain — ISO/IEC 42001:2023 certification (Insight Assurance); scope Cue, Anna, Emma; alongside ISO 27001 and SOC 2 Type II | April 2026 announcement | Frontline/agentic hiring vendor pairing AIMS with security certs |
Scroll to see all columns
None of those announcements mean every AI interviewing vendor is certified — and none of them mean Braintrust is certified. They mean the buyer ask is now normal.
---
42001 vs SOC 2 vs bias audit vs jurisdiction notice
These are complementary artifacts. Requiring one does not retire the others.
Scroll to see all columns
| Artifact | Primary question it answers | What it does not prove | Typical ask |
|---|---|---|---|
| ISO/IEC 42001 (AIMS) | Does the vendor run an audited AI governance management system for a defined product scope? | Model fairness on *your* funnel; statutory notice; security alone | Certificate + scope + CB + validity |
| SOC 2 Type II | Are security / availability / processing-integrity controls operating over a period? | AI risk treatment, adverse-impact testing, or hiring-law notice | Report via Trust Center under NDA |
| Independent bias audit | Was adverse impact tested for defined groups / uses? | Full AIMS maturity; security posture | Full report + methodology + date |
| Jurisdiction notice / AEDT process (e.g., NYC LL144 orientation) | Did the employer meet local notice, audit-summary, and process rules? | Vendor AIMS excellence; global coverage | Notice templates + employer workflow |
Scroll to see all columns
Fountain’s guide is useful here because it states the hierarchy bluntly: approve evidence, not a principles page — and treat 42001 as independent certification while still requiring bias testing and human-oversight evidence alongside it. It also states certification is not a legal safe harbor.
Braintrust’s published orientation for NYC Local Law 144, Illinois interview rules, GDPR, and related regimes lives on How Braintrust AIR stays compliant and AIR Compliance — always as orientation for buyers and counsel, not legal advice.
---
What to demand in procurement (copy/paste RFP set)
Ask every AI hiring / interviewing vendor the same evidence questions — including vendors that already claim 42001.
1. Certificate package — PDF certificate, certified scope (which products/agents), standard edition (e.g., ISO/IEC 42001:2023), validity and surveillance dates. 2. Certification body — who audited; are they accredited under a recognized accreditation framework? 3. SoA / control map — Statement of Applicability or equivalent: which AI controls are in scope and why. 4. Bias audit — independent report, groups tested, date, remediation tracker; who paid. 5. Human oversight — does the product auto-accept or auto-reject? Show the override workflow and that overrides are logged. 6. Explainability — can a recruiter open questions, responses, and rubric mapping for a score? 7. Candidate notice — templates for jurisdictions you hire in; who owns posting the notice. 8. Data use — may candidate inputs train models? Public models? Subprocessors? 9. Security pairing — SOC 2 Type II (and ISO 27001 if claimed) via Trust Center. 10. Employer responsibility — written acknowledgment that the employer remains accountable for employment decisions and local AEDT rules.
If a vendor answers “we have responsible AI principles” without artifacts, treat the diligence as incomplete.
---
How Braintrust AIR approaches compliance (published claims only)
AIR’s public posture is human-in-the-loop interviewing with auditable evidence — not a claim of ISO/IEC 42001 certification.
What Braintrust does publish today:
Scroll to see all columns
| Claim (as published) | Where |
|---|---|
| Conversational voice AI interviews; role-specific scoring; ranked evidence to humans/ATS | AIR product |
| AIR does not auto-reject; humans decide who advances | AIR; stays compliant |
| Third-party bias audit; No Exceptions across tested categories (Gender, Ethnicity, Intersectional Gender & Ethnicity, Age, Disability Status, Veteran Status); “zero bias detected” language on compliance page | AIR Compliance |
| SOC 2 Type II certified / verified security controls | AIR Compliance; Pricing FAQ |
| Risk / security program language aligned to ISO / NIST practice (alignment claim — not an ISO/IEC 42001 certificate) | stays compliant; AIR Compliance |
| Jurisdiction orientation (NYC LL144 Ready language, Illinois, GDPR, EU AI Act mapping in plain English) + notice templates | stays compliant; AIR Compliance |
| Volume-based AIR commercial model (dollars quote-based) | Pricing |
Scroll to see all columns
What Braintrust does *not* publish on those pages: an ISO/IEC 42001 certificate. Say that in RFPs. Then evaluate the published pack — and ask whether AIMS certification or equivalent governance evidence is on the roadmap for your security committee.
Related integrity reading (what detection can and cannot claim): Can candidates cheat an AI interview?. Vendor landscape: Best AI interview software 2026.
Next step for teams diligence-testing AIR: Try AIR · AIR product · Compliance hub · Book a demo
---
Decision rule for TA buyers
Require 42001 (or equivalent accredited AIMS evidence) when AI materially influences who advances — then still require bias audits, notice, and human decision authority.
Practical rule of thumb:
- High-volume or agentic AI in screening/assessment → 42001 checkpoint is reasonable; pair with bias audit + HITL demo.
- Security questionnaire only → SOC 2 is necessary but not sufficient for AI risk.
- NYC / multi-state / EU hiring → jurisdiction notice and recordkeeping are non-negotiable regardless of certificates.
- Vendor has 42001 but auto-rejects without meaningful human review → fail the oversight test even if the certificate is real.
- Vendor has strong bias audit + HITL + SOC 2 but no 42001 yet → decide with counsel whether AIMS is mandatory this cycle or a scored preference with a roadmap ask — do not pretend a missing cert is a published cert.
Raise the category bar, evaluate what AIR already publishes, and never treat a missing certificate as a published one.
---
What “accredited certification” means in practice
A logo on a homepage is not diligence — the scope statement is.
When Fountain’s guide says to ask for ISO/IEC 42001 or an equivalent accredited certification, the operative words are accredited and certification. In procurement language that usually means:
1. An independent certification body audited the vendor’s AIMS. 2. The body operates under a recognized accreditation framework (confirm accreditation on the certificate package). 3. The certificate names a scope — which products, environments, or roles in the AI value chain are covered. 4. Surveillance / recertification continues after the initial award.
PageUp’s September 2026 announcement is useful as a buyer teaching example because it emphasizes certification as an AI Producer (organizations that build AI systems) and zero nonconformities in that audit narrative — still vendor-attributed, still something you verify in the trust center. Greenhouse’s February 2026 newsroom post similarly ties Schellman’s audit to AI capabilities including Real Talent. Fountain’s own certification post (Insight Assurance; scope Cue, Anna, Emma) pairs AIMS with ISO/IEC 27001 and SOC 2 Type II.
Your security questionnaire should therefore have two rows, not one:
- Do you hold ISO/IEC 42001? (yes/no + PDF)
- What exact products and AI activities are in certified scope? (paste scope language)
A “yes” with a scope that excludes the interviewing agent you are buying is a soft fail.
---
Common buyer mistakes (and how to avoid them)
Mistake 1: Treating 42001 as a bias audit. AIMS certification is governance process evidence. Adverse-impact testing is empirical evidence about outcomes for protected groups. You need both when AI influences who advances.
Mistake 2: Treating SOC 2 as AI governance. SOC 2 is necessary for enterprise security reviews. It does not, by itself, prove AI impact assessments, lifecycle controls, or human-oversight design for hiring models.
Mistake 3: Treating jurisdiction notice as vendor certification. NYC Local Law 144-style notice and annual bias-audit publication obligations are primarily employer process duties (orientation only — confirm with counsel). A vendor certificate does not post your notices for you.
Mistake 4: Inventing a vendor’s certificate. If a product page is silent, say so. This article states plainly that Braintrust does not publish ISO/IEC 42001 on AIR / compliance / pricing surfaces as of research time. Buyers should still evaluate AIR’s published SOC 2, bias-audit, and HITL artifacts — and ask roadmap questions in writing.
Mistake 5: Letting a certificate excuse auto-decisioning. If the product auto-rejects without meaningful human authority, fail oversight regardless of AIMS status. Braintrust’s published AIR posture is the opposite: scorecards and evidence for humans; no auto-reject.
---
How this page relates to other Braintrust compliance content
Use this page for the AIMS / 42001 procurement question. Use the compliance hubs for jurisdiction mapping. Use the trust-gap post for why teams adopt AI faster than they trust it.
- How Braintrust AIR stays compliant — regulatory orientation + what AIR does (HITL, notices, logging).
- AIR Compliance — bias-audit categories, SOC 2, explainability, NYC LL144 Ready language.
- AI hiring trust gap — why teams use AI more than they fully trust it.
- What is AI interview software? — category definitions.
Each of those pages answers a different diligence question — send your security reviewer to the one that matches the ask.
FAQ
Should TA buyers require ISO/IEC 42001 from AI hiring vendors?
Treat accredited ISO/IEC 42001 certification as a strong procurement checkpoint for AI governance — not as a legal safe harbor and not as a substitute for independent bias audits, jurisdiction notice, or human decision authority. Ask for the certificate, scope statement, certification body, and validity dates.
What is ISO/IEC 42001 / an AIMS?
ISO/IEC 42001:2023 is the first international management-system standard for artificial intelligence. An Artificial Intelligence Management System (AIMS) is the set of policies, roles, risk and impact processes, lifecycle controls, and continual-improvement practices an organization uses to govern AI responsibly. ISO publishes the standard; accredited certification bodies audit vendors.
Does ISO/IEC 42001 replace SOC 2?
No. SOC 2 Type II attests to security, availability, and related trust-service criteria. ISO/IEC 42001 attests to AI management-system governance. Buyers typically want both when AI touches hiring decisions. See Braintrust’s published SOC 2 language on pricing and AIR Compliance.
Does ISO/IEC 42001 replace a bias audit or NYC LL144 notice?
No. A third-party bias audit tests adverse impact on the tool and population in scope. Jurisdiction rules such as NYC Local Law 144 still require notice, published audit summaries, and employer accountability. Fountain’s September 14, 2026 guide explicitly notes that 42001 is not a substitute for compliance.
Which AI hiring vendors claim ISO/IEC 42001 in 2026?
Public announcements include Greenhouse (February 2026), Fountain (April 2026 certification announcement), and PageUp (September 8, 2026). Always verify live certificate scope and validity with the vendor’s trust center — do not rely on a blog paraphrase alone.
Is Braintrust ISO/IEC 42001 certified?
As of this article’s research date, Braintrust does not publish an ISO/IEC 42001 certification on its AIR product, compliance, or pricing pages. Braintrust does publish SOC 2 Type II, a third-party bias audit with No Exceptions across tested categories, human-in-the-loop decisioning (AIR does not auto-reject), and compliance documentation for jurisdiction orientation on AIR Compliance and How AIR stays compliant.
What should we ask vendors for in an RFP?
Ask for the certificate PDF, certified scope (which products), Statement of Applicability or equivalent control map, certification body and accreditation, validity/surveillance dates, independent bias-audit results, override/HITL demonstration, candidate notice templates, and whether candidate data may train models.
How does Braintrust AIR approach compliance without a published 42001 cert?
AIR publishes human-in-the-loop screening (recruiters decide), explainable scorecards with evidence, SOC 2 Type II, third-party bias-audit results, and jurisdiction-oriented documentation on the compliance hubs. Evaluate those artifacts directly — and ask sales if a 42001 roadmap or equivalent AIMS evidence exists for your security review. Try AIR or book a demo.
