An AI Governance Standard with a Vendor’s Fingerprints on It

Eighty-three percent of UK finance teams are already using artificial intelligence, and just 53% have a formal policy governing how they use it. That gap comes from a survey of 250 UK finance decision-makers commissioned by cloud accounting provider iplicit, and it is not a finance problem alone.

ISO/IEC 42001, the first international standard for the responsible governance of AI systems, published in December 2023 by the International Organization for Standardization and the International Electrotechnical Commission, is built to close exactly that gap. It also happens to double as a sales pitch for the company that paid for the numbers behind it.

Finance Teams Are Sprinting Past Their Own AI Rules

The 53% figure undersells the problem. iplicit’s research found that among finance teams that have not formally adopted AI at all, 46% are already running AI assistants and 30% are using AI-powered forecasting and analysis regardless. Compliance teams have a name for this: shadow AI, tools adopted informally and outside any sanctioned process.

A further breakdown of the same research, reported by trade outlet Intelligent SME.tech, found that partial adopters, defined as teams using AI in some workflows but not others, made up the largest single group at 48% of respondents. Only 45% of that group has any formal policy at all.

  • 83% of UK finance decision-makers say their function is already using AI in some form.
  • 53% have a formal framework covering its safe and compliant use.
  • 46% and 30% of finance teams without formal AI adoption are still running AI assistants and AI-powered forecasting, respectively.
  • 48% of respondents are partial adopters, and only 45% of that group has a policy in place.

Ed Gairdner, iplicit’s chief of staff and a tech compliance expert, argues the pattern almost certainly repeats in other departments beyond finance. Marketing teams run AI copy tools. Sales teams run AI call summaries. Few of those uses show up in a governance register anywhere.

What Must an AI Vendor Prove?

ISO 42001 asks an AI provider to show its outputs can be traced and explained, that a human stays in the loop, and that risk gets reassessed on an ongoing basis rather than signed off once and forgotten. It borrows its management-system structure from ISO 27001, the established standard for information security, but adds requirements written specifically for AI: bias controls, model lifecycle oversight and third-party supplier accountability.

The standard lays out requirements for governing AI projects, models and data across their full lifecycle, and it applies to any organization that builds AI tools or simply uses someone else’s. A business does not need to certify against it to use it as a checklist. iplicit’s own framing makes that point directly: certification is optional, the evaluation habit is not.

Explainability Is Not Optional

“ISO 42001 requires that AI outputs can be explained and traced,” Gairdner said. Whether a system is producing a finance report, running a reconciliation or flagging an anomaly, someone inside the vendor needs to be able to say what it did and why, on request, not just in theory.

Five Questions Every AI Vendor Should Face

Gairdner lays out five specific questions any business should put to a software provider before trusting it with sensitive workflows. Each one maps to a distinct piece of the standard.

Question to the Vendor What ISO 42001 Is Testing Red Flag in the Answer
How are systems developed, tested and monitored? Traceability and a documented human in the loop No one can explain a specific output after the fact
How is the output produced, and what happens when it is wrong? Whether AI draws on verified core data or predicts freehand The vendor cannot say where a number came from
How is performance drift managed over time? Ongoing risk assessment written into the standard’s clause 6.1 Monitoring stops once the system goes live
Who is accountable for the AI inside the provider’s business? Clear, named ownership of systems and their outputs No one owns the AI’s governance
Does the vendor train on your data? Data governance and a zero-retention policy A vague or evasive answer on model training

The third question, on performance drift, addresses something AI users run into constantly: a model that quietly gets worse at a task it used to handle well. Ongoing risk assessment across the AI lifecycle is exactly what the standard demands on top of the security controls already required under ISO 27001.

A Question That Reads Like Marketing

Question two asks whether an AI feature is bolted onto a core system and drawing on its verified data, or generated predictively the way a large language model works. Question five asks whether a vendor trains its models on customer data at all.

Both questions describe, almost exactly, how iplicit pitches its own product. The company markets its AI for the FD guide around AI features that read from a single ledger rather than a bolted-on chat layer, and Gairdner is explicit that customers should look for a zero-retention policy, where data is used only in a live, read-only state and never fed back into training.

None of that makes the advice wrong. A finance system that hallucinates a reconciliation is a genuinely different risk than a marketing tool that hallucinates a headline, and the distinction is one every buyer should be asking about, from any vendor, iplicit included. It is worth knowing, all the same, that the checklist was written by the company whose product it favors.

The data-training question is not unique to finance software. Samsung’s push into a wearable AI health assistant has drawn similar scrutiny over what happens to personal data once an AI feature is switched on, a sign this argument is spreading well past accounting software.

Certification Is Still Rare

The standard is two and a half years old. Actual certification against it is still a small club.

  1. December 2023: ISO/IEC 42001 is published as the world’s first management-system standard built specifically for artificial intelligence.
  2. Late January 2026: Boston Consulting Group announces it is among the first 100 organizations certified worldwide.
  3. Spring 2026: figures compiled from certification-body and company announcements point to roughly 350 organizations certified globally, still concentrated in technology and professional services.

There is no single public register tracking every certificate issued, so that count gets pieced together from press releases and certification-body statements rather than one official source. Even with that caveat, the shape of the gap is clear: 83% of finance teams in iplicit’s survey are already using AI, against a global certified population still numbered in the hundreds.

The Human Backstop

Gairdner uses finance to make a point that applies far beyond it: no amount of AI capability removes the human signature at the end of the process.

However capable AI gets, it won’t be signing the annual accounts any time soon.

That job stays with a human finance director (FD), chief financial officer or board, Gairdner said, and whoever signs is putting their name to a complete and accurate set of data drawn from a system they trust. He argues the same principle holds wherever AI is making decisions on a business’s behalf, not just inside a ledger.

Every one of Gairdner’s five questions ends the same way: with a named person, not an algorithm.

Frequently Asked Questions

Is ISO 42001 certification legally required in the UK?

No. Certification is voluntary and no UK law mandates it, though it is increasingly requested in vendor due-diligence questionnaires and procurement processes as a recognized signal that AI risk controls meet an international bar.

How is ISO 42001 different from ISO 27001?

ISO 27001 governs information security broadly. ISO 42001 shares its management-system structure but adds AI-specific requirements around bias, explainability, model drift and third-party AI supplier oversight, which is why organizations often pursue both standards together rather than choosing one.

What counts as shadow AI, and why does it matter?

Shadow AI is any AI tool used inside a business outside official channels or oversight, such as staff pasting company data into a free public chatbot. The risk is less about the task getting done wrong and more about sensitive data leaving the business with no record of where it went.

How long does ISO 42001 certification actually take?

Certification bodies typically run the process over several months, including a documentation review, a gap assessment against the standard’s clauses and a two-stage audit, a timeline similar to what organizations already experience pursuing ISO 27001.

Does ISO 42001 apply to a business that only uses third-party AI tools?

Yes. The standard is written for organizations that provide AI-based products or services and for those that simply use them, so a company that has never built a model can still apply its framework when vetting a supplier.

Leave a Reply

Your email address will not be published. Required fields are marked *