
What ISO/IEC 42001 actually certifies
ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence. It was published in December 2023 and sets out what an organisation has to do to govern AI responsibly across its whole lifecycle: risk assessment, impact assessment, data governance, supplier management, human oversight, monitoring and continual improvement. You can read the standard on the ISO catalogue.
It is a management system standard, not a product label. It does not certify that a model is accurate. It certifies that the organisation running the model has a governed system for deciding what AI to use, how to deploy it, who is accountable, how it is monitored in production, and what happens when something goes wrong. That distinction matters in regulated lending, where the question a compliance director asks is rarely "is the model good" and almost always "who owns this, and can you show me the record".
Certification is independent. An accredited body audits the system against the standard, and then keeps auditing it. Ours came from ISOQAR, accredited by UKAS. The certificate itself states that it remains current only while we maintain the system to the required standard, and ISOQAR monitors that on a surveillance cycle.
The scope, in plain terms
Scope is the part of an ISO certificate that most people skip and every procurement team reads. Ours reads as the AI management system of Curved Stone Ltd, acting as an AI provider, for the procurement, integration, deployment, maintenance and governance of AI-enabled workflow automation services to clients through third-party AI models, in accordance with our Statement of Applicability version 1.1.
That wording is deliberate, and three parts of it are worth pulling out.
- AI provider. Curvestone is the party supplying the AI-enabled service to the client. We are not describing an internal AI experiment. The certified system is the one behind what customers buy.
- Through third-party AI models. We do not train frontier models. We build the compliance intelligence on top of models from providers such as OpenAI and Microsoft Azure, which is why supplier governance and staged model release are central controls rather than afterthoughts.
- Procurement to governance. The scope runs end to end. It covers how a model gets chosen and evaluated, how it reaches production, how it is monitored once live, and how it is retired.
The certificate number is 19087, the same registration number as our ISO 27001:2022 certificate. Both are listed in the Curvestone Trust Centre, and the certificate PDF is available there on request.
What changed for customers, and what did not
The controls did not appear overnight. Our platform AI Policy already governed vendor evaluation, staged model release with automated evaluation and senior sign-off, live monitoring, incident response and decommissioning. What changed is the evidence standard. Until August, that policy was aligned with ISO/IEC 42001. It is now certified against it, audited by a third party.
For a compliance director running a due diligence exercise, the practical difference is what you can put in a file. Aligned is a claim the vendor makes about itself. Certified is a claim an accredited auditor has tested, dated and will re-test. When you are the accountable person for a decision to automate regulatory work, only one of those two survives a question from your board.
It also closes a gap we have written about before. We have argued that the AI trust problem in financial services is an evidence problem rather than a confidence problem, and that explainability cannot be retrofitted once a regulator asks. It would be inconsistent to hold that position about our customers and not evidence our own AI governance to the same bar.
Aligned is a claim the vendor makes about itself. Certified is a claim an accredited auditor has tested, dated and will re-test.
Why this matters more in regulated lending than elsewhere
A mortgage network, lender or wealth firm that adopts AI does not transfer its accountability to the vendor. Under the FCA senior managers regime, an accountable individual still owns the outcome, and the FCA has been explicit that existing rules already apply to AI rather than waiting for a new AI rulebook. We covered that position in our note on the Mills Review.
The consequence is that your AI vendor becomes part of your control environment. When the supervisor asks how you assured the tool that reviewed 12,000 case files, "the vendor told us it was fine" is not an answer. A dated certificate against a recognised standard, with a named accreditation body and a defined scope, is.
It also shortens procurement. Firms in our sector run long AI due diligence questionnaires, and a large share of the questions map to clauses the standard already requires us to evidence: risk assessment, impact assessment, data governance, human oversight, supplier controls, monitoring. Certification does not remove those questions, but it gives a single audited answer to many of them.
"The vendor told us it was fine" is not an answer.
What comes next
Certification is a floor, not a finish. The standard requires continual improvement and ISOQAR will audit the system on a recurring surveillance cycle, with the current registration period running to 14 August 2029.
Our own next steps are the ones that follow from the scope above: keep the Statement of Applicability current as we broaden the checks the platform can run, keep AI governance tracking UK GDPR, ICO guidance and the parts of the EU AI Act relevant to our risk tier, and keep publishing what we hold rather than describing it.
If you are assessing Curvestone, the fastest route is the Trust Centre. The ISO/IEC 42001 certificate, the ISO 27001 certificate, the Statement of Applicability, the AI Policy overview and the latest CREST accredited penetration test summary are all requestable there.
AI explainability is not optional in regulated compliance
AI explainability means a compliance officer can see which rule an AI flag relied on, which document triggered it, and what evidence sits behind it. In regulated lending it is not a premium feature. It is the baseline the FCA already expects, because a decision no one can explain is a decision no one can defend.
DefinitionModel risk management for AI: from validation to live monitoring
Model risk management is how a firm governs the models behind its decisions, across development, validation and monitoring. The Mills Review says AI forces it to evolve: models now update continuously and can drift, so governance must extend beyond a point-in-time check to live monitoring across the whole model lifecycle.
DefinitionWhat is the Mills Review? The FCA's AI review, explained
The Mills Review is the FCA's July 2026 report on how AI will reshape retail financial services by 2030, led by Sheldon Mills. It sets out an AI autonomy spectrum, four system shifts and seven recommendations. It writes no new AI rules; it raises the bar on how firms evidence the rules they already follow.

Dawid Kotur
CEO and co-founder, Curvestone
Dawid co-founded Curvestone in 2024 after a decade working at the intersection of financial services and applied machine learning. He writes about the strategic direction of regulated-industry AI, the FCA's evolving approach to model risk, and the operational changes UK lenders are making in response to Consumer Duty. He sits on the FCA Smart Data Accelerator advisory cohort.
LinkedIn