Oracle, Microsoft and Workday Hold ISO 42001 Certificates: What They Cover and What Stays With Customers

Updated: 6 days ago
Title: Oracle, Microsoft and Workday Hold ISO 42001 Certificates: What They Cover and What Stays With Customers
Date: 10 July 2026
Type: Blog
Author: SAASiQ (contact@saasiq.ai)
Word count: 1444 words
Reading time: 6 min
Published: 10-07-2026
Oracle, Microsoft, Salesforce, SAP and Workday have all had their AI management systems certified to ISO/IEC 42001, the international standard for governing AI, and Microsoft 365 Copilot passed its annual audit in May with no findings. The EU's amendments to the AI Act cleared their last vote on 29 June. A certificate covers how the vendor governs its own AI, and Oracle, for one, spells out which part of the work stays with the customer.
What the standard is
ISO/IEC 42001 was published by ISO and the IEC in December 2023. It is a management system standard, so it describes how an organisation runs AI (who is accountable, how risk is assessed, how changes are controlled and reviewed) and says little about how any particular model should behave. Its structure follows ISO/IEC 27001:2022, the information security standard, with the same plan-do-check-act cycle, and Oracle's own guidance points out that organisations can reuse policies, audit programmes and templates from earlier ISO certifications.
The part with no equivalent in 27001 is the AI system impact assessment. Clause 6.1.4 requires a process for assessing the consequences an AI system can have for individuals, groups and society, and clause 8.4 requires the assessment to be carried out at planned intervals and whenever a system changes materially, with the results kept. Annex A lists 38 controls in nine areas, from AI policy and data for AI systems to third-party and customer relationships.
Certification is done by accredited bodies. ISO/IEC 42006, published on 31 July 2025, sets the requirements those bodies have to meet, including the competence of their auditors and how audit time is calculated.
Who holds a certificate
AWS announced accredited certification on 25 November 2024, the first major cloud provider to do so by its own account, covering Amazon Bedrock, Amazon Q Business, Amazon Textract and Amazon Transcribe. Anthropic announced its certificate, covering the Claude models, on 13 January 2025. Microsoft 365 Copilot was first certified in March 2025, and Help Net Security reported on 28 May 2026 that its recertification audit found no non-conformities and no improvement observations, with Copilot Studio added to the scope.
Among the finance and HR suites, Workday announced ISO 42001 certification from Schellman on 12 June 2025, alongside an attestation against the NIST AI Risk Management Framework from Coalfire. Salesforce followed on 8 October 2025 for Agentforce, its Einstein AI platform and Slack AI, audited by BDO, and SAP holds a certificate for the management system that governs AI in SAP and its products. Typeform, the online forms company, announced its certificate on 24 June 2026.
Oracle's certificate and the Fusion side
Oracle announced in March 2026 that Oracle America had been certified by Schellman Compliance, which is accredited by the ANSI National Accreditation Board. The certificate covers several management systems: OCI's AI services (Data Science, Document Understanding, Generative AI, Generative AI Agents, Language, Speech and Vision), Oracle Health, Oracle Life Sciences, Oracle SaaS on OCI and NetSuite. Oracle says customers using the certified services inherit parts of its management system, such as its risk assessment methods, monitoring and governance procedures.
A follow-up article from Oracle in June set out where the line falls. Oracle, as the AI service provider, is responsible for model lifecycle governance, impact assessments and prohibited-practice controls. Every customer-facing Oracle AI feature has to pass an internal gate called the Oracle AI Review, which Oracle ties to clause 6.1.4. The customer is responsible for how agents are configured, how prompts are governed, how outputs are checked and how deployed agents are monitored, and risk classification, data handling and incident response are shared.
For customers building in AI Agent Studio for Fusion Applications, Oracle points to what it calls the METRO framework (measurement, evaluation, tracing, reporting and observability). It scores agent answers with a model acting as judge, which can be compared with a human score, traces each run of an agent step by step, reports response times at the 50th and 99th percentiles, and shows the input and output tokens used by each model call.
What a certificate does not cover
A vendor's certificate says its management system meets the standard. It does not show that a particular AI system complies with the EU AI Act. A Cloud Security Alliance research note of 28 April 2026 set out the difference: ISO 42001 applies to an organisation, while the Act regulates each high-risk AI system as a product. ISO 42001 also gives no presumption of conformity under the Act, and the note lists gaps, among them the Act's timelines for reporting serious incidents and its fundamental rights requirements.
The standard written for that purpose is prEN 18286, which CEN and CENELEC are preparing for the quality management system that Article 17 requires of high-risk AI providers. Its public enquiry closed on 22 January 2026, and it includes an annex mapping its requirements to the ISO 42001 Annex A controls, so work done for one carries over to the other.
The timing of the high-risk rules is also changing. The European Parliament adopted the Digital Omnibus on AI on 16 June by 423 votes to 57, with 174 abstentions, and the Council gave its final approval on 29 June. Once published in the Official Journal, it moves the obligations for high-risk systems listed in Annex III, which include recruitment and credit decisions, to 2 December 2027, and those for AI built into products regulated under Annex I to 2 August 2028. Until publication, the original timeline still applies.
Marking what AI produced
The AI Act's transparency rules in Article 50 apply from 2 August 2026. Providers of generative systems have to mark outputs in a machine-readable form so that they can be detected as AI-generated, and deployers have to disclose deepfakes and AI-generated text published on matters of public interest. Under the Omnibus text, systems already on the market before 2 August have until 2 December 2026 to meet the marking rules.
The Commission published its final Code of Practice on marking and labelling AI-generated content on 10 June. It is voluntary, it proposes EU icons for fully AI-generated and partly AI-modified content, and organisations that want to be on the first list of signatories have until 22 July. For a finance or HR team the practical point is a record of which outputs in a decision or a client deliverable were machine-generated.
Securing the data AI can reach
In June Oracle set out an AI security strategy for its database under three headings, secure at source, secure at speed and secure through resilience. The first puts controls in the database itself (SQL Firewall, Database Vault and Deep Data Security), so an AI agent querying the data meets the same authorisation rules as any other user. Oracle also made Database Lifecycle Management Pack, Exadata Management Pack, Data Safe for on-premises databases and Database Security Central free from 12 June 2026 to 28 February 2027 (the management packs for patching and upgrades only), and cut GoldenGate, GoldenGate Veridata and Real Application Testing by 90 per cent on one-year term licences for patching and upgrades until 31 May 2027.
Our own rule on SAASiQ engagements is that client data does not reach an external AI service unmasked: sensitive fields are masked or replaced with consistent tokens before anything leaves the controlled environment.
Supplier continuity
Annex A's controls on third-party relationships cover suppliers, including model providers. Anthropic switched off Claude Fable 5 for every customer on 12 June after a US Department of Commerce directive placed it under export controls, and the model came back on 1 July after the controls were lifted on 30 June. Buying through a cloud provider made no difference, because the control applied to the model.
In SAASiQ's view that belongs in the supplier section of an ISO 42001 risk assessment, with a tested fallback model and a record of which workflows depend on which provider.
Starting without a certificate
Certification is voluntary, and nothing stops an organisation using the standard's requirements as a checklist without an auditor. The first item is an inventory of where AI is in use, including features that arrived in a vendor's quarterly update, each with a named owner. Next come impact assessments for uses that affect employment or credit decisions, and a documented data path showing what leaves the organisation and in what form.
When buying, ask each vendor for its certificate and its scope. Oracle's lists specific services, and a product outside that list is outside the certificate.
The Omnibus has to be published in the Official Journal before 2 August to take effect in time, and the list of initial signatories to the marking code closes on 22 July.
SAASiQ - Intelligent Solutions for SaaS ©


