AI Governance Certification: ISO 42001, AIGP, plus NIST AI RMF
ISO/IEC 42001 certifies an organization’s AI management system. IAPP AIGP credentials people, and NIST AI RMF offers voluntary guidance. This guide separates the programs and explains the runtime evidence none of them automatically produces.

ISO/IEC 42001:2023 is the international standard that certification bodies use to assess an organization's AI management system. That is the direct answer to a procurement form asking which AI governance certification applies to an organization. IAPP AIGP credentials an individual. The NIST AI Risk Management Framework provides voluntary guidance without a NIST certificate.
The ISO 42001 standard page describes the AI management-system standard, while NIST's AI RMF page defines the voluntary framework. I want to separate these programs because "AI governance certified" can otherwise hide three very different claims in a vendor response.
TL;DR
Ask vendors for the ISO/IEC 42001 certificate scope, validate individual credentials separately, map NIST AI RMF as voluntary guidance, and test the runtime evidence route that certification does not prove.
ISO/IEC 42001 certifies the organization
ISO/IEC 42001 specifies requirements for establishing and implementing an AI management system. It also covers maintenance and continual improvement. An accredited certification body evaluates the organization's documented scope and leadership accountability. It also reviews risk treatment and operational controls. Performance evaluation and the improvement process complete the assessment.
The certificate applies to the organization and the stated scope of its management system. Procurement should ask for the certificate and issuing certification body. It should also obtain the scope statement and issue date. Record the expiry date plus the included AI services or business units. A logo on a sales page leaves out the information that makes the claim reviewable.
ISO/IEC 42001 also has limits that buyers should welcome rather than obscure. The standard governs the system of management around AI. It does not prescribe one universal runtime architecture or certify every individual model response. That distinction matters when a regulated customer needs evidence about a decision that occurred on a specific Tuesday afternoon.
AIGP and other professional credentials
The IAPP Artificial Intelligence Governance Professional credential evaluates an individual's knowledge of AI governance and risk. It also covers relevant laws plus responsible deployment. Organizations can use it to show that the people staffing a governance function have relevant training. The credential remains an individual qualification.
ISACA credentials can also be relevant when the operating model sits inside an established information-security or enterprise-governance function. The right question is practical: who owns the AI inventory and risk review? Who approves policy? The governance owner should handle escalation and complete supplier review. A credential helps establish competence; it cannot substitute for the records that show those processes operated.
NIST AI RMF provides a voluntary control structure
NIST AI RMF organizes work across GOVERN, MAP, MEASURE, plus MANAGE. Organizations can use the functions to structure policy and risk assessment. Testing, monitoring, and improvement provide the operating evidence. NIST does not issue an AI RMF certificate, so a claim of "NIST AI RMF certified" needs correction before it reaches a proposal or audit package.
The framework remains useful in a certification program. Map its outcomes to the ISO/IEC 42001 management-system scope. Assign owners and retain the risk and control evidence that supports both. The AI governance and risk management guide gives a practical mapping path for that work.
Executive Order 14179 was federal policy, not a certification
Executive Order 14179 was a United States federal policy instrument, not an organizational certification scheme. It was revoked by Executive Order 14148, issued on 20 January 2025. A vendor cannot present either order as an ISO-style certificate.
For federal work, identify the current contract clause, agency policy, authorization process, and evidence request instead of treating a historic executive order as a compliance badge. Federal requirements can shape procurement. They do not convert an individual credential or a management-system certificate into a per-decision evidence record.
Certification evidence and runtime evidence
An ISO/IEC 42001 auditor may review policies, roles, risk assessments, internal-audit results, corrective actions, and samples of operating controls. A regulator investigating an AI outcome can ask which user or agent initiated the request. It can also ask what data was supplied, which model endpoint responded, which policy applied, and what happened next.
The EU AI Act treats logging as a traceability requirement for high-risk systems. An AI management system can establish the governance around that requirement. The decision records themselves need a runtime source and retention treatment. They also need a retrieval process. The EU AI Act Article 12 logging guide explains the required evidence boundary in detail.
My view is blunt: a certificate without a tested decision-evidence path is a procurement asset, not an operational control. Keep the certificate. Run a sample request through the production route. Retrieve its identity, policy, model, outcome, and retention evidence before the customer asks for it.
DeepInspect
DeepInspect sits between authenticated users or agents and the LLM endpoints they call over HTTP. It can evaluate routed requests against identity-aware policy. The per-decision record can retain request context, policy outcome, selected model endpoint, and correlation identifier.
That evidence can support the operational side of an ISO/IEC 42001 management system. The organization still owns the management-system scope and risk process. Training, supplier management, internal audit, and controls for local or downstream activity remain outside the LLM HTTP route.
Book a technical deep dive at deepinspect.ai.
Frequently asked questions
- Which AI governance certification is an international standard for organizations?
ISO/IEC 42001:2023 is the international AI management-system standard. An organization can seek certification from an accredited certification body for the scope defined in its management system.
- Is NIST AI RMF a certification?
NIST AI RMF is a voluntary framework. NIST does not issue AI RMF certificates, so organizations should describe their claim as alignment or implementation and retain the supporting evidence.
- Is IAPP AIGP an organizational AI governance certification?
IAPP AIGP is a professional credential for an individual. It can support staffing and competence claims, while ISO/IEC 42001 addresses an organization's AI management system.
- Does ISO/IEC 42001 certification satisfy EU AI Act logging obligations?
Certification can demonstrate management-system governance. EU AI Act traceability duties require the relevant system logs and an operating process that can retrieve them, so the organization needs both the management system and decision-level evidence.