ISO 42001 is starting to appear in family office platform RFPs and board conversations, but often without a clear understanding of what the certification actually verifies. This piece explains it plainly. What ISO 42001 is, what it certifies, why it matters specifically for wealth management, and how the AtlasFive® platform by Eton Solutions has been certified against it.
If you are evaluating an AI-enabled family office platform, ISO 42001 is now one of the most important questions to ask.
What ISO 42001 is
ISO 42001 is the international standard for AI Management Systems, published by the International Organization for Standardization in late 2023. It is the first internationally recognised standard specifically focused on how organisations govern, deploy, and manage artificial intelligence.
Where ISO 27001 governs information security and SOC 2 Type II attests to security and operational controls, ISO 42001 sits in the specific gap that AI creates: the need to prove that AI is being developed and used responsibly, with appropriate oversight, transparency, and accountability throughout its lifecycle.
Certification is granted by independent accredited bodies (such as A-LIGN, which certified Eton Solutions) after audit against the ISO 42001 standard. Certification is not a self-attested claim. It is a verified statement that the organisation has an AI Management System that meets the requirements of the standard.
What ISO 42001 actually certifies
ISO 42001 certifies that an organisation has designed, implemented, and operates a documented AI Management System covering the following areas:
Governance and accountability. Clear ownership of AI systems within the organisation. Documented roles and responsibilities. Board-level oversight of AI risk.
Risk assessment and treatment. Systematic identification of risks associated with each AI system, including risks of bias, fairness issues, security vulnerabilities, and unintended consequences. Documented treatment plans for identified risks.
Data governance for AI. Standards for the data used to train, tune, and operate AI systems. Controls to prevent inappropriate data use, including protection against training on customer data in ways that expose it to other clients.
Human oversight and intervention. Documented human-in-the-loop controls where AI systems make consequential decisions. Clear paths for human intervention and override.
Transparency and explainability. Documentation of what AI systems do, what data they use, and how their outputs should be interpreted. Not black-box AI.
Incident management. Documented procedures for detecting, responding to, and learning from AI incidents such as unexpected behaviour, errors, or performance degradation.
Continual improvement. A management system that reviews AI performance, identifies improvement opportunities, and iterates on controls over time.
A certified organisation has been audited against all of these areas and found to be operating in compliance with the standard. It is not a marketing claim. It is a third-party attestation.
Why ISO 42001 matters for family offices
Family offices handle some of the most sensitive personal and financial data in the world. As AI systems take on more of the operational work in a family office (document classification, transaction processing, tax working papers, first-draft investor materials), the question of how that AI is governed becomes a direct fiduciary concern.
Three specific reasons ISO 42001 matters in this context:
First, it addresses board-level risk. Family office boards and family principals increasingly ask how the office’s technology providers govern their AI. An ISO 42001-certified platform gives a defensible answer to that question. An uncertified platform requires the office to rely on the vendor’s own claims.
Second, it addresses data sovereignty. ISO 42001 requires documented controls on how customer data is used in AI training and operations. Combined with tenant isolation and Bring Your Own
Key encryption, ISO 42001 certification provides real assurance that the family office’s data is not being used to improve models serving other clients.
Third, it addresses the audit conversation. External auditors and regulators are beginning to ask about AI governance in the same way they have asked about cybersecurity and privacy for the past decade. Having an ISO 42001-certified platform in place gets ahead of that conversation rather than reacting to it.
How AtlasFive® achieves ISO 42001
The Eton Solutions AtlasFive® platform is one of the first family office platforms globally to achieve ISO 42001 certification. The certification applies across the Eton Solutions group, including Eton Solutions L.P. (United States), Eton Solutions and Technologies India LLP, and Eton Solutions International Pte. Ltd. (Singapore).
The AI Management System operating behind the certification governs the four autonomous agents that make up the EtonAI™ productivity layer running on AtlasFive®: the Web Agent that retrieves statements from custodian portals, the Document Processing Agent that classifies 250+ document types, the Ask EtonAI™ natural-language interface, and the Investor Tear Sheet Agent that generates first-draft materials.
Each of these agents operates under documented human oversight controls, exception-handling procedures, and continuous performance monitoring. The audit trail is comprehensive. Every action taken by an agent is logged, versioned, and reviewable. Data does not leak between tenants. Customer data is not used to train models serving other clients.
The ISO 42001 certification sits alongside SOC 1 Type II, SOC 2 Type II, ISO 27001, and ISO 27701. Together, this certification profile provides institutional-grade assurance that AtlasFive® is not only technically capable but appropriately governed for the sensitivity of family office data.
What to ask when evaluating a family office platform
If you are evaluating any AI-enabled family office platform in 2026 or 2027, three questions worth asking specifically:
- Is the platform certified against ISO 42001, and can you provide the certificate?
- If not, when do you plan to achieve certification?
- What controls do you operate today that would meet the standard, and how are those controls audited?
Vendors that hold the certification will provide the certificate readily. Vendors that do not hold it should have a credible answer about when they will and what they operate today. Vendors that deflect on both questions are worth approaching with caution.
Frequently asked questions
Q: What is ISO 42001?
A: ISO 42001 is the international standard for AI Management Systems, published by the International Organization for Standardization in late 2023. It is the first internationally recognised standard specifically focused on how organisations govern, deploy, and manage artificial intelligence. Certification is granted by independent accredited bodies after audit against the standard.
Q: What does ISO 42001 certify?
A: ISO 42001 certifies that an organisation has designed, implemented, and operates a documented AI Management System covering governance and accountability, risk assessment, data governance, human oversight, transparency and explainability, incident management, and continual improvement. Certification is a third-party attestation, not a self-attested claim.
Q: Is Eton Solutions ISO 42001 certified?
A: Yes. Eton Solutions is one of the first family office platforms globally to achieve ISO 42001 certification for AI Management, alongside SOC 1 Type II, SOC 2 Type II, ISO 27001, and ISO 27701. The certifications apply across the Eton Solutions group. The AtlasFive® platform and EtonAI™ agents operate under the certified AI Management System.
Q: How is ISO 42001 different from SOC 2 or ISO 27001?
A: ISO 27001 governs information security management. SOC 2 Type II attests to security, availability, processing integrity, confidentiality, and privacy controls over time. ISO 42001 is specifically focused on AI management: how AI systems are governed, monitored, made transparent, and controlled. The three standards are complementary, not overlapping. A serious AI-enabled platform should hold all three.
Q: Why does ISO 42001 matter for family offices?
A: ISO 42001 matters for family offices because it addresses three specific concerns: board-level risk around AI governance, data sovereignty in AI training and operations, and the audit conversation that regulators are beginning to focus on. As AI systems take on more of the operational work in a family office, an ISO 42001-certified platform gives a defensible answer to how that AI is governed.
Q: How can I verify a vendor’s ISO 42001 certification?
A: You can verify a vendor’s ISO 42001 certification by requesting the actual certificate from the vendor, which will name the accredited certification body (such as A-LIGN or NQA) and the scope of the certification. Certified vendors will provide this readily. You can then cross-check the certification with the accreditation body’s registry.