Read More

ISO 42001 Certification

We Certify That Your AI Is Built to Be Accountable

Decrypt is one of the few boutique CPA firms in the country offering ISO 42001 certification, led by a Forbes-recognized CPA with Big 4 credentials and hands-on experience running AI governance audits for B2B SaaS teams.
Logo of the California Board of Accountancy with large blue letters CBA above the words California Board of Accountancy in blue on a white background.
California CPA License #9491
A blue circular badge with AICPA SOC in white text, aicpa.org/soc4so below, and SOC for Service Organizations along the bottom edge.
AICPA Accredited
A green oval badge with the text Status: Active at the top, IAF in large letters over a globe, and IAFCERTSEARCH.ORG at the bottom.
Accredited ISO 27001 Auditor
The HITRUST logo with the words Validated Assessor written beneath it in green text.
Authorized HITRUST Assessment Provider

What Is a ISO 42001?

ISO 42001 is the international standard for AI Management Systems (AIMS). Published in 2023, it’s the first certification framework built specifically for organizations that develop, provide, or use AI systems.

Where SOC 2 covers data security and ISO 27001 covers information security broadly, ISO 42001 focuses on how your organization governs AI, the risks it creates, the decisions it makes, and the oversight structures you have in place to keep it accountable. ISO 42001 answers “who’s accountable when your AI makes a bad call?”

Who Needs ISO 42001?

This certification makes sense for any company where AI is part of the product or the operation. That typically includes:

Why Choose Decrypt For ISO 42001 Certification

A teal line icon showing documents with a magnifying glass and check mark, surrounded by gears, arrows, and three people, symbolizing workflow, teamwork, process management, or ISO 27001 Certification.

Most audit firms don't offer this yet

ISO 42001 is new enough that most certification bodies haven’t built out a real practice around it. Decrypt has. If you need ISO 42001 alongside SOC 2 or ISO 27001, you can run all three with one team.
A blue outlined icon showing two people with arrows between them, a document in the center, and a checkmark above, representing approval or agreement between individuals.

The same team runs your audit from kickoff to certificate

At larger firms, the people you meet during sales aren’t the people who run your audit. Decrypt is structured differently. You work with the same team throughout, and when your engagement wraps, they already know your systems.
A turquoise line drawing of a crowned figure pointing forward, standing by a ships wheel with an arrow, and a group of people behind, symbolizing leadership and guidance.

Big 4 credentials, founder-led firm

Raymond Cheng holds the CPA.CITP, CISSP, CISA, and ISO 27001 Lead Auditor certifications. He’s recognized in Forbes’ America’s Best-In-State CPAs and received the AICPA Tech Advisory Standing Ovation Award in 2024.
Light blue outline icon of a person wearing a headset and suit, with a document and magnifying glass featuring an ISO 27001 Certification checkmark, all inside a circle on a white background.

We actually perform the audit

A lot of firms will help you get ready for ISO 42001. Decrypt performs the certification audit itself. That means one team, one invoice, and no readiness consultant handing you off to a separate audit firm at the end.

Our Reviews

Client Stories

4.9 out of 5

Our Latest Articles

Cybersecurity Resources and Insights from Decrypt Experts

Frequently Asked Questions

Get Started

Ready to Get Certified and Close More Deals?

Tell us about your company and we’ll get back to you with a clear path to certification – including timeline and pricing.

Consultation form

Name(Required)