International AI Standards Are Taking Shape… A New Certification Shows Both Their Promise and Their Limits
What the New Certification Establishes
Can a Standard Keep Up With AI?
An International Effort, With a Defined Role
Click here to subscribe to the ESM weekly e-newsletter.
AI is advancing faster than governments can agree on how to oversee it. Yet an international standards effort is already underway, and businesses are beginning to use it. Loyalty Juggernaut’s newly announced certification shows what that effort can accomplish: an independent assessment of the management system governing its AI work. How much weight should we give that achievement. Will the practices remain useful as AI changes? Will certification improve decisions or become paperwork? And how much can an audit of one company do about problems that affect the entire market?
Loyalty Juggernaut provides software for companies to run and improve loyalty programs. Its platform, GRAVTY, keeps track of members and their activity, applies rules for earning and using points or other rewards, manages offers and outside partners, and shows the company whether the program is working. It can also use AI to suggest personalized offers and flag customers who may be losing interest.
The purpose of the ISO/IEC AI standards is to give organizations a common way to develop, use and oversee AI responsibly, even when they operate in different industries or countries. The standards cover different parts of that work. ISO/IEC 42001 sets requirements for an AI management system: assigning responsibility, assessing risks and improving practices as technology changes. ISO/IEC 42005 guides assessments of an AI system’s effects. ISO/IEC 42006 sets requirements for the organizations that audit and certify AI management systems.
In plain terms, the standards aim to make AI governance consistent and examinable across organizations. They can help customers and regulators ask better questions about a company’s practices. They cannot, by themselves, guarantee that an AI system is safe or replace laws and public oversight.
If governments incorporated compatible international AI standards into law, as has been done with other ISO standards in some countries, they could give companies a common, auditable foundation for managing AI risks across borders. A standard such as ISO/IEC 42001 could help establish how organizations assign responsibility, assess risks and document their decisions, while legislation would determine which practices are mandatory, what rights people have and how violations are enforced. This would leave room for companies to adapt their technology while giving regulators a practical way to examine their oversight. A certificate alone cannot establish that every AI system is safe, but standards backed by effective laws and enforcement could address a substantial part of the governance challenge.
What the New Certification Establishes
On Sept. 24, Loyalty Juggernaut announced that the British Standards Institution had certified its AI management system for loyalty to ISO/IEC 42001:2023. According to the company, the certified scope covers the development, deployment, oversight and continual improvement of AI capabilities within its GRAVTY loyalty platform, including systems used for personalization, fraud management and loyalty operations. Emirates Skywards, a customer quoted in the announcement, described the certification as a useful level of assurance as it considers new AI capabilities. Those are claims about the company’s stated practices and the scope of its certification, not proof that every AI decision made by GRAVTY is safe or beneficial.
That distinction matters because ISO/IEC 42001 sets requirements for an organization to establish, maintain and continually improve an AI management system. It concerns such questions as who is accountable, how risks are assessed and how practices are reviewed. It does not certify that a particular model will always produce an accurate or fair result. Nor does ISO issue the certificates; independent certification bodies do. ISO/IEC 42006:2025, a separate standard, sets requirements for bodies that audit and certify AI management systems.
Other companies that have obtained ISO AI standards certification.
Amazon Web Services announced accredited certification covering Amazon Bedrock, Amazon Q Business, Amazon Textract and Amazon Transcribe.
Google Cloud announced certification for its AI management system. Its current compliance page also lists Google Workspace and the Gemini app within its certified offerings.
Microsoft announced certification for Azure AI Foundry Models and Microsoft Security Copilot.
IBM promoted certification of the AI management system supporting its Granite language models.
Salesforce announced its first ISO 42001 certification; its later reporting identifies Agentforce, AI Platform and Slack AI as covered.
ServiceNow announced certification for the AI management system supporting ServiceNow AI.
Can a Standard Keep Up With AI?
The strongest objection to the use of ISO standards is speed. AI products can change between an audit and the next release. A standard that prescribed today’s models, techniques or acceptable outputs in detail could quickly become obsolete. Compliance work can also absorb time that would be better spent finding and fixing problems.
The answer offered by 42001 is narrower than a permanent technical rulebook. It asks an organization to maintain a process for identifying risks, assigning responsibility and improving its controls as its AI uses change. That design may help it remain relevant across changes in technology, but it does not guarantee that a company will recognize a new risk promptly or act on it well. The practical test is whether its management system changes what employees do when a new model, use case or failure appears.
Other standards can add more specific guidance. ISO/IEC 42005:2025 addresses assessments of the effects of AI systems, while 42001 supplies an organizational framework. Together, they offer a way to ask both whether a company has a process and whether it examines the consequences of the systems it puts into use. They still require capable people, current evidence and a willingness to change course.
A company certificate cannot govern the whole market. Skeptics argue that AI is a market challenge, while 42001 certifies individual organizations. That is a legitimate concern. A company can improve its own oversight without resolving harms that arise across platforms, supply chains or society. Voluntary certification cannot decide which uses of AI should be prohibited, establish public rights or enforce them. Governments retain those responsibilities, and customers and affected people need ways to challenge outcomes.
That does not make an organizational standard irrelevant. Buyers can ask a supplier what its certification covers, how it evaluates new uses, and what happens when something goes wrong. Governments can draw on standards for technical guidance where appropriate. Certification may give those conversations a common starting point, provided everyone understands its scope. Loyalty Juggernaut’s announcement is significant for precisely this reason: it shows a loyalty technology supplier submitting the management of its AI capabilities to an external assessment. The value to its customers will depend on the decisions and evidence behind the certificate, not the badge alone.
An International Effort, With a Defined Role
This work did not begin with the recent certification or with ChatGPT’s arrival. The joint ISO and International Electrotechnical Commission AI committee was created in 2017. ISO currently lists 61 participating national members and 24 observing members, along with 44 published standards and 49 under development. Their participation demonstrates substantial international engagement; it does not mean those countries have adopted identical AI laws or agreed on every proposed rule.
The case for paying attention to this effort is therefore more modest, and stronger, than saying it will solve the AI challenge. International standards can give organizations a shared vocabulary and auditable practices. The latest certification shows those practices entering a commercial market where customers have reason to ask how AI is governed. The skeptics remind us what to ask next: Is the certified scope clear? Do assessments respond to new risks quickly? Can auditors see evidence of effective action? And where company controls fall short, are public rules keeping pace? Those answers, along with the number of certificates issued, will determine whether this process earns trust.
Enterprise Engagement Alliance Services
Celebrating our 18th year, the Enterprise Engagement Alliance helps organizations enhance performance through:1. Information and marketing opportunities on stakeholder management and total rewards:
- ESM Weekly on stakeholder management since 2009. Click here to subscribe; click here for media kit.
- RRN Weekly on total rewards since 1996. Click here to subscribe; click here for media kit.
- EEA YouTube channel on enterprise engagement, human capital, and total rewards since 2020
Management Academy to enhance future equity value for your organization.3. Books on implementation: Enterprise Engagement for CEOs and Enterprise Engagement: The Roadmap.
4. Advisory services and research: Strategic guidance, learning and certification on stakeholder management, measurement, metrics, and corporate sustainability reporting.
5. Permission-based targeted business development to identify and build relationships with the people most likely to buy.
Contact: Bruce Bolger at TheICEE.org; 914-591-7600, ext. 230.












