The newly published ISO/IEC 42001 standard is reshaping how payments firms manage external AI technology, emphasizing oversight, transparency, and responsible use amid increasing reliance on third-party vendors.
ISO/IEC 42001 is emerging as a practical benchmark for payments firms trying to control how artificial intelligence is used, especially when the technology comes from outside vendors rather than in-house teams. The standard, published in December 2023, sets out requirements for an AI management system and is aimed at organisations that develop, provide or use AI products and services, according to the International Organisation for Standardisation.
For payments companies, the first step is often less about model performance than about visibility. Christian Jacob, a financial crime and AI governance professional with payments experience, told PYMNTS that the biggest shift is forcing firms to identify where AI is actually embedded in their operations, including fraud detection, transaction monitoring, onboarding and authentication. That review can expose systems that had previously been treated as ordinary operational software rather than governed AI.
The standard’s focus is on management, not model accuracy. According to ISO, it is designed to support responsible AI use through oversight of risks, transparency, continual improvement and lifecycle management. Jacob said the scope of certification matters as much as the certificate itself, because a supplier may be certified while a customer’s own configuration, integration or tuning sits outside the audited boundary. In practice, that makes ISO 42001 more useful as a due-diligence tool than as a substitute for it.
That point matters because payments firms increasingly rely on third-party AI. David Kemmerer, co-founder and chief executive of CoinLedger, told PYMNTS that the hard question is who owns an AI system after it goes live and who is responsible for changes over time. He said the standard helps address creation, implementation, maintenance and ongoing improvements. Rustam Bagautdinov, director of processing at Payzon, pointed to routing as one example, saying that if an AI system suddenly sends cross-border payments down a path that triggers large numbers of false declines, the framework should leave a traceable record of why the decision was made.
There are already signs that the standard is moving from theory into procurement. Financial Software and Systems said in a January blog post that it had achieved ISO/IEC 42001 certification, citing AI use across fraud detection, transaction monitoring, reconciliation, dispute handling and automation. BSI said in February that it had certified Axis Bank after reviewing the lender’s AI governance, risk management and project execution practices. Even so, Jacob said certification applies to the management system rather than to the performance of any single model, meaning a certified firm can still have a weak fraud or authentication tool. That is why, he said, ISO 42001 is likely to gain importance as a purchasing benchmark for regulated financial institutions seeking clearer evidence of AI governance.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





