Back to docs
Research Operations

AI Governance for Customer Research: ISO 42001, the NIST AI RMF, and What Procurement Actually Asks

Security review is asking whether your AI research platform is ISO 42001 certified and NIST AI RMF aligned. Here is what each framework covers, what a certificate does and does not buy you under the EU AI Act, and how to answer.

The short answer

ISO/IEC 42001 certification does not make you compliant with the EU AI Act, and the NIST AI RMF has never been a law. Both are worth having. Neither is what most procurement questionnaires assume it is.

If you are buying or defending an AI-moderated research tool in 2026, three different things get conflated in the same email thread:

What it isLegal forceWhat it gives you
EU AI ActRegulationBinding law in the EUObligations you must meet, with penalties
ISO/IEC 42001:2023Certifiable management system standardVoluntaryA third-party audited certificate that you govern AI systematically
NIST AI RMF 1.0Voluntary frameworkNoneA shared vocabulary and structure for AI risk work

Getting this hierarchy right saves a research team weeks. It also stops you paying for a certificate to solve a problem the certificate does not solve.

ISO/IEC 42001: the certifiable one

Published in December 2023, ISO/IEC 42001 is the first international standard for an AI management system (AIMS). It is structured like ISO 27001 — the same Annex SL management-system shape — but its subject is AI: how you inventory AI systems, assess their impact on the people they touch, assign accountability, and monitor behaviour across the lifecycle.

Certification works the way ISO certification always works. An accredited certification body runs a Stage 1 (documentation readiness) and Stage 2 (implementation) audit. The certificate is valid for three years, with annual surveillance audits in between. Published cost and timeline estimates vary widely by scope and organisation size; consultancies commonly quote figures in the tens of thousands of dollars and four to nine months of preparation. Treat those as directional, not as a quote.

Two supporting standards arrived in 2025 and are worth knowing by name, because sophisticated buyers cite them:

  • ISO/IEC 42005:2025 — guidance for conducting AI system impact assessments. It is guidance, not a certifiable requirement, and it complements 42001 with lifecycle-continuous assessment practice.
  • ISO/IEC 42006:2025 — requirements for the bodies that audit and certify AIMS. This one matters indirectly: it is what makes one vendor's 42001 certificate comparable to another's.

The presumption-of-conformity trap

Here is the point that most vendor questionnaires get wrong, and the single most useful thing to know in this whole area.

Under Article 40 of the EU AI Act, applying a harmonised standard — one cited in the Official Journal of the EU — gives you a presumption of conformity with the corresponding AI Act requirements. That is a real, valuable legal shortcut.

ISO/IEC 42001 is not a harmonised standard. A 42001 certificate therefore carries no presumption of conformity with the AI Act. The European deliverable being developed to serve that role is prEN 18286; until it is cited in the Official Journal, nobody has the shortcut. Neither 42001 nor 42005 was designed to operationalise the full set of AI Act obligations in the first place.

So when a security reviewer writes "we require ISO 42001 certification to satisfy the EU AI Act," the honest answer is that the two are complementary but not substitutes: the certificate is credible evidence of governance maturity, and the AI Act obligations still have to be met on their own terms.

For customer research specifically, those obligations are usually lighter than people fear. AI-moderated interviews sit in the AI Act's limited-risk transparency tier, where the core duty is to tell participants they are talking to an AI before the conversation starts. Our EU AI Act guide walks through the tiering and the narrow cases that escalate it.

NIST AI RMF: useful framework, frequently mis-cited

NIST released the AI Risk Management Framework 1.0 in January 2023, organised around four functions — GOVERN, MAP, MEASURE, MANAGE — plus a companion Generative AI Profile (NIST AI 600-1) published in July 2024.

It is genuinely good structure, and it is free. But be careful with claims about its legal status. Much of the guidance still circulating online states that federal agencies are directed to align with the AI RMF under Executive Order 14110. EO 14110 was revoked on 20 January 2025, and replaced days later by a different executive order with a different posture. The framework itself is unaffected — NIST still publishes it, and enterprises still use it — but it remains what it always was: voluntary. If a vendor tells you AI RMF alignment is legally mandatory, they are working from stale material.

What is true is that AI RMF vocabulary has become the lingua franca of enterprise AI questionnaires. Answering in its terms (here is our GOVERN evidence, here is our MEASURE evidence) makes a review go faster whether or not anyone is certified.

The overlap you can build once

Across the AI Act, ISO 42001, and the NIST AI RMF, the same five control areas keep appearing:

  1. Risk and impact documentation — what the system does, who it affects, what could go wrong
  2. Data governance — provenance, minimisation, retention, quality
  3. Human oversight — who can intervene, and how
  4. Incident monitoring — detection, logging, escalation
  5. Transparency documentation — disclosure to affected people, and system documentation for reviewers

Build the evidence once, tag each artefact against all three frameworks, and most questionnaires answer themselves.

What to actually ask an AI research vendor

Skip the framework name-dropping and ask questions whose answers are checkable:

  • Which model providers process interview data, and are they named as sub-processors? AI interview tools route text and audio to model and transcription providers. Unnamed sub-processors are the real risk, not the absence of a certificate.
  • Is participant data used to train models? Get this in the contract, not in a sales email.
  • How is AI disclosure handled in the participant flow? Under the AI Act this is the operative obligation for research. Ask to see the actual screen.
  • What human oversight exists over the AI interviewer? Can a researcher review, correct, and re-run analysis?
  • What is logged, and for how long? This is where AI governance and your retention schedule meet — see research data retention and deletion.
  • Do you hold ISO 42001, or have a dated roadmap? A credible roadmap beats a vague yes. Ask which certification body and what scope — scope is where certificates get thin.
  • What is your AI incident process? Ask for one worked example.

Ask the same seven of every vendor on the shortlist, including Koji. Answers that vary in specificity tell you more than answers that vary in confidence.

How Koji's architecture changes the governance conversation

Two structural properties of Koji make several of these questions easier to answer than they are for the tools research teams are migrating from.

Interviews are asynchronous, link-based, and transcript-first. There is no third-party meeting recorder in the chain, which removes a sub-processor and the consent trail that comes with it. Participants receive the AI disclosure in the flow before the conversation begins, so the AI Act transparency duty is satisfied by the product's default path rather than by researcher discipline.

Analysis runs on transcripts, not on biometric signals. This distinction does real work under the AI Act: emotion recognition obligations attach to biometric inference, so analysing what someone said sits in a materially different place from inferring affect from vocal tone. A transcript-first architecture keeps you out of the harder tier by design rather than by configuration.

On the research-quality side, Koji's six structured question types — open_ended, scale, single_choice, multiple_choice, ranking, and yes_no — matter more for governance than they first appear. Structured questions produce predictable, typed data with a stable question ID from interview plan through to report. When a reviewer asks what data you collect and how it is processed, "these six typed fields plus transcript" is a far easier answer than "free-text, variably" — and it is the same property that makes deletion and access requests tractable.

Common mistakes

  • Buying a certificate to answer a regulation. ISO 42001 is evidence of governance maturity, not a conformity shortcut under the AI Act.
  • Citing EO 14110. It was revoked in January 2025. Cite the framework, not the executive order.
  • Accepting "we're SOC 2" as an AI governance answer. SOC 2 addresses information security controls. It says nothing about model behaviour, training use, or human oversight. Both matter; they are not interchangeable.
  • Ignoring certificate scope. A 42001 certificate covering a parent company's internal tooling tells you little about the product you are buying.
  • Treating AI governance as a one-time procurement gate. All three frameworks assume ongoing monitoring, and the EDPB expects controllers to re-verify processing chains over time.

Frequently asked questions

Does ISO 42001 certification make me EU AI Act compliant? No. ISO/IEC 42001 is not a harmonised standard under the Act, so a certificate carries no presumption of conformity. The European deliverable intended for that role is prEN 18286. The certificate is still strong evidence of governance maturity in a vendor review.

Is the NIST AI RMF mandatory? No. It is and always has been a voluntary framework. Guidance claiming a federal mandate typically traces to Executive Order 14110, which was revoked on 20 January 2025.

Do we need ISO 42001 to run AI-moderated customer research? No. Customer research generally sits in the AI Act's limited-risk transparency tier, where the operative duty is disclosing to participants that they are interacting with an AI. Certification becomes relevant when your own enterprise buyers demand it of you.

What is the difference between ISO 42001 and ISO 42005? 42001 is the certifiable management system standard. 42005 is guidance for conducting AI system impact assessments and is not certifiable; it complements 42001.

What is the difference between SOC 2 and ISO 42001 for an AI vendor? SOC 2 attests to information security controls — access, encryption, availability. ISO 42001 attests to how the organisation governs AI systems specifically. Enterprise buyers increasingly want both, for different reviewers.

How should a small research team answer an AI governance questionnaire? Answer in NIST AI RMF terms even without certification: document what the AI does, who it affects, what human oversight exists, what is logged, and what you disclose to participants. That covers most of what the questionnaire is reaching for.

Related Resources

Related Articles

AI Interview Data Privacy & Security: A Buyer's Evaluation Guide

How to evaluate the privacy and security of an AI customer research platform — the questions to ask about data handling, PII, retention, sub-processors, and compliance — plus how Koji approaches each one.

DPIA for User Research: When You Need One and How to Write It (2026)

A practical guide to Data Protection Impact Assessments for customer and user research: the Article 35 triggers, the WP29 nine criteria, what belongs in each section, and a worked example for AI-moderated interviews.

Enterprise Security for AI Customer Research Platforms: SOC 2, SSO, and Vendor Review

A procurement-ready guide to evaluating the security of an AI customer research platform — SOC 2, encryption, SSO/SAML, data residency, sub-processors, and the questions your security team should ask.

The EU AI Act and User Research: What AI-Moderated Interviews Actually Require (2026)

AI-moderated customer interviews sit in the EU AI Act's limited-risk transparency tier, not the high-risk tier. Here is exactly what Article 50 requires from 2 August 2026, the two things that escalate a study to high-risk, and a compliance checklist you can run this week.

Research Data Retention and Deletion: How Long Should You Keep Interview Data?

There is no universal legal number - which is exactly why having no retention schedule is itself the compliance failure. A tiered, per-artifact schedule for recordings, transcripts, quotes, and reports, plus how to handle deletion requests without losing your insights.

Structured Questions in AI Interviews

Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.

User Research for AI Products: A Practical Guide for 2026

AI products break the assumptions traditional UX research is built on — outputs are non-deterministic, trust is the central UX problem, and prompts replace navigation. This guide covers the methods, question types, and study designs that actually work for teams shipping AI features.