On June 30, 2026, Greenlight Guru announced it had achieved ISO/IEC 42001 certification for its AI Management System. The certification, conducted by Prescient Security, covers how AI is designed, trained, tested, deployed, monitored, and updated across all three of its products — eQMS and clinical EDC.
The announcement landed two days before the EU AI Act enforcement date of August 2, 2026. That timing was not accidental.
Greenlight Guru now holds ISO 42001 (AI governance), ISO 9001 (quality), ISO 27001 (information security), and SOC 2 Type II (operational controls). That stack — AI governance, quality, security, and operational effectiveness — is the trust framework that regulated industries are converging on.
MasterControl is the only other life sciences QMS vendor publicly claiming ISO 42001 certification. Everyone else is either building toward it or hoping nobody asks.
What ISO 42001 actually is
ISO/IEC 42001:2023 is the first international standard for AI Management Systems. Published December 2023 by ISO and IEC jointly. It’s not a technical standard for building AI — it’s a governance standard. Similar in structure to ISO 27001 (information security) and ISO 9001 (quality management). Follows the Annex SL high-level structure, which means it’s compatible with those standards and can be audited alongside them.
The standard applies to any organization, regardless of size, that provides or uses products or services that utilize AI systems. If AI plays any role in how your organization operates, delivers products, or makes decisions, this standard applies to you.
It covers: AI governance and leadership. Risk and impact assessments — not just technical risks, but social and ethical ones. Data management — clarity on what data feeds your AI and whether it’s clean and fair. Transparency and explainability. Human oversight — humans should still be in the loop where it matters.
The structure: 68 checkboxes
The standard has two layers of requirements.
Layer 1: Management System Requirements (Clauses 4-10) — 30 requirements covering context, leadership, planning, support, operation, performance evaluation, and improvement. These are the same structural elements as ISO 27001 and ISO 9001. If you already have either of those, roughly half of this work is done.
Layer 2: Annex A Controls — 38 specific controls organized into 9 categories:
- A.2 Policies (3 controls): Document your AI policy, align it with other org policies, review it regularly
- A.3 Organization (2 controls): Define AI roles and responsibilities, establish concern reporting
- A.4 Resources (5 controls): Document your data, tools, hardware, and people
- A.5 Impact Assessment (4 controls): Assess impacts on individuals, groups, and society
- A.6 Life Cycle (9 controls): The biggest section — requirements through design, development, V&V, deployment, operation, monitoring, and event logging
- A.7 Data (5 controls): Data management, acquisition, quality, provenance, and preparation
- A.8 Transparency (4 controls): User documentation, external reporting, incident communication
- A.9 Use (3 controls): Responsible use processes, objectives, and intended use
- A.10 Third Parties (3 controls): Supplier management, customer relationships, responsibility allocation
Total: 68 verifiable requirements.
Not all 38 Annex A controls apply to every organization. You produce a Statement of Applicability that lists all 38, marks each as “applicable” or “not applicable,” and justifies exclusions. If you only use third-party AI and don’t develop your own, you can exclude some of the life cycle development controls. Typical exclusions: 3-8 controls. Typical applicable: 30-35.
Effective checkbox count for most organizations: ~62-66.
The three layers of proof
The auditor doesn’t just check “yes/no” on each checkbox. Each item requires three levels of proof:
1. Does it exist? Policy, procedure, or process is documented.
2. Does it work? Actually implemented in practice — logs, records, screenshots, timestamps, personnel interviews.
3. Does it improve? Monitored, reviewed, corrective actions taken. Evidence of continual improvement.
68 checkboxes × 3 layers = approximately 204 verification points. The auditor will want 75-150 pieces of evidence for the internal audit and 50-75 audit artifacts for the Stage 2 operational review.
The certification process
ISO doesn’t certify organizations directly. Independent certification bodies (registrars) conduct audits. These bodies must be accredited by national accreditation bodies — ANAB in the US, UKAS in the UK, DAkkS in Germany, RvA in the Netherlands.
The process has five phases:
Phase 1: Gap Analysis (2 weeks to 3 months). Define your AIMS scope. Identify your role with respect to AI systems — are you a provider, producer, customer, or multiple? Inventory all AI systems. Compare current practices against the 68 requirements. Secure top management commitment.
Phase 2: AIMS Design and Documentation (1 to 3 months). Draft AI policy. Define roles and responsibilities. Establish risk criteria and assessment processes. Design impact assessment processes. Create your Statement of Applicability. Document life cycle processes. Establish data governance.
Phase 3: Implementation and Training (1 to 4 months). Train staff. Implement controls. Begin operating under the AIMS. Log incidents. Monitor performance. Collect 75-100 pieces of evidence.
Phase 4: Internal Audit (~1 month). Independent review of all controls. Verify documentation completeness and operational effectiveness. Address non-conformities. Management review.
Phase 5: External Certification Audit (1 to 2 months). Stage 1 is a documentation review — 1-2 days. Stage 2 is an operational review — 3-9+ days. Stages are typically spaced 4-12 weeks apart.
Total timeline: 4-12 months. Smaller organizations can complete it in 3-4 months. Larger organizations take closer to a year.
What it costs
| Category | Range |
|---|---|
| Gap analysis / readiness | $3,500 – $5,000 |
| Implementation (consulting, tools, training) | $6,000 – $25,000 |
| Stage 1 + Stage 2 audit fees | $15,000 – $50,000 |
| Annual surveillance audit | 20-30% of initial fee |
| Total for SMB | $4,000 – $20,000+ |
| Total for enterprise | $30,000 – $100,000+ |
Factors that increase cost: organization size, scope breadth, geographic distribution, number of AI systems in scope. Factors that decrease cost: existing ISO 27001 or ISO 9001 certification, narrow scope (certify one product line instead of everything), bundling audits with the same firm.
The 15 accredited certification bodies
As of June 2026, 15 certification bodies are accredited to issue ISO 42001 certificates:
Market leaders (most certifications issued): Schellman (first ANAB-accredited, clients include AWS, Anthropic, IBM, Snowflake, GitLab), BSI Group (first UKAS-accredited, clients include Darktrace, SAP, BCG), A-LIGN (issued the first-ever ISO 42001 certificate to Synthesia), Mastermind Assurance (Microsoft, Grammarly).
Global players: SGS, DNV, Bureau Veritas, TÜV SÜD, TÜV Rheinland, LRQA, EY CertifyPoint, MSECB, BDO.
Specialists: Prescient Security (certified Greenlight Guru), Sensiba.
Greenlight Guru’s auditor — Prescient Security — is a smaller firm. That’s worth noting. The big names (Schellman, BSI, A-LIGN) have issued the most ISO 42001 certifications globally. Prescient Security is credible but less established in this specific standard.
Can you get certified while using shared LLMs?
This is the question most life sciences companies are actually asking. The answer: yes, but the audit looks different.
The standard doesn’t require you to own or build the AI model. It requires you to govern your relationship with it. Clause 4.1 asks you to define your role — if you’re using GPT-4 via API, you’re an AI customer and user, not an AI producer. The controls shift accordingly.
If you use shared APIs (OpenAI, Anthropic, Google via API): You don’t control model weights, training data, or infrastructure. The audit focuses on supplier controls (A.10.3), data handling (what goes in/out), output monitoring, and incident response. The auditor will ask: “How did you evaluate this supplier’s AI?” “What data leaves your environment?” “Can you disable the AI if it fails?”
If you self-host (Llama, Mistral on your own infra): Full control. All controls apply directly. Simpler audit. This is the path Greenlight Guru and MasterControl took — both explicitly state they do not use third-party LLMs.
The smartest approach: Self-host for GxP-critical applications (validation, quality decisions). Use shared APIs for non-critical tasks (drafting, summarization). Document the boundary. Certify the whole governance framework.
Why this matters more than you think
Three forces are converging:
1. The EU AI Act is live. Enforcement began August 2, 2026. ISO 42001 doesn’t make you EU AI Act compliant by itself, but it maps closely to what the Act requires — governance, risk assessment, documentation, monitoring, human oversight. Getting certified now means building governance infrastructure on your own timeline, not a regulator’s.
2. Procurement teams are asking. Enterprise buyers are adding AI governance requirements to vendor assessments. If you sell to pharma, medtech, or biotech, your customers are asking how you govern AI. ISO 42001 is the documented answer.
3. Two vendors just raised the bar. Greenlight Guru and MasterControl now have independently verified AI governance. Every other QMS, CSV, MES, and LIMS vendor that ships AI features without this certification is exposed. Not legally — yet. Commercially. When a procurement team compares two vendors and one has ISO 42001 and the other has a marketing page with an AI badge, the decision gets easier.
The vendor trust stack is consolidating
Greenlight Guru’s certification stack — ISO 42001 + ISO 9001 + ISO 27001 + SOC 2 Type II — is becoming the minimum viable trust framework for regulated software vendors. It covers AI governance, quality management, information security, and operational effectiveness.
This is what “trust us, we’re the compliance experts” looks like when it’s actually verified by a third party. As we noted in our research on how QMS vendors handle AI data training guarantees, the gap between marketing and verification is the biggest risk in the market right now. ISO 42001 closes that gap — for the vendors that bother to get it.
The question for every other vendor in the space: if Greenlight Guru and MasterControl can do it, what’s your excuse?
The bottom line
ISO 42001 certification takes 4-12 months, costs $4K-$100K+ depending on size, and requires checking approximately 62-66 boxes with three layers of proof each. It’s not trivial, but it’s not insurmountable — especially if you already have ISO 27001 or ISO 9001.
The standard explicitly allows using shared/third-party LLMs. You don’t need to build your own AI. You need to govern how you use it.
Two life sciences QMS vendors are certified today. The EU AI Act is enforcing tomorrow. The procurement teams are already asking.
The checkbox count is 68. The question is how many of your competitors have checked them before you.
Saram Consulting