---
title: "ISO 27001, ISO 9001 and ISO 42001 Assurance | Data-Driven AI"
canonical: "https://data-driven.com/iso-27001-and-iso-9001-certifications/"
description: "Review Data-Driven AI's ISO 27001 and ISO 9001 certifications, ISO 42001 verification, and the evidence to request for assurance."
---

Certified and verified assurance

# Security, quality and AI management, independently assured

Data-Driven AI is certified to ISO/IEC 27001 and ISO 9001, and independently verified against ISO/IEC 42001. Each engagement still needs its own scope, controls and evidence.

![Icon of a padlock on a shield surrounded by circuit lines](/_astro/DD-Website-Page-Banner-image-25.D8UJjabL_Z16EpwO.webp)

Published assurance

## Read each mark by its own status and scope

Data-Driven AI is certified to ISO/IEC 27001:2022 for information-security management and ISO 9001:2015 for quality management. We have also been independently verified against ISO/IEC 42001:2023 for AI management.

The NSW Government supplier profile records our ISO 27001 and ISO 9001 certifications. Ask us for the current scope, validity dates, certification body, or verification statement you need to assess.

[Request evidence](/contact-us/)[NSW supplier profile](https://buy.nsw.gov.au/supplier/profile/2473)

![Equal Assurance ISO 27001 certified mark](/_astro/iso-27001.B15AU1nf_Z2w67DU.webp)

Certified

### ISO/IEC 27001:2022

Information-security management

![Equal Assurance ISO 9001 certified mark](/_astro/iso-9001.3Q5-Y0XL_Z1wVdcB.webp)

Certified

### ISO 9001:2015

Quality management

![Equal Assurance ISO 42001 verified mark](/_astro/iso-42001.Bk7SGgtJ_Z26hxfK.webp)

Verified

### ISO/IEC 42001:2023

AI management

Certification and verification are different forms of assurance. Request the current documents before relying on either for a formal review.

What each standard governs

## Each credential applies to a defined management system

They show how Data-Driven AI manages organisational processes. They do not make every solution, workload, or customer environment compliant.

27001

### Information security

How we identify, treat, monitor, and improve information-security risks.

9001

### Quality

How we control delivery processes, meet requirements, and improve our work over time.

42001

### AI management

How we establish, operate, and improve an AI management system for the responsible development or use of AI.

Assurance review

## Read the scope before you rely on the mark

A useful review connects the assurance document to the services, people, and responsibilities involved in your work.

01

### Identify the assurance type

Confirm whether you are reviewing a certificate or a verification statement, then note the standard and edition.

02

### Check the entity, scope, and dates

Review the legal entity, assurance provider, locations, covered activities, issue date, and validity period.

03

### Map it to the engagement

Record which controls belong to Data-Driven AI, your organisation, Microsoft, and any other provider.

Review the official ISO introductions to [ISO/IEC 27001](https://www.iso.org/standard/27001), [ISO 9001](https://www.iso.org/standard/62085.html), and [ISO/IEC 42001](https://www.iso.org/standard/42001).

Engagement boundary

## Your workload still needs its own assurance case

Before delivery, connect the relevant management-system controls to the actual data, services, environments, and people in scope.

Confirm for your engagement

-   Data classification, location, and permitted use
-   Identity, access, and environment ownership
-   Logging, incident, change, and evidence responsibilities

## Need the evidence for your review?

Tell us which certificate, verification statement, scope, or validity detail your procurement, security, or risk team needs.

[Request assurance material](/contact-us/)

[Review our project methodology](/data-driven-ai-project-methodology/)

## Want to learn more?

Explore the rest of the site or get in touch with the team.

[Back to home](/)
