Skip to content

Certified and verified assurance

Security, quality and AI management, independently assured

Data-Driven AI is certified to ISO/IEC 27001 and ISO 9001, and independently verified against ISO/IEC 42001. Each engagement still needs its own scope, controls and evidence.

Icon of a padlock on a shield surrounded by circuit lines

Published assurance

Read each mark by its own status and scope

Data-Driven AI is certified to ISO/IEC 27001:2022 for information-security management and ISO 9001:2015 for quality management. We have also been independently verified against ISO/IEC 42001:2023 for AI management.

The NSW Government supplier profile records our ISO 27001 and ISO 9001 certifications. Ask us for the current scope, validity dates, certification body, or verification statement you need to assess.

Equal Assurance ISO 27001 certified mark

Certified

ISO/IEC 27001:2022

Information-security management

Equal Assurance ISO 9001 certified mark

Certified

ISO 9001:2015

Quality management

Equal Assurance ISO 42001 verified mark

Verified

ISO/IEC 42001:2023

AI management

Certification and verification are different forms of assurance. Request the current documents before relying on either for a formal review.

What each standard governs

Each credential applies to a defined management system

They show how Data-Driven AI manages organisational processes. They do not make every solution, workload, or customer environment compliant.

27001

Information security

How we identify, treat, monitor, and improve information-security risks.

9001

Quality

How we control delivery processes, meet requirements, and improve our work over time.

42001

AI management

How we establish, operate, and improve an AI management system for the responsible development or use of AI.

Assurance review

Read the scope before you rely on the mark

A useful review connects the assurance document to the services, people, and responsibilities involved in your work.

01

Identify the assurance type

Confirm whether you are reviewing a certificate or a verification statement, then note the standard and edition.

02

Check the entity, scope, and dates

Review the legal entity, assurance provider, locations, covered activities, issue date, and validity period.

03

Map it to the engagement

Record which controls belong to Data-Driven AI, your organisation, Microsoft, and any other provider.

Review the official ISO introductions to ISO/IEC 27001, ISO 9001, and ISO/IEC 42001.

Engagement boundary

Your workload still needs its own assurance case

Before delivery, connect the relevant management-system controls to the actual data, services, environments, and people in scope.

Need the evidence for your review?

Tell us which certificate, verification statement, scope, or validity detail your procurement, security, or risk team needs.

Want to learn more?

Explore the rest of the site or get in touch with the team.