Table of contents
We're proud to announce that Moveworks has achieved ISO/IEC 42001 certification — the world's first international standard for managing the risks and responsibilities of AI.
What is ISO 42001?
ISO/IEC 42001 is the AI counterpart to standards like ISO 27001 (information security) and ISO 27701 (privacy). It defines the requirements for an AI Management System — the policies, controls, roles, and oversight mechanisms an organization needs to develop and operate AI responsibly.
To get certified, an independent accredited auditor evaluates whether those mechanisms exist, work, and are continuously improved. It's the first globally recognized way for customers, regulators, and partners to externally verify how a company governs its AI.
What this means for Moveworks customers
Certification reflects work we've been doing for years, not a new program built for the audit. The AI risk management, model evaluation, and human oversight controls the auditor reviewed were already running in production — certification confirms they meet a rigorous international benchmark.
For customers — particularly those in government, financial services, and healthcare — that means independent, third-party assurance that Moveworks' AI is governed to a standard their own regulators are increasingly going to expect.
ISO 42001 was only published in December 2023; certifying now puts Moveworks among the early adopters, ahead of where most enterprises will be by the time AI regulation catches up.
"ISO 42001 matters because it's the first time AI governance has a globally recognized, independently audited bar — not a self-attestation, not a marketing claim.
Achieving it confirms what we already knew internally: that the controls we've built around how we develop, deploy, and operate AI hold up under external scrutiny." —
Damián Hasse, Chief Information Security Officer, Moveworks
Stronger together with ServiceNow
ServiceNow already holds ISO 42001. With Moveworks now certified, AI governance is aligned to the same international standard across the combined organization — one less integration question for the federal, regulated, and global enterprise customers we serve together.