
Share
As enterprises grow wary of ungoverned AI agents, ZoomInfo just picked up a clean-sheet audit on how it manages its AI lifecycle. Here's what that certification actually checks, and why it matters for procurement teams.
ZoomInfo (NASDAQ: GTM) has achieved ISO/IEC 42001:2023 certification for its Artificial Intelligence Management System, or AIMS. If you haven't run into this standard yet, you will. It's the first international standard specifically built around how organizations govern AI across its full lifecycle, not just how they secure data or handle privacy, which is where most existing compliance frameworks still live.
The certification came from Schellman, an accredited certification body, after a multi-stage independent assessment. That's worth sitting with for a second: this isn't a self-attestation or a marketing badge ZoomInfo slapped on its website. It's a third party going through the company's governance structure, risk and impact management practices, operational controls, and improvement processes, then signing off that they actually hold up.
For context, ISO/IEC 42001 is still relatively new, published in late 2023. Think of it as the AI-specific sibling to ISO/IEC 27001, the long-established standard for information security management. Where 27001 asks "how do you protect data and systems," 42001 asks "how do you manage the risks, accountability, and lifecycle of AI systems you build or deploy." As more companies bolt AI agents onto core products, auditors and procurement teams are increasingly going to expect answers to both questions.
Schellman's review happened in two stages: a Stage 1 readiness review and a Stage 2 certification audit. The assessors evaluated ZoomInfo's AIMS against the core management-system requirements in Clauses 4 through 10 of the standard, plus relevant Annex A controls (the standard's library of specific AI governance controls, covering things like risk assessment, data provenance, and system impact evaluation).
The result: zero findings. Zero nonconformities. Zero opportunities for improvement. That's a notably clean outcome for a first-time certification audit. Auditors almost always flag something, even minor process gaps, on an initial pass. A zero-across-the-board result signals the governance work was already mature before Schellman showed up to check it.
"ISO/IEC 42001 certification reflects ZoomInfo's commitment to governing AI with rigor, accountability, and ongoing oversight," said James Grant, Vice President Security and Field Chief Information Security Officer at ZoomInfo. "Schellman's independent assessment found that our AI management system met the standard and was operating effectively, with no findings, nonconformities, or opportunities for improvement. That is a strong indication that the management system we've built for AI is mature, durable, and working as intended."
Certification isn't a one-time stamp, either. ZoomInfo will need to maintain it through periodic surveillance audits, meaning Schellman (or another accredited body) will keep checking back to confirm the AIMS stays compliant as ZoomInfo's AI capabilities evolve. That continual-improvement loop is baked into the standard itself.

For ZoomInfo's customers, specifically the sales, marketing, and revenue teams using its B2B data platform and its growing stack of agentic features, this certification is less about trust-fall marketing and more about practical procurement friction.
Enterprise security and vendor-risk reviews are getting more complicated as AI gets embedded deeper into SaaS tools. Buyers increasingly want proof that a vendor's AI systems are governed, not just that the product works. A recognized third-party certification like 42001 gives procurement and security teams a standardized artifact to point to, instead of each customer independently interrogating ZoomInfo's internal AI practices from scratch.
"This certification gives customers confidence that ZoomInfo is governing AI effectively, and it's another demonstration of our investment in compliance, privacy, and security," said Ben Calvert, Chief Information Security Officer at ZoomInfo. "As agentic capabilities evolve, it gives GTM leaders the assurance they need to adopt ZoomInfo with confidence and cut through procurement red tape."
That "agentic capabilities" line is the real driver here. ZoomInfo has been pushing GTM.AI, its headless go-to-market layer that exposes APIs and Model Context Protocol (MCP) endpoints for AI agents to plug into, with integrations spanning Salesforce Agentforce, HubSpot Breeze, Microsoft Copilot Studio, Claude, ChatGPT, and others. As more autonomous agents start pulling and acting on ZoomInfo's data, the governance question shifts from "is this data accurate" to "what is the AI doing with it, and who's accountable if something goes wrong." ISO/IEC 42001 is built to answer exactly that kind of question.
This certification also adds to a growing stack. ZoomInfo already holds ISO/IEC 27001 (information security management), ISO/IEC 27701 (privacy information management), ISO/IEC 27017 (cloud security controls), a SOC 2 Type II examination, and a separate TRUSTe Responsible AI Certification from TrustArc. Layering 42001 on top rounds out the picture: security, privacy, cloud, and now AI governance specifically, all independently verified.
Tags
Original Sources
ZoomInfo Expands ISO Assurance Program with ISO/IEC 42001 Certification, Validating its Rigorous AI Governance
↗ https://venturebeat.com/business/zoominfo-expands-iso-assurance-program-with-isoiec-42001-certification-validating-its-rigorous-ai-governance
About the author
Kai built ML infrastructure at a Bay Area startup before developing an obsession with transformer architectures and inference optimisation that eventually pulled him out of product work entirely. A stint at a compute research lab sharpened his instinct for what actually matters in a model release versus what is marketing. He writes from the inside — from the perspective of someone who has debugged the systems he is describing at three in the morning. He is allergic to hype and instinctively drawn to the unglamorous plumbing questions that everyone else skips over.
More from The Engineer →This Week's Edition
7 October 2026
34 articles
Related Articles

Cisco's Edge Intelligence Tackles the Unsexy Problem of Getting IoT Data Out of the Field
Tools & Engineering · 5 min

Anthropic Opens Up Cyber Tools for Claude, With Hospitals in Mind
Tools & Engineering · 5 min

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min
Related Articles

Cisco's Edge Intelligence Tackles the Unsexy Problem of Getting IoT Data Out of the Field
Tools & Engineering · 5 min

Anthropic Opens Up Cyber Tools for Claude, With Hospitals in Mind
Tools & Engineering · 5 min

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.