Payments firms need a way to identify where artificial intelligence is being used and who’s responsible for it, as well as to monitor how those systems are managed over time.
ISO/IEC 42001 puts a management framework around those systems, including AI a company buys rather than builds.
Published in December 2023, the standard establishes requirements for an AI management system, or AIMS. It applies to organizations that develop, provide or use AI products and services and covers the establishment, implementation, maintenance and continual improvement of the management system.
The intent is to govern how an organization manages AI throughout its lifecycle. At a high level, the standard addresses responsibility, risk assessment, monitoring and other management processes rather than setting technical performance requirements for individual fraud, authentication or underwriting models.
For payments companies, implementing ISO 42001 can start with finding the AI already operating inside the business.
“The biggest change is that it makes firms take a much closer look at where AI is actually being used,” Christian Jacob, a financial crime and AI governance professional with payments experience, told PYMNTS.
That includes machine-learning components inside fraud detection, transaction monitoring, onboarding, authentication and other decisioning workflows, Jacob said. The review can uncover systems that previously had been treated simply as operational technology.
Jacob, who works at Deel, told PYMNTS his comments were being provided in a personal capacity.
Identifying those systems is one issue. Responsibility after deployment is another.
David Kemmerer, co-founder and CEO of CoinLedger, told PYMNTS separately that payments companies may already have established processes for security, fraud, privacy, model risk and compliance. The problem can emerge after an AI system has entered production.
“The tough bit is who owns an AI system after deployment or the governance of changes in the model,” Kemmerer said. “ISO 42001 provides coverage for creation, implementation, maintenance and improvements.”
The requirement for continuing oversight is significant because AI systems can change in effectiveness as data, behavior and operating conditions change. Management of the system therefore continues after its initial approval.
When AI Touches the Transaction
Rustam Bagautdinov, director of processing at Payzon, pointed to payment routing as an example of where the issue reaches transaction processing.
AI can be used to select an acquiring route using variables such as expected approval rates and cost. A change in the model’s behavior can therefore alter where transactions are sent.
“If an AI suddenly routes a batch of cross-border transactions through a path that triggers massive false declines, ISO 42001 ensures there is a traceable, documented logic to understand why the model made that choice, rather than just blaming the algorithm,” Bagautdinov said.
The example illustrates the operational purpose of governance without turning certification into a performance guarantee. ISO 42001 does not determine whether an individual routing decision is correct. It requires management processes around AI systems within the organization’s defined scope.
The Standard Reaches Outside the Company
Payments companies also depend on technology they do not own.
Fraud detection, screening, onboarding and authentication can be supplied by third parties. A processor can itself depend on other technology suppliers while providing services to banks and merchants.
For ISO 42001, the boundaries of a certification are important.
“The scope statement is the document worth reading, not the certificate,” Jacob said.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
A vendor can be certified while a customer’s particular configuration, integration or tuning falls outside the audited scope, Jacob said. Certification should strengthen third-party due diligence rather than replace it.
For a bank or processor buying an AI-enabled service, the inquiry can extend beyond whether the supplier possesses a certificate to which systems were examined, what the supplier controls and what responsibility remains with the customer.
Payments and Banks Begin Certifying
There are direct payments examples.
Financial Software and Systems (FSS) said in a January blog post that it achieved ISO/IEC 42001 certification. AI is embedded in fraud detection, transaction monitoring, reconciliation, dispute management and operational automation across its platforms.
FSS said the certification involved structured oversight across the AI lifecycle, including monitoring systems after deployment.
Banking provides another case. BSI said in a February press release that it certified Axis Bank to ISO/IEC 42001 after an audit of the bank’s AI governance, risk management and project execution practices.
A certified management system can still contain an AI model that performs badly.
“Certification applies to an AI management system, not to the performance of an individual model,” Jacob said.
A certified payments firm can still have a fraud model that misses a new attack pattern or an authentication system that produces uneven outcomes, Jacob said. Certification establishes that the organization’s AI management system met the requirements of the standard within its audited scope.
The limitations carry weight if ISO 42001 becomes part of vendor selection. A certificate can provide evidence about governance without answering whether the product being purchased is effective.
“Certification should strengthen third-party due diligence, not replace it,” Jacob said.
Jacob said he expects the standard to become more important as a governance and procurement benchmark, particularly for firms selling AI-enabled services to regulated financial institutions. Firms can ask suppliers to document which AI systems fall within their management framework, what their certification covers and how outside AI dependencies are handled. If those questions become routine in technology reviews, ISO 42001 could acquire its standing in payments through procurement rather than regulation.
For all PYMNTS AI coverage, subscribe to the daily AI newsletter.