Six certifications, one goal: making enterprise AI worthy of trust
This week Memori completed the picture: with the arrival of ISO 9001:2015 (Quality) and ISO/IEC 27001:2022 (Information Security), the company now holds all six of the attestations it had set out to obtain. Together with the already-obtained ISO/IEC 27017:2021, ISO/IEC 27018:2020, ISO 42001:2023, and compliance with the NIS2 directive, this closes a long path made of documentation, evidence, and cross-departmental work.
But a list of acronyms, on its own, doesn't say much. The question that matters is another one: why are these certifications important specifically for those choosing an AI agent platform? In this article we go through them one by one, explaining what they attest and how they connect to the way AIsuru is built.
Why an agentic orchestrator concentrates three risks at once
An AI agent is not a chatbot that answers questions. It's a system that reads company data, integrates with third-party systems, and takes actions on people's behalf. This means a platform like AIsuru touches, at the same time, the three most sensitive areas of an organization:
- Data: documents, records, files, confidential know-how.
- The cloud: the environment where agents run, integrate, and communicate.
- The AI that decides and acts: models that generate content, call tools, execute operations.
Each certification covers a piece of this risk, and it does so with verification by an independent third-party body. It's not the company declaring itself secure: it's an accredited auditor attesting to it, with periodic surveillance audits. The difference, for the buyer, is enormous: it's the shift from trusting a promise to relying on a verified system.
Let's look at them in detail, starting from the foundations and moving up to the newest layer, the AI one.
ISO/IEC 27001:2022 — Information Security
This is the international reference standard for an Information Security Management System (ISMS). It doesn't certify a single product, but the way the organization governs security: risk analysis, definition of controls (the standard's Annex A), statement of applicability, incident management, continuous improvement. The company defines the scope, demonstrates in audits that it manages it continuously, and obtains a certificate issued by an accredited body.
Why it matters for an agentic orchestrator. It's the foundation everything else rests on. When an agent accesses a CRM, an ERP, or a document archive, the customer's question is: who guarantees that data is handled with secure, verifiable processes? ISO 27001 answers at the system level — not with a single technical measure, but with a structured method for governing information risk. At AIsuru this translates into concrete architectural choices: encrypted credentials, role-based access (RBAC), traceability of operations, incident management.
ISO/IEC 27017:2021 — Information security for cloud services
27017 extends 27001 with cloud-specific controls. It addresses the issues that arise when infrastructure is no longer entirely under the company's own roof: the division of responsibilities between provider and customer, secure configuration of services, segregation of environments, management of administrative access in virtualized environments.
Why it matters for an agentic orchestrator. Agents live and integrate in cloud environments. An orchestrator that connects multiple systems, calls APIs, and manages sessions must demonstrate mastery of typical cloud risks, not just those of a traditional datacenter. 27017 gives the customer a precise guarantee: responsibilities are clear and cloud controls are in place. This is particularly relevant for those adopting AIsuru as SaaS or private cloud, where correctly managing the shared-responsibility model makes the difference.
ISO/IEC 27018:2020 — Protection of personal data (PII) in the cloud
While 27017 covers cloud security in general, 27018 is dedicated to a specific and highly sensitive aspect: the protection of personal data (PII) processed in the cloud. It defines controls on how such data is collected, used, retained and deleted, on consent, on transparency toward the data subject, and on limits to the provider's use of the data.
Why it matters for an agentic orchestrator. An agent that analyzes a document, manages a customer case, or answers an employee almost always touches personal data. 27018 turns privacy from a declaration into demonstrated practice: it's the operational, cloud-based counterpart of GDPR principles. For a company that must carry out a Data Protection Impact Assessment (DPIA) before putting an agent into production, being able to rely on a 27018-certified provider simplifies and strengthens the entire compliance chain.
ISO 42001:2023 — Artificial Intelligence Management System
Here we reach the layer that truly stands out. ISO/IEC 42001:2023 is the world's first international standard dedicated to the management of artificial intelligence (AI Management System, AIMS). It doesn't certify a model or an algorithm: it certifies that the organization has a structured system to develop, provide, and use AI responsibly, transparently, and under risk control, across the entire lifecycle. It addresses AI's typical challenges — opacity, bias, explainability, oversight — and integrates with other existing management systems (9001, 27001).
The most important point: 42001 is designed to align with the EU AI Act. Adopting it means structurally preparing for the requirements of the European regulation, turning an obligation into an advantage: increasingly, in B2B procurement and in Public Administration, AI governance is a tender requirement, not a nice-to-have.
Why it matters for an agentic orchestrator. This is the certification that separates those who govern AI from those who simply use it. A platform on which agents that act are built must be able to demonstrate that a process exists to assess their risks, maintain human oversight, document decisions, and improve over time. This is exactly the philosophy AIsuru was born with: AI as a tool empowered by humans and kept under human control, not as blind automation. 42001 puts an independent stamp on this approach.
NIS2 — Directive (EU) 2022/2555
NIS2 is not an ISO certification, but a European cybersecurity directive, transposed into Italian law with Legislative Decree 138/2024 and in force since October 16, 2024. It sets stringent obligations for essential and important entities across 18 strategic sectors: risk management, incident notification to the national authority within set timeframes, technical measures such as MFA and encryption, secure communications, training, and personal liability of company leadership. Penalties are severe: up to €10 million or 2% of turnover for essential entities.
There's an element that makes NIS2 particularly relevant for a technology provider like Memori: supply chain security. The directive extends obligations to relationships with suppliers and service providers. In practice, a critical entity or a large enterprise within the NIS2 scope must demand security guarantees from its suppliers while including the AI technologies it adopts.
Why it matters for an agentic orchestrator.
It means AIsuru can be adopted by and for organizations within the NIS2 scope without becoming the weak link in their security chain. For anyone evaluating an AI platform to place at the center of their processes, having a provider aligned with NIS2 is not a detail: it's the condition that makes adoption possible. It's worth clarifying that NIS2 is a regulatory obligation and does not replace, nor is replaced by, ISO certifications: ISO 27001 is a solid foundation, but NIS2 compliance adds specific obligations (notifications, supply chain, top management liability) that must be addressed separately. Having both means covering both the management system and the legal obligation.
ISO 9001:2015 — Quality Management System
We close with what, on the surface, is the most "classic" one, but which actually holds everything else together. ISO 9001 certifies the quality management system: defined and documented processes, customer orientation, measurement and continuous improvement.
Why it matters for an agentic orchestrator. Quality is what ensures that security, AI governance, and data protection are not isolated episodes, but a repeatable method. A customer entrusting their processes to an AI platform wants to know that the company behind that platform works in a structured way, releases improvements in a controlled manner, and collects and manages feedback. 9001 is the framework that makes everything else sustainable over time.
How they fit together: defense in depth
Taken individually, each of these six covers one risk. Taken together, they form a defense in depth that covers the entire perimeter of an agentic orchestrator:
- information security as the foundation (27001),
- extended specifically to the cloud (27017) and to personal data in the cloud (27018),
- responsibly managed AI aligned with the AI Act (42001),
- cyber resilience and supply chain reliability under European law (NIS2),
- and quality as the method that keeps the whole thing coherent and improving.
It's no coincidence that these standards are designed to integrate: 42001 is explicitly built to be compatible with 9001 and 27001, so that AI governance is grafted onto the existing management system instead of living as a separate silo.
What this concretely means for those adopting AIsuru
For an IT manager, a DPO, or a procurement office, all of this translates into practical, measurable benefits:
- Faster onboarding: the certifications answer, in advance, most of the questions in a supplier assessment.
- Simplified DPIA and compliance: 27018 and 27001 provide ready-made evidence for impact assessments and GDPR compliance.
- AI Act readiness: 42001 aligns AI adoption with European requirements, reducing regulatory risk.
- Adoption possible within the critical perimeter: NIS2 compliance makes AIsuru an acceptable provider even for entities and companies subject to the directive.
- Demonstrable trust: when a customer asks for guarantees on how their data is handled with AI, the answer isn't a brochure, but a set of third-party-verified attestations.
And above all, these certifications are not a coat of paint on top of the product: they mirror the way AIsuru is built. Encrypted connector credentials never exposed to the model, human oversight, traceability of actions, deployment options down to on-premise, centralized governance: these are the same practices the standards require. In this sense, certification hasn't changed what we do — it has made verifiable what we were already doing.
The real standard is trust
Private, controllable, and governed knowledge has always been Memori's guiding light. With these six attestations, that principle stops being a statement of intent and becomes something a third party has examined, measured, and confirmed from the first line to the last.
For those bringing AI into processes that matter, businesses and Public Administration, this is exactly the difference that counts: not the power of a model, but the trust that can be demonstrated around it.