
ISO 42001 vs SOC 2 for AI vendors in 2026: what each audits, which one covers AI decisioning, and how to verify a vendor's compliance claims before signing.
ISO 42001 and SOC 2 answer two different questions about an AI vendor, and enterprise buyers evaluating voice AI platforms in 2026 need both answered before they sign. One tells you the vendor won't leak your data. The other tells you the AI won't make an undocumented decision on your behalf. This breaks down what each certification actually audits, which one carries more weight for a phone-based AI vendor, and how to verify a vendor isn't just name-dropping a standard on a sales deck.
TL;DR
SOC 2 Type II covers data security and infrastructure; ISO 42001 covers AI governance and model behavior — most enterprise vendors need both by 2026.
ISO 42001, published December 2023, is the only standard that audits how an AI system makes and documents decisions, not just how data is stored.
harmony.ai runs SOC 2 Type II, HIPAA BAA availability, GDPR/CCPA readiness, and TCPA-aware calling controls — verify equivalents before signing any voice AI contract.
Skip vendors offering only a SOC 2 Type I letter — demand Type II, which covers 6-12 months of observed controls, not a single point in time.
Why this matters
A voice AI vendor that qualifies leads, books appointments, or handles a collections call is making decisions on your behalf in real time, on a live phone line, often with regulated data in play. SOC 2 was built for SaaS companies storing data in a database. It was never built to answer "does the AI escalate correctly" or "can you show me why it said that."
ISO 42001 closes that gap. It's an AI management system standard — it audits risk assessment, lifecycle controls, and documentation of how an AI system behaves, not just where the data sits. For a category built on autonomous phone calls, that distinction is the whole evaluation. harmony.ai treats both as baseline, not marketing checkboxes, because a vendor that only has one has only answered half the question an enterprise buyer is actually asking in 2026.
The practical stakes: a bank, insurer, or collections agency putting an AI voice agent on live calls is on the hook for both data handling and decision auditability. Skipping either certification in vendor diligence means signing a contract you can't defend to your own compliance team.
How we ranked these
The order below reflects how enterprise RFPs actually weight these frameworks in 2026 — cross-referenced against what regulated buyers in banking, healthcare, insurance, and collections require before a voice AI vendor gets past security review. Weight is based on how often each certification appears as a hard requirement (not a nice-to-have) in aggregated vendor evaluation criteria, not on marketing claims from any single vendor. A framework ranks higher when its absence is a deal-breaker rather than a footnote.
The ranked list
1. SOC 2 Type II — the floor, not the ceiling
The baseline every enterprise security team checks first. SOC 2 Type II audits a vendor's controls over a 6-12 month observation window, covering data security, availability, and confidentiality — not a single-day snapshot like Type I.
A voice AI vendor without SOC 2 Type II shouldn't reach a contract discussion in 2026, full stop. It says nothing about the AI's decision quality, but it's the entry ticket. Verdict: Buy — non-negotiable, reject any vendor with only a Type I letter.
2. ISO 42001 — the AI-specific layer SOC 2 skips
Published in December 2023, ISO 42001 is the first international standard for AI management systems. It audits risk assessment, data provenance, model change control, and documentation of how an AI system reaches a decision — exactly the gap SOC 2 leaves open for a vendor running autonomous voice calls.
Certification runs on a 3-year cycle with annual surveillance audits, so it's not a one-time badge. For any vendor whose AI is qualifying leads, quoting renewals, or handling a collections call, this is now the differentiator that separates a compliance-serious platform from one running an unaudited model in production. Verdict: Buy — required for any AI vendor making autonomous decisions on live calls.
3. HIPAA BAA availability — mandatory for healthcare, irrelevant otherwise
A Business Associate Agreement isn't a certification — it's a contractual commitment that the vendor will handle PHI under HIPAA rules. Neither SOC 2 nor ISO 42001 covers this; it has to exist separately. For a full breakdown of which vendors offer it, see the roundup of HIPAA-compliant AI voice agents.
If your calls touch patient data — scheduling, intake, benefits verification — a vendor without BAA availability is a hard stop regardless of what else is on their compliance page. If they don't, it's simply not relevant to your evaluation. Verdict: Buy if healthcare touches the call flow, Skip the line item entirely if it doesn't.
4. GDPR/CCPA readiness — table stakes for any consumer-facing deployment
GDPR and CCPA aren't certifications either — they're regulatory frameworks a vendor either architects around or doesn't. Readiness means data minimization, deletion rights, and consent logging are built into the call flow, not bolted on after a legal review flags a problem.
Any vendor calling US or EU consumers in 2026 without a clear answer on data retention and deletion is exposing you to regulatory risk you didn't sign up for. Verdict: Buy — confirm in writing, not in a sales deck.
5. ISO 27001 — solid, but largely redundant next to SOC 2
ISO 27001 is the general information security management standard that ISO 42001 borrows its structure from. Many vendors hold both ISO 27001 and SOC 2 Type II, and the overlap is real — both audit access controls, incident response, and data handling.
It's a reasonable signal of security maturity, and it matters more if your buying committee is international and unfamiliar with SOC 2's US-centric audit format. But if a vendor already has SOC 2 Type II, ISO 27001 adds confirmation, not new information. Worth weighing when comparing build vs. buy for enterprise voice AI — building in-house means you own this audit burden yourself. Verdict: Hold — nice to have, not worth trading off against a vendor with stronger ISO 42001 or SOC 2 posture.
6. TCPA-aware calling controls — the one that's actually about the phone
None of the frameworks above touch outbound calling law directly. TCPA compliance is about consent capture, calling window restrictions, and Do Not Call list enforcement — specific to the fact that this vendor is dialing phones, not just storing data. The compliance-first playbook for outbound AI calling breaks down what a real audit trail looks like here.
A vendor can pass SOC 2 and ISO 42001 and still mishandle consent on an outbound dial. This is the line item that gets missed in security review because it's a calling-law issue, not an infosec one. Verdict: Buy — ask for the audit trail format before the contract, not after a complaint.
Comparison table
SOC 2 Type II
What it audits: Data security, availability, confidentiality controls
Audit cadence: Annual, 6-12 month observation
Who needs it: Every vendor, no exceptions
ISO 42001
What it audits: AI decisioning, model change control, risk management
Audit cadence: 3-year cycle, annual surveillance
Who needs it: Any vendor running autonomous AI on live interactions
HIPAA BAA
What it audits: Contractual PHI handling commitment
Audit cadence: N/A — contract, not audit
Who needs it: Healthcare-touching call flows only
GDPR/CCPA readiness
What it audits: Consent, retention, deletion rights
Audit cadence: Ongoing self-attestation, verify in contract
Who needs it: Any consumer-facing deployment
ISO 27001
What it audits: General infosec management
Audit cadence: 3-year cycle, annual surveillance
Who needs it: Redundant if SOC 2 Type II is present
TCPA-aware controls
What it audits: Consent capture, calling windows, DNC enforcement
Audit cadence: Ongoing, vendor-maintained
Who needs it: Any outbound dialing use case
How to verify a vendor's certifications
Ask for the actual report, not the logo. A SOC 2 badge on a website means nothing without the report itself — request it under NDA and check the audit period, not just the certification date.
Check the scope statement on ISO 42001. Some vendors certify a narrow slice of their org, not the AI system making the calls. Read the scope paragraph before assuming it covers your use case.
Confirm the audit is current. SOC 2 Type II reports expire on a rolling 12-month basis and ISO 42001 runs annual surveillance audits — an 18-month-old report is a red flag, not a technicality. If a vendor is dodging the request, that's your answer. For a wider look at how platforms stack up on this axis, the ranked list of enterprise AI voice agent platforms for 2026 is a useful cross-check before you shortlist.
Check harmony.ai's compliance posture
SOC 2 Type II, HIPAA BAA availability, GDPR/CCPA readiness, TCPA-aware calling controls.
FAQ
What is the difference between ISO 42001 and SOC 2?
SOC 2 audits data security and infrastructure controls; ISO 42001 audits how an AI system makes and documents decisions. A voice AI vendor needs both to cover data handling and AI decisioning risk in 2026.
Does SOC 2 cover AI-specific risks?
No. SOC 2 Type II covers access controls, availability, and confidentiality of stored data, not model behavior, drift, or decision logic. ISO 42001 is the standard built specifically for AI management systems.
Is ISO 42001 mandatory for AI vendors in 2026?
It's not legally mandatory, but it's becoming a hard requirement in enterprise RFPs for any vendor running autonomous AI on live customer interactions. Regulated industries like banking and insurance increasingly treat it as a deal-breaker.
Do I need both ISO 42001 and SOC 2 from a voice AI vendor?
Yes, for any vendor whose AI is autonomously qualifying leads, booking appointments, or handling regulated calls. SOC 2 covers the infrastructure; ISO 42001 covers the AI decisioning layer that SOC 2 doesn't touch.
How long does ISO 42001 certification take?
Initial certification typically runs several months from gap assessment to audit, followed by a 3-year certification cycle with annual surveillance audits. Published in December 2023, it's still new enough that certified vendor pools are smaller than SOC 2.
What is a HIPAA BAA and why does it matter for voice AI?
A Business Associate Agreement is a contractual commitment that a vendor will handle protected health information under HIPAA rules. It's separate from SOC 2 or ISO 42001 and required for any voice AI touching patient scheduling, intake, or benefits calls.
Is TCPA compliance part of SOC 2 or ISO 42001?
No. TCPA compliance covers consent capture, calling window restrictions, and Do Not Call enforcement for outbound calls — neither infosec framework addresses it. Ask for the audit trail format separately from either certification.
Which certification should I check first when evaluating a voice AI vendor?
Start with SOC 2 Type II as the non-negotiable floor, then check ISO 42001 for any vendor whose AI is making autonomous decisions on calls. Treat HIPAA BAA and TCPA controls as separate, use-case-specific requirements layered on top.
One last thing
Most vendor security pages list ISO 27001 and SOC 2 side by side and stop there — ISO 42001 doesn't show up because most voice AI vendors don't have it yet. That gap is temporary. As more enterprise RFPs in banking, insurance, and collections start requiring it by name, the vendors without it will be explaining the absence in every security review instead of pointing to a report. Ask for it now, before it's the standard question.