Neptune Software is now Certified Under the World’s First International Standard for AI Management Systems.
By Ron Kapelle, General Counsel, Neptune Software
Enterprise AI is moving fast. The models are improving, the use cases are multiplying, and the pressure to deploy is real. What is not keeping pace is the governance infrastructure around it: who is accountable for what the AI does, how supplier risk is managed, how data is protected, and how the organization responds when something goes wrong.
For companies deploying AI inside an SAP environment, those questions have real weight. SAP holds the operational core of the business: financial records, HR data, procurement, supply chain. AI operating within or adjacent to that data needs to be governed with the same rigor applied to the data itself.
As General Counsel at Neptune Software, AI governance is not an abstract concern for me. It is a daily operational responsibility. This post explains what we have done to formalize that responsibility, and what it means for the enterprises we work with.
ISO/IEC 42001 is a different kind of bar. It is an internationally recognized standard for Artificial Intelligence Management Systems, and it requires independent certification. Not self-attestation. Not a policy document. Proof, reviewed by an accredited Certification Body.
Neptune Software has earned that certification.
What makes this certification worth noting is not only the achievement itself, but the scope of the certification.
“The use, development, integration, configuration, deployment, distribution, and operation of third-party AI systems within the organization’s software, including supplier oversight, AI risk management, monitoring, data governance, and continual improvement, supporting the delivery of AI-enabled tools.”
Our certification scope reflects the real-world lifecycle of AI within an enterprise software platform. That distinction matters for any enterprise evaluating AI vendors, and we will explain why below.
What ISO/IEC 42001 actually is
ISO/IEC 42001:2023 is the first international standard specifically built for AI Management Systems. Developed by the International Organization for Standardization and the International Electrotechnical Commission, it establishes a framework for how organizations use, govern, develop, and operate AI responsibly.
ISO 42001 follows the same high-level structure as ISO 27001 and ISO 9001: policy, risk assessment, controls, audit, and continual improvement. Organizations already running either framework will find the architecture familiar. What distinguishes it is a set of AI-specific control objectives and controls that govern the full AI lifecycle, from system acquisition and data governance to supplier oversight and continual improvement. Together, these controls make responsible AI governance operational, not as a standalone initiative, but as an integrated management system with clear ownership, documented objectives, and measurable outcomes.
Why scope is the differentiator
Any software company serious about AI governance can pursue ISO 42001 certification. The question worth asking is: what did they certify, and across how many AI roles?
ISO/IEC 42001 defines specific AI roles, drawn from the EU AI Act framework. Neptune’s certification scope covers the following:
- AI User
- AI Provider
- AI Developer
- AI Integrator
- AI Deployer
- AI Operator
- AI Platform Provider
- AI Distributor
Across all of those roles, the standard governs AI risk management, data governance, monitoring, and continual improvement. That is the picture of how AI operates inside a platform like Neptune, and what our customers need governed when they deploy AI through our software into their SAP environments.
A narrower scope, limited to how AI is used internally for example, or covering only development, leaves significant surface area unaddressed. When an enterprise asks whether a vendor’s AI is governed, the answer depends entirely on what that governance actually covers.
What this means for enterprises running SAP
The enterprise SAP environment has particular requirements when it comes to AI. SAP data is often among the most sensitive an organization holds: financial records, HR data, supply chain, procurement, operational systems of record. AI operating within or adjacent to that data carries meaningful risk.
For Neptune customers, ISO 42001 certification translates to three concrete outcomes.
First, validated governance across the full AI lifecycle. Not a policy document. A certified management system, independently audited, covering every stage from how AI is sourced and configured to how it is monitored in production.
Second, faster internal compliance approvals. In regulated industries such as financial services, the public sector, and utilities, vendor AI governance is increasingly a procurement requirement. A certified scope that covers supplier oversight and data governance gives procurement and legal teams something substantive to work with.
Third, alignment with the EU AI Act trajectory. ISO 42001 aligns with the risk-based approach the EU AI Act takes. Organizations that are already working toward compliance will find a certified AI Management System reduces the distance significantly.
The honest version of what certification requires
Achieving ISO 42001 certification is not a checkbox project. It requires building and maintaining a genuine management system: documented policies, formal risk assessment processes, supplier evaluation frameworks, monitoring mechanisms, and a structured approach to continual improvement. The audit tests all of it.
We pursued this because the framework reflects how we already believe AI should be governed: with accountability at every stage, clear oversight of the systems and suppliers we rely on, and a feedback loop that improves over time. The certification validates that commitment against an external standard.
ISO certification is not a one time event. It requires ongoing maintenance through annual internal and external audits, with continuous improvement and updates to keep the management system current and maintain the certification over time.
Where this fits in the broader AI governance landscape
AI governance is moving from voluntary to mandatory. The EU AI Act is in force. Sector regulators in financial services, healthcare, and the public sector are tightening their expectations of AI vendors. Procurement teams at large enterprises are adding AI governance requirements to their standard vendor assessment processes.
ISO 42001 is the most credible independent standard available today for AI management systems. It is the framework that regulators and enterprise buyers will increasingly reference. Earning it now, and with a scope that covers AI roles, positions Neptune and our customers ahead of where the regulatory environment is heading.
We are not making claims about what certification delivers in the abstract. The scope of our certification describes exactly what is governed. Enterprises evaluating AI vendors can use that scope as a concrete checklist.
What comes next
ISO 42001 certification is one part of how Neptune governs AI. It sits alongside our data governance practices, our approach to model quality and auditability, and the controls we build into how AI is surfaced inside our low-code platform.
For customers who want to understand the certification in more detail, including what the management system covers and how it maps to their own compliance requirements, we are available to walk through it directly. Contact your Neptune account team or reach us through this link.


