STOCK TITAN

ZoomInfo Expands ISO Assurance Program with ISO/IEC 42001 Certification, Validating its Rigorous AI Governance

ZoomInfo will maintain the certification through periodic surveillance audits and continued improvement of its AI management system.

(Moderate)

Sentiment and the balance of points

Rhea-AI Sentiment reads the wording of the document, how positive or negative its language is on a 1 to 5 scale. The balance of points shown with the takes weighs what the document actually discloses, so the two can disagree, for example when a trial that missed its main goal is described in upbeat language.

Tags
AI
See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

Independent assessment by Schellman recognizes ZoomInfo’s disciplined approach to governing AI, managing risk and impact, and continually improving its AI management system.

VANCOUVER, Wash.--(BUSINESS WIRE)-- ZoomInfo (NASDAQ: GTM) announced today that it has achieved ISO/IEC 42001:2023 certification for its Artificial Intelligence Management System (AIMS). The achievement builds on ZoomInfo's record in responsible AI.

The ISO/IEC 42001 certification was issued by Schellman, a well-established, accredited certification body, following an independent, multi-stage assessment. The certification marks an important achievement in ZoomInfo’s ongoing investment in secure, accountable, and well-governed AI. The certification is the international standard for artificial intelligence management systems, providing a framework for organizations to establish, implement, maintain, and continually improve the way AI is governed across its lifecycle.

ZoomInfo established the governance structure, accountability, risk and impact management practices, operational controls, performance evaluation, and continual-improvement processes assessed during certification.

“This certification gives customers confidence that ZoomInfo is governing AI effectively, and it’s another demonstration of our investment in compliance, privacy, and security. As agentic capabilities evolve, it gives GTM leaders the assurance they need to adopt ZoomInfo with confidence and cut through procurement red tape,” said Ben Calvert, Chief Information Security Officer at ZoomInfo.

What This Means for Customers

For customers, this certification provides independent, third-party assurance that ZoomInfo manages its AI capabilities through a structured, internationally recognized management system. It supports:

  • Greater confidence in AI-enabled capabilities: Independent validation that ZoomInfo has established governance, accountability, risk-management, impact-assessment, and oversight practices for its AIMS.
  • More efficient enterprise reviews: Recognized third-party certification that can help support security, vendor-risk, and procurement assessments.
  • Assurance that continues beyond certification: ISO/IEC 42001 is not a point-in-time review. ZoomInfo will maintain its certification through periodic surveillance audits and the continual improvement of its AIMS.
  • Broader assurance: ISO/IEC 42001 certification adds to ZoomInfo’s portfolio of third-party AI assurance, which also includes a separate TRUSTe Responsible AI Certification from TrustArc.

Independent Assessment by Schellman

Schellman evaluated ZoomInfo’s Artificial Intelligence Management System through a Stage 1 review and Stage 2 certification audit.

Schellman concluded that ZoomInfo’s AIMS conforms to the requirements of ISO/IEC 42001 and is operating effectively. The assessment found ZoomInfo’s controls effective across the core management-system requirements in Clauses 4 through 10, as well as applicable Annex A control testing. The final report recorded zero findings across ZoomInfo’s 2026 Stage 1 and Stage 2 reviews, including zero nonconformities and zero opportunities for improvement, demonstrating the maturity and effectiveness of ZoomInfo’s AI management system.

“ISO/IEC 42001 certification reflects ZoomInfo’s commitment to governing AI with rigor, accountability, and ongoing oversight,” said James Grant, Vice President Security and Field Chief Information Security Officer at ZoomInfo. “Schellman’s independent assessment found that our AI management system met the standard and was operating effectively, with no findings, nonconformities, or opportunities for improvement. That is a strong indication that the management system we’ve built for AI is mature, durable, and working as intended.”

ZoomInfo’s Enterprise Trust Credentials

ISO/IEC 42001 certification complements ZoomInfo’s broader independent assurance portfolio, which includes:

  • ISO/IEC 27001 for information security management
  • ISO/IEC 27701 for privacy information management
  • ISO/IEC 27017 for information security controls for cloud services
  • SOC 2 Type II examination
  • TRUSTe Responsible AI Certification from TrustArc

Learn More
Visit the ZoomInfo Trust Center for more information about ZoomInfo's responsible AI practices, data privacy certifications, and governance frameworks.

About ZoomInfo
ZoomInfo (NASDAQ: GTM), the all-in-one AI GTM platform, enables sales, marketing, and customer success teams to execute their go-to-market strategy with confidence. Powered by the industry's most comprehensive B2B data, including more than 100 million companies, 500 million contacts, and billions of signals, ZoomInfo delivers the intelligence, automation, and integrations that modern revenue teams need to identify, engage, and convert their best buyers.

GTM.AI is ZoomInfo's headless GTM context layer. It is the API and Model Context Protocol home for AI agents, powering integrations across Salesforce Agentforce, HubSpot Breeze, Microsoft Copilot Studio, Alysio, Claude, ChatGPT, and dozens more.

Learn more at zoominfo.com and gtm.ai.

Media: Public Relations Team, ZoomInfo, PR@zoominfo.com

Source: ZoomInfo

Key Terms

iso/iec 42001:2023 technical
An international standard that sets out requirements for an organization’s management system to govern the safe, reliable, and responsible development and use of artificial intelligence. Think of it as a playbook or safety checklist that helps companies design processes, controls and documentation so AI tools behave predictably and comply with laws and expectations; for investors, certification or alignment can signal lower operational, legal and reputational risk and better long-term value.
surveillance audits technical
Periodic examinations of a firm’s or market regulator’s surveillance systems, controls and procedures that monitor trading, communications or other activity for market abuse, rule breaches or compliance failures. A surveillance audit checks whether the algorithms, data feeds, alerting thresholds, recordkeeping and escalation processes are operating as designed and producing appropriate investigations or reports; it assesses effectiveness and documents required remediation but is distinct from a financial audit of accounting records.
nonconformities regulatory
Nonconformities are specific instances where a process, product, record, system, or behaviour fails to meet a required standard, specification, law, regulation, contract term, or internal policy. They are usually identified by audits, inspections, testing, or monitoring and trigger documented corrective or preventive actions to restore compliance; a nonconformity is a factual departure from a requirement, not a judgment about intent or legal liability.
soc 2 type ii technical
A SOC 2 Type II report is an independent audit that verifies a company’s operational controls for protecting customer data work effectively over a sustained period, not just at a single point in time. Think of it like a multi-month health inspection for a business’s data practices: it reassures customers and investors that systems are managed reliably, lowering the risk of breaches, service interruptions, and regulatory or liability costs.

Keep reading