top of page
Search

Which Five Certifications Are Non-Negotiable for Regulated Translation

  • 3 hours ago
  • 5 min read

An ISO 17100 certificate on its own no longer clears a regulated tender. Buyers in medical devices, defence, and finance ask for a stack of standards now, and they check each one against your supplier file. A translation company that holds one process certificate and nothing else looks thin the moment a notified body auditor or a data protection authority starts reading.


The five that form the entry ticket


Five certifications now sit at the base of any serious regulated-translation supplier. Each proves a different thing, and each is audited independently:


  • ISO 17100 governs the translation process itself, with qualified linguists, a mandatory independent second-linguist revision, and defined project records.

  • ISO 27001 covers information security, the control set your client relies on for GDPR and for handling controlled technical data under Regulation 2021/821 Article 2.

  • ISO 42001 runs the AI management system, the operating layer behind EU AI Act obligations for any supplier using machine translation or large language models.

  • ISO 14001 manages the environmental side, now a scored line in public and enterprise procurement rather than a footnote.

  • ISO 9001 is the quality baseline the other four build on, tying objectives, audits, and corrective action into one management system.


Hold four of the five and the gap is the first thing a procurement reviewer circles.


Why the five behave as one system


These are not five separate binders. Since 2021 every ISO management system standard is built on the Harmonized Structure, the template once called Annex SL, a fixed ten-clause sequence with shared terms. Context, leadership, planning, support, operation, performance evaluation, and improvement read the same way across ISO 9001, ISO 27001, ISO 42001, and ISO 14001.


So a company that holds all five runs one integrated management system, not five parallel ones. A single risk register feeds every standard, and one internal audit programme covers the set. When ISO 14001:2026 arrived in April 2026, folding the 2024 climate-change amendment into the main text, it moved onto the structure the others already used, which is why an integrated shop absorbed the change without rebuilding how it works. We set out the environmental footprint of AI translation separately.



What a missing certification costs in an audit


The consequence surfaces at review time, and it is specific to whoever is reviewing. A gap tends to show in three places:


  • In a notified body audit under MDR (Regulation 2017/745), a device manufacturer must show translation ran through a controlled process. A supplier without ISO 17100 leaves the independent revision step undocumented, and the manufacturer wears the finding.

  • In a data protection authority review, a supplier without ISO 27001 has no certified control set to point to, so you carry the full burden of proving GDPR-adequate handling of the content you sent for translation.

  • In a client or tender qualification, a supplier routing text through an ungoverned AI tool with no ISO 42001 has no impact assessment and no audit trail, a direct exposure under EU AI Act Articles 9, 10, and 15.


Each gap moves risk from the supplier back to you, which is the opposite of what a certificate is meant to do.


Why ISO 17100 alone stopped being enough


For years a single ISO 17100 certificate was shorthand for a serious translation company. That held while translation stayed a human-only task with no AI in the loop and no security or environmental line in the tender. None of those conditions still holds. Machine translation and LLMs sit inside most production workflows now, which pulls AI governance into scope. GDPR enforcement turned data security into a contract term. Public buyers score environmental management. A supplier that stopped at ISO 17100 is certified for the one part of the job that changed least, which is why regulated buyers ask for the wider certification set.



Where AD VERBUM stands


AD VERBUM holds all five: ISO 17100, ISO 27001, ISO 42001, ISO 14001, and ISO 9001. We also carry ISO 13485 for medical device documentation and ISO 18587 for post-editing, plus AQAP 2110 certification for NATO defence work. We run them as one system on EU-hosted infrastructure, so the ISO 42001 governance behind our LangOps System, the ISO 27001 controls around client data, and the independent revision step under ISO 17100 all sit inside the same audited framework. If you want the detail on the AI side, we set out what ISO 42001 requires from an AI-governed supplier.


That means when your notified body, your data protection authority, or your procurement team asks for the supplier file, the answer is one integrated set of certificates instead of a single badge and a list of things we align to. It also lets us pair security and environmental credentials without treating either as an add-on.


Our regulated translation services


Our translation services for regulated sectors run on ISO 27001 and ISO 42001 certified, EU-hosted infrastructure, with no reliance on public cloud tooling for core processing. Every project runs through our AI+HUMAN hybrid workflow: we ingest client Translation Memories and Term Bases first, our proprietary LLM-based LangOps System generates output constrained by client terminology on client-tuned open-weight models, and our certified subject-matter experts review for technical accuracy and regulatory compliance. Our QA is aligned to ISO 17100 and ISO 18587, with sector-specific requirements such as the EU AI Act (Regulation 2024/1689), ISO 42001 AI-management governance, and ISO 14001 environmental management applied where relevant. We serve Life Sciences, Legal, Finance, Defense, and Manufacturing clients across 150+ languages with 3,500+ subject-matter linguists. For teams managing audit-sensitive content, contact us to discuss your security and compliance requirements directly.


FAQ


Which five certifications are non-negotiable for regulated translation?


ISO 17100 for the translation process, ISO 27001 for information security, ISO 42001 for AI management, ISO 14001 for environmental management, and ISO 9001 for the quality baseline. Together they cover the process, the data, the AI, the environmental footprint, and the underlying quality system that regulated buyers now check.


Is an ISO 17100 certificate enough on its own?


No. ISO 17100 certifies the translation process and independent revision, but it says nothing about information security, AI governance, or environmental management. Since machine translation and GDPR entered every regulated workflow, buyers treat a lone ISO 17100 badge as a starting point, not a full answer.


What is the Harmonized Structure, formerly Annex SL?


It is the fixed ten-clause template every ISO management system standard follows, with shared terminology across ISO 9001, ISO 27001, ISO 42001, and ISO 14001. Because the standards share this structure, a supplier can run them as one integrated management system with a single audit programme rather than five separate ones.


Which certification covers AI in translation?


ISO 42001, the first certifiable AI management system standard. It maps to EU AI Act (Regulation 2024/1689) obligations, including risk management under Article 9, data governance under Article 10, and accuracy and robustness under Article 15. Without it, a supplier using machine translation has no documented impact assessment or audit trail.


Does ISO 27001 satisfy GDPR?


ISO 27001 is not the same as GDPR, but it gives a client an audited information-security control set to rely on when proving adequate data handling. It also underpins how a supplier handles controlled technical data under Regulation 2021/821 Article 2, which matters for defence and dual-use content.


What changed in ISO 14001:2026?


ISO 14001:2026 was published in April 2026 and folds the 2024 climate-change amendment into the main text, so climate risk now sits at the centre of the environmental management system. Certificates issued to the 2015 version transition before May 2029. The revision moved onto the same Harmonized Structure the other standards use.


Recommended



 
 
bottom of page