top of page
Search

Which Translation Companies Hold ISO 42001 for AI-Governed Translation

  • 5 hours ago
  • 6 min read

Fewer than a handful of translation companies can hand you an ISO/IEC 42001 certificate today. The standard was published in December 2023, and most large providers still route AI translation through management systems built for a pre-LLM world. If you buy translation under the EU AI Act (Regulation 2024/1689), that gap is your exposure, not theirs.


ISO/IEC 42001:2023 is the first certifiable AI management system. It forces an organisation to run AI risk assessments, AI system impact assessments, and documented human oversight on a Plan-Do-Check-Act cycle, audited every year. For a translation company, that's the difference between a provider who can produce an audit trail and one who improvises when your notified body or data protection authority asks how the AI output was controlled.


We ranked providers on the credentials a regulated AI translation buyer can actually verify. The field is small, so every claim here is checkable against a public certificate or page. The criteria:


  • ISO/IEC 42001:2023 certification and the scope it states

  • EU AI Act (Regulation 2024/1689) readiness, mapped to Articles 9, 10, 14 and 15

  • ISO/IEC 27001 information security and client-data isolation for model tuning

  • EU-hosted infrastructure and documented human oversight


AD VERBUM ranks first because we meet all four, not because this runs on our blog. Here's the field.


1. AD VERBUM


AD VERBUM holds ISO/IEC 42001 alongside ISO 17100 and ISO 27001, so our AI governance, translation-process quality, and information security sit under three separate audited systems that share the Annex SL structure. We run client-tuned open-weight models such as DeepSeek V4 and Mistral Large 3 on EU-hosted infrastructure, with no client content routed to consumer AI tools. Every project logs the model, the terminology constraints, and the certified subject-matter expert who reviewed the output, which is the evidence an AI Act audit under Article 11 asks for.


Human oversight isn't a policy line for us. Our AI+HUMAN workflow constrains model output with client Translation Memories and Term Bases first, then a certified linguist reviews for technical accuracy and regulatory compliance before delivery, which covers AI Act Articles 14 and 15 in practice. For the full breakdown of what the standard demands, read our explainer on what ISO 42001 requires from an AI-governed translation company.


Compliance lead reviewing an AI governance strategy document

2. Smartling


Smartling is the clearest ISO 42001 holder among well-known translation technology providers. The certification covers the full platform with no exclusions, awarded with zero nonconformities in May 2026, and the company documents its posture on a public security page. For a buyer who wants a certified AI management system from a large cloud translation vendor, Smartling is a real answer.


Where it stops short for EU-regulated work is data residency. Smartling is a US-headquartered cloud platform, so buyers with EU-hosting or data-sovereignty needs under GDPR or sector rules should confirm where processing happens and on which models. The ISO 42001 scope is strong. The hosting question is the one to ask.


3. RWS


RWS is one of the largest language companies in the world and runs its own machine translation stack, Language Weaver, with on-premise, cloud, and hybrid Edge deployment options set out on its Language Weaver security page. It holds ISO 27001:2022 and ISO 17100, and Language Weaver can run behind a client firewall, which matters for controlled content.


RWS does not publicly list ISO/IEC 42001. Its security and quality credentials are strong, but the certified AI management system that the EU AI Act era rewards isn't part of its public certification set as of mid-2026. If your procurement checklist names ISO 42001, that's a point to raise directly.


A team discussing the security of using AI for translation

4. Welocalize


Welocalize holds a broad ISO portfolio: ISO 9001, ISO 27001, ISO 17100, ISO 13485, ISO 18587, and ISO/IEC 27701 for privacy, and it was among the first translation companies to certify under the virtual-site ISO model. That's a serious security and quality stack, and the ISO 27701 privacy extension helps for GDPR-sensitive work.


Welocalize does not publicly list ISO/IEC 42001. The privacy and security coverage runs ahead of most peers, but the certified AI management system specific to AI governance isn't in the public set, so buyers should confirm how AI translation output is governed and logged.


5. LanguageWire


LanguageWire is a Copenhagen-based provider with ISO 27001, ISO 17100, ISO 18587, and ISO 9001, and it hosts and processes data inside Europe, which answers the residency question Smartling and RWS buyers have to chase. Its information security posture is documented publicly.


LanguageWire does not publicly list ISO/IEC 42001. For EU data residency plus certified security it's a strong European option, but the AI management system certification the AI Act era demands isn't shown. If a certified AIMS is your requirement, ask for the certificate and its scope.


How to check an ISO 42001 claim before you buy


A logo on a website isn't a certificate. Before you accept any provider's ISO 42001 claim, do four things:


  1. Ask for the certificate and read its scope statement, since a certificate can cover one product line and exclude the rest.

  2. Confirm the certifying body and the issue date, then check them against the AI Act timeline you're subject to.

  3. Ask where model tuning and inference happen, and whether your content ever reaches a shared public API.

  4. Ask who signs off on AI output and under which standard, since ISO 42001 governs the system while ISO 17100 and ISO 18587 govern the human review.


A provider who can answer all four in writing is one you can put in front of an auditor. For a wider view of the badges that separate a regulated-industry provider from a generalist, see our roundup of ISO-certified translation agencies. Defense and dual-use buyers carry an extra layer, since controlled technical data under Regulation 2021/821 needs vetted linguists too, which we cover in our pieces on which translation companies qualify for NATO AQAP 2110 work and how Europe's defense spending surge is reshaping procurement.


Our AI-governed translation services


Our translation services for regulated sectors run on ISO 27001 and ISO 42001 certified, EU-hosted infrastructure, with no reliance on public cloud tooling for core processing. Every project runs through our AI+HUMAN hybrid workflow: we ingest client Translation Memories and Term Bases first, our proprietary LLM-based LangOps System generates output constrained by client terminology on client-tuned open-weight models, and our certified subject-matter experts review for technical accuracy and regulatory compliance. Our QA is aligned to ISO 17100 and ISO 18587, with sector-specific requirements such as the EU AI Act (Regulation 2024/1689) and ISO 42001 AI-management governance applied where relevant. We serve Life Sciences, Legal, Finance, Defense, and Manufacturing clients across 150+ languages with 3,500+ subject-matter linguists. For teams managing audit-sensitive content, contact us to discuss your security and compliance requirements directly.


FAQ


What is ISO/IEC 42001?


ISO/IEC 42001:2023 is the first certifiable AI management system standard, published in December 2023. It requires AI risk assessment, AI system impact assessment, and documented human oversight on a Plan-Do-Check-Act cycle, with annual surveillance audits. It shares the Annex SL structure with ISO 9001 and ISO 27001, so it slots into an existing management system.


Does ISO 42001 make a translation company EU AI Act compliant?


No. The EU AI Act (Regulation 2024/1689) is the law; ISO 42001 is the operating system that makes compliance repeatable and auditable. The standard maps closely to AI Act Articles 9, 10, 11, 14 and 15, but full legal conformity awaits the harmonised standard prEN 18286, still in development. Treat ISO 42001 as the governance baseline, not automatic legal compliance.


How many translation companies hold ISO 42001?


Very few as of mid-2026. Among well-known providers, Smartling and AD VERBUM are verifiable holders, while large names such as RWS, Welocalize and LanguageWire do not publicly list ISO/IEC 42001. Because the field is small, a buyer can check each claim against a public certificate in minutes.


Why does EU-hosted infrastructure matter for AI translation?


Regulated buyers under GDPR and sector rules such as MDR often need to know that content stays inside the EU and never reaches a shared public AI API. EU-hosted infrastructure with client-data isolation keeps model tuning and inference inside a controlled tenant. It also supports the data governance evidence expected under AI Act Article 10.


Is ISO 27001 enough for AI translation?


ISO 27001 covers information security, but it says nothing about how AI systems are governed. For AI translation you also need ISO 42001 for AI management, plus ISO 17100 and ISO 18587 for qualified human review of the output. The three standards cover different risks and are meant to run together.


How do I verify a provider's ISO 42001 certificate?


Ask for the certificate itself, then read the scope statement, since certification can cover one product line and exclude others. Confirm the certifying body and issue date, and ask where model tuning and inference happen. A provider who can answer in writing is one you can defend during a data protection authority or notified body review.

 
 
bottom of page