Which AI Translation Certifications Matter for Medical Devices and Pharma

Five certifications decide whether an AI translation company can touch medical device and pharma content without creating a compliance problem: ISO 13485, ISO 17100, ISO 18587, ISO 27001 and ISO 42001. A logo on a website is not the same as a certificate, and a certificate for the wrong scope is worth less than it looks. The difference shows up in an audit, not in a sales deck.
AD VERBUM holds all five, plus ISO 9001, ISO 14001 and AQAP 2110, with GDPR- and HIPAA-compliant processes. We deliver AI translation as a client-tuned open-weight language model constrained by your Translation Memory and Term Base, then certified subject-matter review, on EU-hosted infrastructure with no training on your data. That full stack is rare, and the reason it matters is that a medical device file and a pharma dossier each lean on a different subset of it.
No regulation tells you to hire a certified translation company. What the rules require is accuracy, traceability and data control, and these certifications are how a provider proves it delivers all three on AI output rather than asserting it. We set out the workflow behind that in our explainer on what AI translation means for regulated content. Here are the five that matter for devices and medicines, ranked by how much weight each carries in a regulated workflow, with what it actually covers and what to check before you trust it.
The five certifications that matter, ranked
These are the certifications worth asking for, ordered from the one every regulated translation rests on to the one that separates a serious AI translation provider from the rest. For each, here is what it governs in plain words, and why the scope on the certificate decides whether it means anything for your content.
1. ISO 17100, the translation process standard
ISO 17100 is the baseline. It sets requirements for the translation service itself: qualified translators, a mandatory independent revision step by a second linguist, defined project management, and documented quality control. A translation company without it is asking you to take its process on trust. The ISO 17100 standard does not mention AI, and that is the point. Whatever generates the first draft, a machine or a person, the standard demands that a competent human reviser checks the result and that the process is recorded. For AI translation this is the control that converts raw model output into a defensible translation, because it forces the independent review and the audit trail that a regulator later reads. Ask whether the certificate covers your language pairs and your subject field, not just a head office.
2. ISO 18587, post-editing of machine and AI output
ISO 18587 is the one written for exactly this moment. It defines full human post-editing of machine translation output, requiring a qualified post-editor who takes responsibility for the final text. When your first draft comes from a language model, this is the standard that governs the step that makes it safe to publish. The ISO 18587 standard is under revision, with the updated version expected in October 2026 to broaden its scope explicitly to non-human translation output, which is to say LLM-generated content. That revision closes any argument that the standard only covered older engines. A provider certified to ISO 18587 is telling you its AI output passes through a defined, qualified editing process, the distinction we draw in what AI translation means for regulated content. Without it, post-editing is whatever the vendor decides it is on the day.
3. ISO 13485, the medical device quality system
ISO 13485 is the medical device quality management system standard, and for devices it is the one that moves a translation vendor from general to qualified. It requires supplier control, competence management and documented procedures across the device supply chain, which is what MDR expects of the manufacturer and flows down to translation. The ISO 13485 standard does not describe how to translate, so on its own it is not enough, which is why a compliant device workflow pairs it with ISO 17100. The language obligation itself sits in Article 10(11) of the Medical Device Regulation 2017/745, which requires instructions for use and labelling in the official languages of each market. The trap here is scope: some providers hold ISO 13485 for an unrelated activity, not for translation of device documentation, so we go into exactly how to read it in our piece on which AI translation companies hold ISO 13485 for medical devices. Read the scope line before you count it.

4. ISO 27001, information security
ISO 27001 is the information security management standard, and for both devices and pharma it answers the question regulators and legal teams ask first: where does our data go. It governs access control, encryption, incident handling and supplier security across the whole workflow, from file intake to delivery. The ISO 27001 standard matters doubly for AI translation, because the risk is not only who reads a file but whether the content transits a public-cloud endpoint or trains someone else's model. Clinical data and pre-authorisation content are special-category or confidential by nature, and Article 9 of the GDPR sets a high bar for health data specifically. A provider with ISO 27001 across EU-hosted infrastructure, and a clear statement that it does not train on your data, is the combination that keeps that content inside the jurisdiction that regulates it. A certificate scoped to a single office is not the same as one covering the production workflow.
5. ISO 42001, the AI management system
ISO 42001 is the newest of the five and the one most translation companies still do not publicly hold. Published in December 2023, it is the first certifiable standard for an artificial intelligence management system, covering AI risk assessment, data governance for AI, human oversight and continual improvement. The ISO 42001 standard is the operating system for auditable AI, and it maps directly onto the obligations in the EU AI Act, Regulation 2024/1689, including risk management under Article 9, data governance under Article 10 and human oversight under Article 14. For a buyer choosing an AI translation provider, this is the certificate that shows the AI itself is managed, not just the words it produces. A handful of platform vendors hold it at product scope. Among translation companies serving regulated life sciences, it is still the exception, and that is why we treat it as the separator rather than the baseline.
Ask for the certificate, and read the scope line
A badge proves nothing on its own. Before you rely on any of the five, ask the provider four questions, and expect a document rather than a reassurance:
Show me the certificate itself, with the certification body named and the expiry and surveillance-audit dates current. A lapsed certificate is not a certificate.
What is the scope line. It should name translation or localisation of your document type, not software, consulting or an unrelated activity that happens to carry the same ISO number.
Which sites and processes does it cover. A certificate for one office is not a certificate for the production workflow that will handle your files.
For AI specifically, does the ISO 18587 and ISO 42001 scope cover the model-plus-review workflow you will actually use, including where the data is hosted.
The same discipline applies when you compare named providers against each other, which we do criterion by criterion in our guide to AI translation companies for MDR and IVDR documentation. The certificate, its scope and its dates are the facts that survive an audit.

Why the full stack, not a single certificate, is the real test
A provider can hold one or two of these and still leave a gap that surfaces at the worst time. A device IFU needs ISO 13485 and ISO 17100 together. A pharma dossier leans on ISO 17100 and ISO 27001. Any AI workflow that touches either needs ISO 18587 for the post-editing and ISO 42001 for the governance. Hold only part of the set and part of the risk is unmanaged, which is the case we make across our guide to AI translation companies for life sciences.
We at AD VERBUM built the full stack on purpose, because regulated device and pharma work needs all five at once. Our certified subject-matter linguists review AI output under ISO 17100 and ISO 18587, on client-tuned open-weight models we host in the EU with no training on your data, under ISO 27001 security and ISO 42001 AI governance, and ISO 13485 for device documentation. That is the same combination behind our AI translation services for medical device IFUs and labelling, and it is what lets a manufacturer or a marketing authorisation holder hand an auditor a record instead of an assurance.
Our regulated AI translation services
Our translation services for regulated sectors run on ISO 27001 and ISO 42001 certified, EU-hosted infrastructure, with no reliance on public cloud tooling for core processing. Every project runs through our AI+HUMAN hybrid workflow: we ingest client Translation Memories and Term Bases first, our proprietary LLM-based LangOps System generates output constrained by client terminology on client-tuned open-weight models, and our certified subject-matter experts review for technical accuracy and regulatory compliance. Our QA is aligned to ISO 17100 and ISO 18587, with sector-specific requirements such as ISO 13485 for medical devices and GDPR Article 9 handling of health data applied where relevant. We serve Life Sciences, Legal, Finance, Defense, and Manufacturing clients across 150+ languages with 3,500+ subject-matter linguists. For teams managing audit-sensitive content, contact us to discuss your security and compliance requirements directly.
FAQ
Which certifications matter most for AI translation in medical devices and pharma?
Five: ISO 13485 for the device quality system, ISO 17100 for the translation process, ISO 18587 for post-editing of AI output, ISO 27001 for information security, and ISO 42001 for AI management. Devices lean on ISO 13485 and ISO 17100, pharma on ISO 17100 and ISO 27001, and any AI workflow needs ISO 18587 and ISO 42001 on top.
What does ISO 18587 cover for AI translation?
ISO 18587 defines full human post-editing of machine translation output and requires a qualified post-editor to take responsibility for the final text. Its revision, expected in October 2026, broadens the scope explicitly to non-human translation output, meaning LLM-generated content. It is the standard that governs the review step turning raw AI output into a publishable translation.
Does ISO 42001 certification matter when choosing a translation company?
Yes, because ISO 42001 is the first certifiable AI management system standard and maps onto the EU AI Act, Regulation 2024/1689, covering AI risk, data governance and human oversight. Most translation companies serving regulated life sciences do not publicly hold it, so it separates a provider that manages its AI from one that only manages its words.
Is ISO 13485 alone enough for medical device translation?
No. ISO 13485 is the device quality management system standard but does not describe the translation process, so a compliant workflow pairs it with ISO 17100. The language obligation itself comes from Article 10(11) of the Medical Device Regulation 2017/745. Always check the ISO 13485 scope names translation of device documentation, not an unrelated activity.
How do I verify a translation company's certifications?
Ask for the certificate itself, with the certification body named and the expiry and surveillance dates current, then read the scope line to confirm it covers translation of your document type and the sites that will handle your files. A logo is not proof; a scoped, in-date certificate is.
Does AI translation keep data secure under these standards?
It does when the provider holds ISO 27001 across EU-hosted infrastructure and trains no model on your data, which keeps health and pre-authorisation content inside the jurisdiction that regulates it under GDPR Article 9. AD VERBUM processes regulated content on EU infrastructure under ISO 27001 and ISO 42001, with no public-cloud reliance for core processing.

