How ISO/IEC 42001 Is Changing the Game for AI-First Companies

Nebuly knew achieving ISO/IEC 42001 compliance was integral to their continued commitment to security.

Based in the United States and Italy, Nebuly is a plug-and-play user analytics platform for generative AI chatbots. They’ve cracked the code on improving user engagement with GenAI chatbots by uncovering the nuances hidden in conversational AI interactions.
Nebuly’s User Intelligence platform extracts valuable insights from 99% of conversations where users implicitly express their needs and preferences. The platform then turns them into actionable insights to increase user satisfaction.

  • ISO/IEC 42001
  • ISO/IEC 27001
  • SOC 2

Challenge

Nebuly maintains a strong commitment to security and compliance, holding both ISO/IEC 27001 certifications and SOC 2 attestation, and wanted to remain at the cutting edge of compliance for their AI-first product. Operating in regions with evolving regulatory landscapes, it was no surprise when customers started asking about responsible AI and the EU AI Act. This led Nebuly to investigate ISO/IEC 42001. “Customers started asking about EU AI Act compliance, we looked into how to approach it, and we identified ISO/IEC 42001 as the practical solution we needed,” said Roux.

“We think about this as a triangle. We (Nebuly) have the knowledge about the company and our proprietary AI systems, Fairly AI has been very helpful in providing structure in terms of how to prepare for the audit, and Sensiba in conducting the audit itself.”

Julien RouxCo-Founder, Nebuly
Nebuly

Solution

Having already gone through ISO/IEC 27001 and SOC 2 audits, Roux and the team understood the work required in “preparing for the audit, and that an external partner would be needed.” Although with a newer standard, the Nebuly team had to find a partner who already had experience in the space.

Enter Fairly AI. Fairly AI provides automated testing on AI products on dimensions like fairness, privacy, and security, and this is helpful to companies wanting to adopt responsible AI practices. “We moved earlier than most companies (Q4 2024), and there were not many companies working on ISO/IEC 42001 back then. When I researched, I could see Fairly AI shaped the space and had real experience,” said Roux.

Fairly AI’s role was instrumental in getting the Nebuly team not only audit-ready but implementing the findings from the ISO/IEC 42001 audit. “I’d like to praise Fairly AI, because they’ve been instrumental in making this happen. They have been very helpful in providing the structure on how to prepare for the ISO/IEC 42001 audit.”

Result

With their audit readiness underway, Nebuly began the process of looking for an audit firm to complete the audit itself. Nebuly has been working with Sensiba for their ISO/IEC 27001 and SOC 2 audits, so adding ISO/IEC 42001 to the mix was a no-brainer for the team.

“We’re a startup, we need to move fast, and when we were looking at ISO/IEC 27001 and SOC 2, we felt that Sensiba’s process aligned with those values. Since we work with big companies, it’s important that we have a reputable auditor. After having a good experience with the other standards and a good relationship with the team, we thought this was the best way to get ISO/IEC 42001 off the ground,” said Roux.

The collaboration and communication between all three teams had an added layer of complexity, with Nebuly’s AI team based in Italy, Fairly AI in Canada, and Sensiba offering global teams. Because the audit process was spread out, it gave all three companies the chance to collaborate in a way that worked for everyone. Sensiba provided great collaboration and communication, which meant that if there was ever an issue, it got solved fast. This agile, remote approach meant the time zones didn’t impact the experience or the result.

“We think about this as a triangle. We (Nebuly) have the knowledge about the company and our AI proprietary systems. Fairly AI has been very helpful in providing structure in terms of how to prepare for the audit, and Sensiba in conducting the audit itself,” said Roux.

Ready to get started?

Find out how our GRC team can help you with your compliance. Contact us to learn more about how we can work together toward your goals.

Ready for more inspiration? Dive into additional client success stories where we showcase diverse projects, innovative solutions, and the transformative impact we’ve had on businesses like yours.