· David

Jitterbit gets ISO 42001: AI governance becomes a buying criterion

Jitterbit says it is the first integration vendor certified to ISO 42001, the standard for AI management systems. What the certificate covers, and what it does not.

Les på norsk

On 5 March, Jitterbit published a status update on its business. Most of it is the usual mix of growth figures and customer ratings. One line is more interesting than the rest: Jitterbit says it is the first company in the integration market to be certified to ISO/IEC 42001, the international standard for AI management systems.

What ISO 42001 is

ISO 42001 was published at the end of 2023. It does for AI roughly what ISO 27001 does for information security. It does not test whether a model gives good answers. It checks whether the organisation has a management system for AI: clear roles, risk assessments, rules for data, follow-up of suppliers, and routines for monitoring and improving AI systems over time.

A certificate means an external auditor has checked that these routines exist and are followed. It says nothing directly about a single feature in the product.

Why it matters for an iPaaS

An integration platform sits in the middle of a company’s data flows. When the platform also runs AI agents, those agents get access to the same systems: ERP, CRM, HR and finance. Buyers therefore need to know how the vendor itself handles AI risk, not just which AI features it sells.

Jitterbit’s own figures show why the question is urgent. According to the company’s upcoming benchmark report, more than 80 per cent of organisations already have between one and 50 AI agents running. Many of them were built quickly, and few have been through the kind of review a new integration normally gets.

Jitterbit has launched a series of AI features over the last two years, including ready-made agents for sales, HR and knowledge search, and describes a “layered” architecture where users can move between ordinary automation and agent-based flows. The certificate is meant to show that this is done in a controlled way.

What the certificate does not answer

A certificate is a good sign, but it is not a replacement for your own assessment. A few things to keep in mind:

  1. Check the scope. Ask which parts of the organisation and which products the certificate covers. A narrow scope says less than a broad one.
  2. It is about the vendor, not about you. ISO 42001 does not govern the agents you build on the platform. You still need your own rules for access, logging and approval.
  3. It will not stay unique for long. Expect other iPaaS vendors to follow. The certificate is useful as a filter in a tender, but it does not separate the platforms from each other in the long run.

What you should ask for

Add AI governance to your requirements when you choose or renew an integration platform. Ask whether the vendor has ISO 42001 or is working towards it, how the platform logs what agents do, and how you can limit which systems an agent may reach. The answers say more about the platform’s maturity than a list of AI features.

Sources

This post was written with AI assistance and reviewed by the editor before publishing.

← All posts