What this review assesses and what it does not

A desk-based document audit assesses just one thing: what can be verified from public evidence. It does not replace a first-, second- or third-party certification audit; it has no access to the Statement of Applicability, management review minutes, internal KPIs or internal audit records. Its output is an assessment of auditable public support: what can be stated on the basis of open evidence and what requires speculation. That boundary matters more than marketing usually admits. The rule in Criterion 14 also applies. Evidence inherits the trust of its custody — and all the evidence examined here is in the provider's own custody, a limitation incorporated into the assessment of each standard.

The assumed scope covers OpenAI's main operations and services: API, ChatGPT for business, Enterprise and Edu and, where the organisation itself declares it, its consumer and business AI products and models. Azure OpenAI Service is excluded, as its certification and perimeter fall under Microsoft. The time cut-off: public evidence available as of 26 April 2026.

ISO/IEC 27001 · strong support, a scope the customer must reconstruct

OpenAI publishes ISO/IEC 27001 certification and explicitly links it to the systems supporting API, ChatGPT Enterprise and ChatGPT Edu. In August 2025, the Trust Portal announced the public availability of the certificate; in September 2025, the organisation announced certification by Schellman under ISO/IEC 27001, 27017, 27018 and 27701, alongside expanded SOC 2. The declared operational controls are concrete and consistent across sources.

Fact sheet

27001 controls verified in public evidence

AES-256 encryption at rest and TLS 1.2+ in transit · SSO/SAML, RBAC, SCIM and mandatory MFA · periodic access reviews · logical segregation · immutable audit logs · penetration testing at least annually · formal supplier management with contracts and safeguards · incident response plan with notification under the DPA.

For an auditor, this describes a serious operational control system — declared by the provider and consistent across the public sources reviewed.

The main observation concerns not controls, but clarity of scope. The verified public certification names API, Enterprise and Edu. Open evidence does not make it equally clear whether ChatGPT Business and the mass-market consumer service fall within the same certified perimeter, although both appear in the enterprise security programme and the declared 42001 AIMS. A corporate customer should not have to browse three pages and two portals to find out which service is covered and which is not.

ISO/IEC 42001 · observable governance, certificate not found

OpenAI declares that it maintains an AI Management System compliant with ISO/IEC 42001:2023 for its consumer and business AI products and models, in its role as producer and provider. There are observable artefacts: the Preparedness Framework defines governance through risk categories, thresholds, a Safety Advisory Group and oversight by the board's safety committee; system cards document pre-deployment evaluation, external red teaming, mitigations and residual risks; DSA reports and the page on the EU AI Act show active transparency mechanisms. Against the requirements for organisational context, risk management, transparency and data governance, the evidence is compatible with components of the 42001 architecture.

The gap concerns external verifiability. No publicly available ISO/IEC 42001 certificate was found with an identified issuing body, number, validity period and certified legal entity at the level of detail available for 27001. The Trust Portal lists 42001 as «compliance», and that label carries less weight than an auditable certificate. The distance between observable governance and verifiable certification is the same as that between asserting that the system exists and demonstrating that an independent third party verified it against the standard.

ISO 9001 · operational elements that do not prove a system

ISO 9001 requires a quality management system with customer focus, planning, operational control, performance monitoring, handling of nonconformities and continual improvement. OpenAI displays elements compatible with service operation: documented support, very detailed release notes, administrative change control, features requiring explicit administrative enablement. Operational elements do not prove a QMS. No public evidence was found of a quality policy, explicit quality objectives, QMS internal audit results, formal CAPA, management review, or satisfaction or correction metrics characteristic of a mature 9001 system. ISO 9001 certification also does not appear among OpenAI's public accreditations or in the Trust Portal reviewed.

The cross-cutting problem: controls without a map

The cross-cutting weakness identified by the audit is the fragmentation of public scope. The controls exist; the map connecting them does not yet. The security page claims 27001 and 27701 for API, Enterprise and Edu; the September 2025 announcement adds 27017, 27018 and SOC 2; the Trust Portal lists 42001 as «compliance»; and the same security page declares an AIMS covering consumer and business products and models. Each source speaks its own language and delineates different services with different degrees of precision. For an auditor, this is a traceability gap that shifts the work of reconstructing the map to the buyer.

The minimum recommendation: a single scope matrix by standard, service, legal entity, region and exclusions, published on a single versioned and updated page. This is the basic standard any certified organisation should meet without its customer having to deduce it.

The Italian episode and what it says about governance

In December 2024, the Italian data protection regulator closed an investigation with a fine of 15 million euros. In March 2026, an Italian court annulled that fine. The judicial outcome reduces the immediate economic impact. The audit lesson remains intact: OpenAI's privacy and transparency governance was questioned sufficiently by a competent authority to generate litigation lasting more than a year. That type of event is a materialised risk, regardless of the final resolution.

Executive assessment table by standard

StandardExecutive assessmentMain condition
ISO/IEC 27001Favourable with scope observationsVerified certification (Schellman, Sept 2025) for API, Enterprise and Edu; consumer service scope not publicly unified
ISO/IEC 42001Favourable with a reservation regarding external verifiabilityDeclared AIMS with documented governance artefacts; public certificate with number and validity period not found as of the cut-off
ISO 9001Not supportable with available public evidenceOperational elements present; certified or publicly demonstrable QMS: not found

What this means for user organisations

For a security or compliance officer who must demonstrate to their own auditor what the provider's technology base covers, the practical result is this: support for 27001 is defensible for API and ChatGPT Enterprise; support for 42001 rests more on the provider's declaration than on an auditable certificate; and any argument requiring ISO 9001 is left without public evidence to sustain it. Organisations integrating OpenAI into critical processes must treat traceability of standards coverage as their own task. The provider does not resolve it for them; as of this review's cut-off, it has not resolved it across its own public-facing sources either.