Regfyl Achieves ISO/IEC 42001:2023 Certification for Artificial Intelligence Management

Regfyl has achieved ISO/IEC 42001:2023 certification, strengthening our approach to responsible AI governance and supporting financial institutions navigating the CBN Baseline Standards.

Regfyl Achieves ISO/IEC 42001:2023 Certification for Artificial Intelligence Management

Regfyl Achieves ISO/IEC 42001:2023 Certification for Artificial Intelligence Management

Regfyl has achieved ISO/IEC 42001:2023 certification for its Artificial Intelligence Management System (AIMS), marking an important milestone in our continued investment in the responsible development and governance of AI-enabled compliance technology.

ISO/IEC 42001 is the international standard for Artificial Intelligence Management Systems. It establishes requirements for organisations to develop, implement, maintain and continually improve a structured management system around the responsible development and use of artificial intelligence.

Regfyl’s certification covers the design, development, maintenance, technical support, operations, sales and marketing of our AI-enabled compliance platform across AML compliance, fraud prevention, data protection, due diligence, audit readiness and compliance training.

Why ISO/IEC 42001 matters for financial institutions

Artificial intelligence (AI) is becoming increasingly embedded in financial crime compliance. AI can help institutions improve customer risk assessment, identify suspicious patterns, support investigations, reduce false positives and make compliance teams more efficient. But greater use of AI also creates important questions around governance, accountability, risk management, transparency, oversight and ongoing validation.

ISO/IEC 42001 provides organisations with a structured framework for managing those risks and opportunities. Rather than focusing only on what an AI system can do, the standard addresses how AI should be governed throughout its lifecycle. ISO describes the standard as a framework for managing AI-related risks and opportunities while supporting responsible use, transparency, traceability and reliability.

For Regfyl, achieving certification therefore represents more than a technology milestone. It reflects the governance framework within which we develop, operate and continuously improve the AI-enabled capabilities used across our products.

Supporting alignment with the CBN Baseline Standards

The certification is also particularly relevant to financial institutions in Nigeria following the introduction of the Central Bank of Nigeria’s Baseline Standards for Automated AML/CFT/CPF Solutions.

Issued in March 2026, the Baseline Standards establish minimum functional, governance and control requirements for automated AML/CFT/CPF solutions used by regulated financial institutions. The CBN states that the standards are intended to strengthen real-time detection and reporting of suspicious activity while supporting the appropriate use of emerging technologies in financial crime risk management.

Importantly, Section 6(d) of the Baseline Standards requires financial institutions to adhere to ISO 42001 and/or other applicable standards in the usage and governance of Artificial Intelligence, where relevant to the Standards.

The same section also places significant emphasis on third-party technology governance. Financial institutions are required to maintain appropriate vendor and third-party management arrangements, ensure third-party providers comply with applicable provisions of the Baseline Standards, and apply heightened due diligence to providers of AML solutions.

For institutions procuring AI-enabled AML technology, this makes the governance framework of the technology provider increasingly important.

What this means for Regfyl customers

Our ISO/IEC 42001 certification gives customers and prospective customers an additional level of assurance around the way AI is governed within Regfyl.

It demonstrates that the management system behind our AI-enabled platform has been assessed against an internationally recognised AI management standard and provides further support to customers carrying out vendor due diligence or assessing their technology environment against the CBN Baseline Standards.

The certification does not, by itself, make a financial institution compliant with ISO/IEC 42001 or the CBN Baseline Standards. Each institution remains responsible for its own governance framework, implementation, configuration and use of AI and AML technology.

However, we believe financial institutions should be able to expect their technology providers to demonstrate the same seriousness about governance, accountability and risk management that regulators increasingly expect from the institutions themselves.

As a compliance technology provider, our responsibility is therefore not limited to helping customers meet functional requirements. It also means continuing to invest in the governance, controls and assurance surrounding the technology we provide.

Building responsible AI into compliance technology

AI will continue to play a larger role in financial crime prevention and regulatory compliance. Used appropriately, it has the potential to help compliance teams analyse more information, identify risks earlier and focus human expertise where it adds the greatest value.

But innovation and governance cannot be separated.

As we continue to develop Regfyl’s AI-enabled capabilities, ISO/IEC 42001 provides an important framework for ensuring that the systems, processes and controls surrounding that development evolve alongside the technology.

Achieving this certification is another step in that journey and part of our broader commitment to building compliance technology that financial institutions can confidently rely on.

Learn more about Regfyl and the CBN Baseline Standards here.

Tags: #ISO 42001 #Artificial Intelligence #Responsible AI #AI Governance #CBN Baseline Standards #AML Compliance #RegTech #Financial Crime Compliance #Compliance Technology #Nigeria #Risk Management #Regfyl
← Back to Insights