Trust You Can Verify: Figma Is Now ISO 42001 Certified | Figma Blog (opens in new tab)
Figma has achieved ISO/IEC 42001:2023 certification, making its AI governance independently verifiable rather than based solely on company assurances. An ANAB-accredited certification body, Schellman, audited Figma’s policies, risk management, data practices, and AI development processes. The certification is intended to give customers—especially regulated organizations—stronger evidence for vendor assessments, regulatory reviews, and board reporting.
Why Independent Verification Matters
- Vendors can describe their AI controls through questionnaires, whitepapers, and documentation, but those materials remain self-reported.
- ISO 42001 requires an accredited third party to evaluate whether an organization’s AI management system meets an international standard.
- Figma says this provides more reliable evidence than simply claiming to practice responsible AI governance.
Scope of Figma’s Certification
- The certification covers the AI Management System governing how Figma designs, develops, and operates AI features.
- It applies across:
- Figma Design
- Figma Make
- FigJam
- Dev Mode
- Figma Sites
- Figma Slides
- Figma Draw
- Figma Buzz
- Figma Weave
What the Audit Evaluated
- The audit took place in two stages:
- Stage 1: Reviewed the design of Figma’s AI Management System, including documentation, policies, and risk methodology.
- Stage 2: Tested operational effectiveness through staff interviews, process observation, and control evaluations.
- Auditors assessed 38 controls across nine areas:
- AI impact assessment
- Governance and accountability
- AI-specific risk management
- AI system lifecycle management
- Data governance
- Third-party AI risk
- Monitoring and performance evaluation
- Human oversight
- Responsible use of AI systems
- Figma emphasizes that the certification validates implementation, not merely the existence of written policies.
Relevance for Customers
- The certification gives customers evidence they can reference in:
- Vendor risk assessments
- Board reporting
- Regulatory submissions
- AI procurement processes
- It is particularly relevant to financial services, healthcare, insurance, and public-sector organizations with strict security, privacy, and regulatory requirements.
- Figma connects the certification to the EU AI Act and emerging procurement standards, which increasingly require demonstrable governance rather than vendor promises.
Ongoing Commitment
- Figma plans to continue submitting its AI governance practices to independent verification as its AI capabilities evolve.
- Its certificate and broader compliance documentation are available through
compliance.figma.com. - The certificate can also be verified through Schellman’s directory, and Figma says it will update its documentation when governance changes affect customer risk assessments.
ISO 42001 certification represents a baseline for Figma’s ongoing AI governance efforts, giving customers independently audited evidence they can use when evaluating the company’s AI products.