About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

Theta Lake Touts First-of-its-Kind ISO Certification for AI Comms Data Trust

Subscribe to our newsletter

Data security specialist Theta Lake has been awarded trust certification for its artificial intelligence-powered compliance communications services.

The designation was conferred as the company prepares to release a report that shows IT teams in financial services and other industries are facing challenges with their AI governance and security.

Santa Barbara, California-based Theta Lake achieved ISO 42001 AI Management System Certification for its Digital Communications Governance and Archiving (DCGA) platform. The company said the award makes it the first AI-native vendor in the DCGA space to provide detailed transparency and explainability around its AI models.

“Financial services AI, compliance, security and risk teams evaluating AI technologies should view the ISO 42001 certification as a gold standard indicative of independent, third-party validation of the rigour applied to the development, maintenance and security of AI systems,” Theta Lake general counsel and vice president of compliance Marc Gilman told Data Management Insight.

Data Monitoring

Financial institutions are increasingly using AI in their internal communications systems, not only to monitor employees’ behaviour for security issues but also to derive sales and trade leads from interactions with clients. That has put pressure on vendors to provide guardrails to ensure the AI it uses and the data it generates is utilised responsibly within terms of regulations such as the EU’s AI Act.

Theta Lake said, however, that not all providers of AI communications technology offer detailed visibility into their systems’ documentation, procedures and tools. The company added that its new ISO certification makes it the only such vendor that can provide trust in its AI capabilities.

“From an AI provider perspective, ISO 42001 provides a set of industry-aligned baseline competencies for the internal processes and procedures used to develop and deploy AI products and services,” Gilman said. “Additionally, it supports compliance with emerging regulatory frameworks such as the EU AI Act and existing mandates such as those under the Federal Reserve’s SR 11-7 Guidance on Model Risk Management.

“The ISO 42001 certification cuts to the heart of these challenges as it is designed specifically for entities providing or using AI-enabled products or services to ensure responsible innovation.”

Data Challenge

In its survey more than 500 IT and compliance professionals, the detailed results of which will be published this month, the company found that 88 per cent of respondents cited AI governance and data security as a core challenge. The scope of that is magnified by the findings that all but a small handful said they plan to implement or expand the use of AI features in their unified communications and collaboration (UCC) tools. Nine in 10 of those said the technology they’re most likely to deploy would be generative AI (GenAI).

Theta Lake warned that GenAI is “exactly the type of applications where jailbreaking may occur”, referring to the act of circumventing regulations around the technology’s use.

“This type of behaviour risk is new, and presents a huge risk to organisations as they look to… maximise productivity,” the company said in a statement.

Theta Lake said its own DCGA product had been updated with better capabilities to detect jailbreak attempts and have provided the ability to hare detailed insights from AI communications with detailed metadata via new observability and security information and event management (SIEM) API endpoints.

The new endpoints ensure customers can maximise the value and intelligence of the data they derive from their communications stack, the company said.

Positive Signal

Gilman said that use ISO 42001-accredited services sends a signal that a company is serious about protecting its data.

“Overall, given regulatory scrutiny around the adoption and use of AI in financial services, the ISO 42001 certification is meaningful and demonstrable evidence of an organisation’s maturity and sophistication in managing these complex technologies,” he said.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Best approaches for trade and transaction reporting

Compliance practitioners and technology leaders in capital markets face mounting pressure to ensure that reporting processes are efficient, accurate, and aligned with global standards. Market developments and jurisdictional nuances in regulatory frameworks like MiFID II, EMIR, SFTR and MAS create a continual challenge for compliance teams. This webinar brings together senior RegTech executives and seasoned...

BLOG

UK Equity Consolidated Tape and EU MiFIR – Two Data Regimes, One Control Problem

The UK’s proposed equity consolidated tape is framed as a response to long-standing fragmentation in equity market data. By aggregating post-trade information and an attributed best bid and offer across trading venues, the tape is intended to provide a single, standardised view of UK equity trading. At the same time, transaction reporting under the Markets...

EVENT

ExchangeTech Summit London

A-Team Group, organisers of the TradingTech Summits, are pleased to announce the inaugural ExchangeTech Summit London on May 14th 2026. This dedicated forum brings together operators of exchanges, alternative execution venues and digital asset platforms with the ecosystem of vendors driving the future of matching engines, surveillance and market access.

GUIDE

The DORA Implementation Playbook: A Practitioner’s Guide to Demonstrating Resilience Beyond the Deadline

The Digital Operational Resilience Act (DORA) has fundamentally reshaped the European Union’s financial regulatory landscape, with its full application beginning on January 17, 2025. This regulation goes beyond traditional risk management, explicitly acknowledging that digital incidents can threaten the stability of the entire financial system. As the deadline has passed, the focus is now shifting...