Skip to main content

Altus ARGUS Earns ISO 42001 AI Certification: What It Means for CRE Vendor Diligence

By Avi Hacker, J.D. · 2026-10-05

What is ISO 42001 AI certification? ISO/IEC 42001 is the world's first international standard for artificial intelligence management systems, and certification against it means an independent accredited auditor has verified how a company governs the AI it builds and ships, not just what that AI can do. On October 5, 2026, Altus Group (TSX: AIF), the Toronto company behind ARGUS, announced it had achieved ISO/IEC 42001 certification covering its ARGUS Intelligence Platform and its growing suite of AI agents. For CRE buyers, that moves AI governance from a vendor talking point to a checkable credential. For the wider landscape, see our guide to the best AI tools for commercial real estate investors.

Key Takeaways

  • Altus Group announced ISO/IEC 42001 certification on October 5, 2026, covering the ARGUS Intelligence Platform and its growing suite of AI agents.
  • ISO/IEC 42001 certifies how a vendor governs AI risk, transparency, data quality, and lifecycle monitoring. It is not a security certification like SOC 2.
  • ISO does not certify companies. Independent accredited bodies run the audit, which is what separates certification from a self-published responsible AI policy.
  • Altus describes itself as among the early adopters. As of early October 2026, no other major CRE core platform vendor has publicly announced ISO/IEC 42001 certification.
  • Certification covers the management system, not the accuracy of any single AI output, so your own review of AI-extracted NOI and lease terms still matters.

What Altus Actually Certified

Altus certified its AI management system, meaning the policies, risk assessments, and oversight processes that sit around its AI products, across the ARGUS Intelligence Platform and the AI agents the company has been adding to it. The certification complements the ISO/IEC 27001 information security certification Altus already holds.

ARGUS matters here in a way a generic proptech certification would not. ARGUS Enterprise is the default property level cash flow modeling and valuation engine across institutional CRE, used by investors, lenders, and appraisers to build the discounted cash flow models that support valuations. When the vendor that owns that calculation layer starts shipping AI agents into it, the governance question stops being abstract: AI-generated inputs can flow into the NOI, cap rate, and IRR figures that back a real valuation.

Altus chief executive Mike Gordon, who took the CEO role in January 2026, framed it in trust terms, saying that in AI, trust is everything, and noting that customers rely on Altus to inform some of the most consequential real estate decisions they make. Gordon also said the certification was achieved on an accelerated timeline, placing Altus among the early adopters. That is the honest framing: early-mover positioning, not an industry baseline.

One limit is worth stating plainly. ISO/IEC 42001 is a management system standard. It audits whether a company has a working process for identifying and treating AI risk. It does not certify that any particular ARGUS AI agent read a lease escalation or a reimbursement structure correctly. Read it as evidence of discipline, not as a warranty on output.

ISO 42001 vs SOC 2 vs ISO 27001: What Each Credential Tells You

These three get conflated in vendor pitch decks, and they answer different questions. Ask which one a vendor holds and for which scope, because a SOC 2 report tells you nothing about AI-specific risk.

  • SOC 2 Type II: tests whether security, availability, and confidentiality controls actually operated over a period of months. Tells you your data is handled under tested controls. Silent on how models are trained, evaluated, or monitored.
  • ISO/IEC 27001: certifies an information security management system, meaning infosec governance as a discipline. Also silent on AI-specific risk.
  • ISO/IEC 42001: published in December 2023, certifies an AI management system built on a Plan, Do, Check, Act cycle. Covers AI policy and objectives, AI risk and impact assessment, data quality, transparency, lifecycle monitoring, and oversight of third-party AI the vendor itself depends on.

That last item is the underrated one for CRE. Most proptech AI is a wrapper around a frontier model from OpenAI, Anthropic, or Google, so your vendor's AI risk is partly inherited. ISO/IEC 42001 explicitly reaches organizations that manage AI systems provided by third parties, per ISO's own explainer on the standard. ISO is also clear that it does not certify organizations itself: accredited independent certification bodies do, and management system certifications typically run on a three-year cycle with annual surveillance audits.

For context on who else holds it, AWS certified in November 2024 across services including Amazon Bedrock and Amazon Q Business, Anthropic certified in January 2025 for its Claude models, and Microsoft has certified across products including GitHub Copilot and Microsoft 365 Copilot. The infrastructure layer moved first. Altus is the CRE application layer catching up.

Why ISO 42001 Became a CRE Procurement Question in 2026

Two forces converged. The first is regulatory. Tenant screening, property valuation, and underwriting are the exact use cases that emerging AI rules classify as high risk, a wave we tracked in our breakdown of the state AI bills hitting CRE investors. Under the EU AI Act and the state frameworks modeled on it, a documented AI management system is the practical evidence a firm produces when a regulator or counterparty asks how it controls an automated valuation or screening decision. A certified one is far faster to produce than a hastily assembled binder.

The second is that CRE leaders already rank this near the top of their risk list. In JLL's Future of Work research, CRE and C-suite leaders placed cybersecurity and data privacy at 47% and technology and AI disruption at 41% among their top portfolio risks. JLL's own guidance on navigating AI risk in real estate tells occupiers to ask third-party providers directly about how models are trained, whether data can be opted out, and whether the provider complies with frameworks like the EU AI Act. ISO/IEC 42001 answers several of those questions at once.

It also lands against a weak adoption record. Roughly 92% of corporate occupiers have initiated AI programs while only about 5% report achieving most of their AI program goals. Governance is not the whole explanation, but firms that cannot say who owns an AI output tend to be the ones whose pilots never reach production. If you are trying to move an AI program past the pilot stage, The AI Consulting Network works on exactly that gap between tooling and operating discipline.

How to Add ISO 42001 to Your CRE Vendor Diligence Checklist

Add it as one line, not as a gate. Almost no CRE vendor holds the certification yet, so a hard requirement would disqualify most of the market. Use it as a tiebreaker and as a prompt for sharper questions:

  • Ask for the certificate and the scope statement. Scope is where claims get soft. "We are ISO 42001 certified" can cover one product line and not the module you are actually buying.
  • Ask who the certification body was and whether it is accredited. ISO does not issue certificates itself, so an unaccredited attestation is a weaker signal than it sounds.
  • Ask what it does not cover, specifically whether the vendor claims any accuracy guarantee on AI-extracted financial data. Most will not, which is the correct answer.
  • Keep the security questions separate. Our walkthrough on vetting AI tool security before sharing confidential deals covers the training-data and data-residency terms that ISO/IEC 42001 does not resolve for you.
  • Weigh it against the deployment model. For firms that would rather handle governance by keeping models in-house, the tradeoffs are in our analysis of on-prem enterprise AI for CRE investors.

For acquisitions teams, the decisive test still sits downstream of any certificate: run a closed deal through the vendor's AI agent and check the extracted rent roll and reimbursement terms line by line against the source documents. CRE investors who want help building that vendor evaluation process can reach out to Avi Hacker, J.D. at The AI Consulting Network.

Frequently Asked Questions

Q: Does ISO 42001 certification mean an AI tool's outputs are accurate?

A: No. ISO/IEC 42001 certifies the management system around AI, including risk assessment, transparency, and lifecycle monitoring. It does not validate any individual output, so a certified vendor's AI can still misread a lease clause or an operating statement. Human review of AI-extracted NOI and lease terms remains necessary.

Q: Is Altus the first CRE company to get ISO 42001 certified?

A: Altus describes itself as being among the early adopters rather than first. As of early October 2026, no other major CRE core platform vendor has publicly announced ISO/IEC 42001 certification, though the standard is held outside CRE by AWS, Anthropic, and Microsoft.

Q: Should I require ISO 42001 from every AI vendor I buy from?

A: Not in 2026. Adoption is still too thin, and a hard requirement would rule out most useful CRE AI tools. Treat it as a positive differentiator between otherwise comparable vendors, and keep SOC 2 Type II plus explicit contract terms on training data as your baseline.

Q: How is ISO 42001 different from a vendor's responsible AI policy?

A: A responsible AI policy is self-published and self-enforced. ISO/IEC 42001 certification requires an independent accredited body to audit that the policies, risk assessments, and controls actually operate, typically on a three-year cycle with annual surveillance audits.