Figma’s ISO 42001 Certification: What Was Audited and Why It Matters

Figma has achieved certification under ISO/IEC 42001:2023, the international standard for AI management systems published in December 2023. The certification covers the Artificial Intelligence Management System (AIMS) governing how Figma designs, develops, and operates AI features across its platform, including Figma Design, Figma Make, FigJam, Dev Mode, Figma Sites, Figma Slides, Figma Draw, Figma Buzz, and Figma Weave.

The certification was issued by Schellman, an ANAB-accredited independent certification body, and joins Figma's existing ISO/IEC 27001 and SOC 2 Type II certifications.

Why third-party verification matters

Security teams evaluating AI vendors face a common problem: every vendor's documentation looks the same regardless of whether the underlying governance is real. Vendor risk assessments, board questions about AI, and decisions about enabling AI-assisted features all demand more than a company's account of its own controls.

An AIMS is the operational backbone of AI governance—the policies, processes, and controls that govern how AI is built, deployed, and monitored. ISO 42001 provides a framework for what responsible AI governance requires and subjects it to independent verification. The certification is designed for AI's equivalent role to what ISO 27001 plays for information security.

Prior to certification, Figma's AI governance practices were documented in whitepapers and questionnaire responses, requiring customers to trust the company's account of its own controls. Now, an accredited third party has examined those governance policies, data practices, risk processes, and technical safeguards against an international standard.

The audit scope and process

Accreditation of the certification body itself was a prerequisite, distinguishing this certification from unaccredited alternatives. An ANAB-accredited body must undergo a formal audit before it can issue conformant certificates.

The audit ran in two stages. Stage 1 assessed the design of Figma's AIMS, covering documentation, policies, and risk methodology. Stage 2 tested operational effectiveness, with auditors interviewing staff, observing processes, and evaluating 38 controls organized into nine Annex A control objectives:

  • AI impact assessment
  • Governance and accountability
  • AI-specific risk management
  • AI system lifecycle management
  • Data governance
  • Third-party AI risk
  • Monitoring and performance evaluation
  • Human oversight
  • Responsible use of AI systems

Implications for customers

Figma operates on both sides of vendor risk assessments: it builds programs to answer security questionnaires while running vendor risk programs to evaluate its own suppliers. The certification offers customers an alternative to parsing questionnaire responses—a recognized international standard, verified by an accredited body, that can be cited in vendor risk assessments, board reporting, and regulatory submissions.

This carries particular weight under the EU AI Act and emerging AI procurement standards, which require proof rather than promises. For organizations in regulated industries—financial services, healthcare, insurance, and the public sector—vendor risk programs are themselves subject to audit. An externally verified AI governance posture represents a distinct class of evidence compared to a vendor's self-assessment.

Ongoing commitment

Figma intends to continue submitting its AI governance to third-party verification as AI capabilities expand. The ISO 42001 certificate and full security and compliance documentation are available at compliance.figma.com and verifiable through Schellman's certificate directory. The company has committed to keeping that documentation current throughout the vendor relationship and to disclosing governance changes that could affect customer risk assessments.