Workday Secures Independent Verifications of Its Approach to Responsible AI

We’re not only building AI that serves our customers needs, but we’re doing so responsibly. We understand that a high quality responsible AI governance framework facilitates AI innovation and adoption because it helps drive trust.

Kelly Trindel June 12, 2025
Man and woman looking at computer

At Workday, we’re not only building AI that serves our customers needs, but we’re doing so responsibly and in a way that inspires trust. We understand that a quality Responsible AI governance framework facilitates AI innovation and adoption because it helps drive trust in our products, which our customers have come to expect and identify with our brand.

Today we’re proud to announce that it’s not only Workday who sees it that way. Our Responsible AI governance practices have now been rigorously vetted and validated against external standards and frameworks by independent parties who agree that Workday is a leader in responsible AI governance.

Recognizing the complexities of AI, we proactively partnered with Coalfire, a cybersecurity leader, to evaluate our AI processes against the NIST AI Risk Management Frameworkand with Schellman to certify our program to ISO 42001 standardsThese independent evaluations validate our commitment to the highest standards of responsible AI, including fairness testing and controls for AI security and privacy. 

 

Why NIST AI RMF and ISO 42001 Are Important

Establishing trust in our approach to AI is a top priority for Workday, and we value the high water mark that these best practice frameworks and standards introduce. 

These independent evaluations validate our commitment to the highest standards of responsible AI, including fairness testing and controls for AI security and privacy.

The NIST AI RMF is a voluntary framework developed by the United States Department of Commerce, whereas ISO 42001 is an internationally recognized credential. We chose to pursue validation against both, because they represent different facets of a leading Responsible AI approach.

Our ISO credential demonstrates our commitment to quality standards for our overall Responsible AI governance program. Our NIST AI RMF attestation validates our leading risk-based approach to AI governance. The concepts of quality and risk of AI systems are not mutually exclusive, in fact they are inherently linked. Our effort at Workday is to maintain, and continuously improve upon, an RAI governance program that is robust and industry-leading. As such, we choose to hold ourselves accountable to the highest and most comprehensive standards available today.

What Are NIST AI RMF and ISO 42001?

The US-based National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF) is a voluntary risk management framework directed by Congress that provides a how-to guide for organizations of all sizes, industries, and geographies to develop and deploy trustworthy AI. The NIST AI RMF was developed through a multi-stakeholder process in collaboration with civil society, academia, and industry. Workday was an early champion of its creation, providing technical expertise throughout its development, and was featured as NIST’s first-ever case study highlighting industry adoption of the framework. 

The Swiss-headquartered International Organization for Standardization (ISO) is a leading global standards development organization that provides foundational technical standards underpinning widely-adopted privacy and cybersecurity certifications. Over the past decade, Workday has demonstrated our commitment to leadership in these areas by obtaining multiple ISO certifications, including ISO 27001, ISO 27017, and ISO 27018. ISO 42001 is a technical standard that “specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations,” designed for entities that both develop and deploy AI products and services. Like other voluntary consensus technical standards, ISO 42001 was developed in collaboration with stakeholders from across industry, civil society, academia, and government, and reflects a widely-agreed upon approach for AI risk management. 

NIST and the ISO are leading organizations, widely respected for technical standards and measurement science. Workday is proud to demonstrate our alignment to each as it relates to our Responsible AI program. NIST has developed a crosswalk between its RMF and the 42001 ISO Standard, which can be accessed and reviewed here. See below for Workday’s condensed version, highlighting areas of overlap and differences.

Building Trustworthy AI

We continue to actively collaborate with leaders in public policy and industry, as well as our customers and partners, to shape the future of responsible AI. Our commitment to frameworks like NIST AI RMF and ISO 42001, and our partnerships with independent assessors like Coalfire and Schellman, demonstrate our dedication to leadership in responsible AI governance.

We will continue to share lessons learned and be as transparent as possible about our approach as we improve and solve problems. We understand that fostering communities of practice and excellence in responsible AI is the way forward, as we continually strive to build AI technologies that amplify human potential and positively impact society.

Kickstart your enterprise AI journey with Workday AI Masterclass.

More Reading