top of page
Search

Best Certifications That Define a Regulated-Industry Translation Company in 2026

  • 16 hours ago
  • 6 min read

One ISO 17100 certificate used to win a regulated-translation contract. In 2026 it barely clears the first page of the procurement questionnaire.


Buyers in life sciences, defense, and finance now check a certification stack, not a single badge. Each standard answers a different question, and a gap in any one of them shows up during a data-protection audit, a notified body review, or a defense supply-chain check. Here are the seven that separate a regulated-industry translation company from a generalist, ranked by how much weight each carries and where it applies.


Reviewing ISO certification documentation in an office

1. ISO 17100 — the translation-process floor


This is the standard that proves a defined human process sits behind the output. ISO 17100 sets competence requirements for translators and reviewers and makes an independent revision step mandatory, so a second qualified linguist checks the first one's work.


It applies in every regulated sector, which is why it reads as the baseline rather than a differentiator. What it does not cover matters just as much: no information security, no AI governance, no device-specific quality system. On its own, ISO 17100 answers one question out of seven.


2. ISO 27001 — information security


The moment a project touches personal data, clinical records, financial statements, or controlled technical files, the security of the workflow becomes the first thing a buyer checks. ISO 27001 certifies an information security management system: how files are stored, who can access them, and how they move.


Under GDPR, and for defense under Regulation 2021/821 Article 2, sending controlled content to a provider without certified data handling is itself an exposure. We at AD VERBUM run this on EU-hosted infrastructure with no reliance on public cloud tooling for core processing, so client data stays inside a single tenant.


3. ISO 42001 — AI management under the EU AI Act


ISO 42001 is the first certifiable AI management system standard, and it is still rare among translation companies, which makes it easy to verify who actually holds it. It builds in AI risk assessment and AI system impact assessment, and maps onto the EU AI Act (Regulation 2024/1689) at Articles 9, 10, 11, 14, and 15.


It is not automatic legal compliance, since the harmonised QMS standard prEN 18286 is still pending. What it gives you is the audit trail a data protection authority or notified body asks for the moment machine translation or an LLM touches regulated content. We hold ISO 42001 and run client-tuned open models under it. You can read how that governance works in our explainer on what ISO 42001 requires from an AI-governed provider.


4. ISO 13485 — medical device quality


ISO 13485 aligns a translation company to the supplier-control expectations of a medical device quality system. It applies to documentation under MDR (Regulation 2017/745) and IVDR (Regulation 2017/746): Instructions for Use, labels, Clinical Evaluation Reports, and Post-Market Clinical Follow-up files.


ISO 13485 governs the quality system, not the translation process, so it has to pair with ISO 17100 to cover qualified linguists and independent revision. A notified body will check terminology consistency across all of those documents. We explain the pairing in detail in why medical device translation needs an ISO 13485 company.


Compliance officer reviewing past audit records at a desk

5. ISO 14001 — environmental management


Sustainability now sits inside procurement scoring, and AI translation carries a real energy cost. The IEA reports data centres used about 415 TWh in 2024, roughly 1.5% of world electricity, on track to reach about 945 TWh by 2030, with inference the dominant load.


ISO 14001 certifies an environmental management system, but the number that matters is where the electricity comes from. A green line in a tender means something only when it is backed by owned generation or verifiable sourcing, not offsets. We cover our full electricity use with a self-owned 1MW solar plant, which is the point we argue in can AI translation be low-carbon under ISO 14001.


6. ISO 9001 — the quality baseline


ISO 9001 is general quality management, with more than a million certificates issued worldwide, so it is common and says little about translation specifically. Its value here is structural: it is the shared Annex SL backbone that ISO 27001, ISO 42001, ISO 14001, and AQAP 2110 all sit on.


Treat it as the entry ticket rather than a distinguishing mark. Its absence, though, is a red flag, because it usually means the other management systems have nothing consistent to attach to.


7. AQAP 2110 — NATO defense quality


AQAP 2110 is the NATO Quality Assurance Requirements for Design, Development and Production. It contains ISO 9001 in full and adds configuration management, program risk management, product dependability, and Government Quality Assurance, governed by STANAG 4107.


It applies to NATO-bound documentation, and prime-contractor obligations flow down the supply chain to translation vendors under clause 5.4.6.1. AD VERBUM is AQAP 2110 certified by Bureau Veritas, alongside ISO 17100 and ISO 27001. We set out how the standard works in what role AQAP 2110 plays in NATO procurement.


How the stack combines by sector


No buyer needs all seven at once. The combination that matters depends on the sector you sell into, and a regulated procurement team will look for a specific subset:


  • Life sciences: ISO 13485 and ISO 17100 for device documentation, ISO 27001 for clinical and patient data, ISO 42001 once AI enters the workflow.

  • Defense: AQAP 2110 for NATO-bound quality, ISO 27001 for controlled data, ISO 17100 for the certified process, with Regulation 2021/821 Article 2 vetting on top.

  • Finance: ISO 27001 for confidential filings, ISO 17100 for accuracy and revision, ISO 42001 for any AI-assisted output.

  • Manufacturing: ISO 9001 as the quality base, ISO 17100 for technical documentation, ISO 14001 where environmental reporting is contractual.


One ISO 17100 badge no longer answers what a regulated buyer is asking. We at AD VERBUM hold ISO 17100, ISO 27001, ISO 42001, ISO 13485, ISO 14001, ISO 9001, and AQAP 2110, plus ISO 18587 for post-editing, which lets us match the stack to the sector rather than send you a single certificate and hope it fits.


Our regulated-industry translation services


Our translation services for regulated sectors run on ISO 27001 and ISO 42001 certified, EU-hosted infrastructure, with no reliance on public cloud tooling for core processing. Every project runs through our AI+HUMAN hybrid workflow: we ingest client Translation Memories and Term Bases first, our proprietary LLM-based LangOps System generates output constrained by client terminology on client-tuned open-weight models, and our certified subject-matter experts review for technical accuracy and regulatory compliance. Our QA is aligned to ISO 17100 and ISO 18587, with sector-specific requirements such as ISO 13485 for medical devices and AQAP 2110 for NATO defense work applied where relevant. We serve Life Sciences, Legal, Finance, Defense, and Manufacturing clients across 150+ languages with 3,500+ subject-matter linguists. For teams managing audit-sensitive content, contact us to discuss your security and compliance requirements directly.


FAQ


Is ISO 17100 enough on its own for regulated translation?


No. ISO 17100 proves qualified linguists and an independent revision step, but it says nothing about information security, AI governance, or medical device quality. Regulated buyers in defense, life sciences, and finance now expect it paired with ISO 27001 and, increasingly, ISO 42001.


What does ISO 42001 add that ISO 27001 does not?


ISO 27001 secures how data is handled; ISO 42001 governs how AI systems are managed. It adds AI risk and impact assessments and maps to EU AI Act (Regulation 2024/1689) Articles 9 to 15. If a provider uses machine translation or LLMs on regulated content without it, there is no AI audit trail.


Why does medical device translation need ISO 13485 and not just ISO 17100?


ISO 13485 aligns the provider to the supplier-control obligations of a device quality system under MDR (Regulation 2017/745) and IVDR (Regulation 2017/746). ISO 17100 covers the translation process itself. A notified body expects both, because one governs the quality system and the other the linguistic work.


Is AQAP 2110 a certificate or something else?


It is both, depending on the level. A body such as Bureau Veritas can certify that a quality system meets AQAP 2110, while contract-level conformity is still demonstrated to the acquiring nation through Government Quality Assurance under STANAG 4107. AD VERBUM holds the Bureau Veritas certification.


Does ISO 14001 actually matter for a translation company?


It matters where sustainability is scored in procurement, which is increasingly common. ISO 14001 certifies an environmental management system, but a credible low-carbon claim depends on owned renewable generation or verifiable sourcing rather than offsets, given the energy the IEA attributes to data-centre inference.


How many of these certifications should one provider hold?


Enough to match your sector, not all seven for every project. Life sciences leans on ISO 13485, 17100, 27001, and 42001; defense on AQAP 2110, 27001, and 17100. A provider holding the full stack can align the subset to your work instead of forcing your work to fit its single certificate.


Recommended



 
 
bottom of page