Guide

Who certifies data for AI?

Updated September 14, 2026 · Maintained by SuperTruth, Inc.

As of 14 September 2026, no single body certifies data for AI. The standards and programs that come closest each certify a different thing. A data license certifies the right to use a dataset. NCQA's Data Aggregator Validation certifies a health data stream so its results count for HEDIS reporting. ISO 8000 certifies how an organization manages data quality and exchanges master data. The Data & Trust Alliance's Data Provenance Standards give a dataset labels for its source, provenance and permitted use. A per-record score, such as SuperTruth's Data Trust Index (DTI), scores one record 0 to 100 and travels with it. The table below sets them side by side by what is certified, who does it, what you receive, and what it says about a single record.

Who certifies data for AI: five programs and standards compared, with what each certifies and what it says about one record
Program or standardWho runs itUnit certifiedWhat you receiveSectorSays anything about one record?Covers provenance / consent / currency
Data licensing (licensors and collective licensing bodies)The rights holder or its licensing bodyA dataset or corpusA license: the right to reproduce, share and adapt, not a statement the data is trueAnyNoRights only; none of the three as measured properties
NCQA Data Aggregator Validation (for HEDIS)NCQAA clinical data stream from an aggregator (for example a health information exchange), output as CCD or FHIR filesValidated status conferred to the data stream; the data counts as standard supplemental data in HEDIS reporting without primary source verification during the HEDIS audit; NCQA lists a next review date per streamUS health plans, health information exchanges and other clinical data aggregatorsNo; the stream is validated, not each recordProvenance: primary source verification checks the output file against the source EHR. Consent: not stated. Currency: not stated
ISO 8000 (data quality series)ISO publishes the standardsAn organization's data quality management processes (ISO 8000-61:2016) and the exchange of master data (ISO 8000-110:2021), including its provenance (ISO 8000-120:2016)not statedAnyNo; process and exchange levelProvenance of exchanged master data: yes (ISO 8000-120). Consent: not stated. Currency: not stated
Data & Trust Alliance Data Provenance StandardsData & Trust Alliance, a group of member companies within the Center for Global Enterprise, a New York nonprofitA dataset, described by metadata the provider supplies22 metadata fields in three groups (Source, Provenance, Use), version 1.0.0, released 9 July 2024; no certificate or third-party audit statedAnyNo; dataset-level metadataProvenance: yes (origin, collection dates and methods). Consent: a field for the location of consent documentation. Currency: a range of dates for data generation
Per-record scoring: Data Trust Index (DTI)SuperTruth, Inc. (patented; methodology published, DOI 10.5281/zenodo.19601616, 2026)One record, at intake and on every useA 0 to 100 score across eight dimensions with a tier, sealed with the record; replayableAny record; published weights calibrated in healthYesProvenance 25 percent, consent 20 percent, recency 15 percent, plus five more (default weights)

Of the five in this table, DTI is the only one that scores a single record. It is a score, not a certification, and no third party accredits it; the methodology is published under a DOI so anyone can check it.

Sources, with the date each was read

What "certify" means here

The word covers five different acts. A license certifies a right: you may use this. A validation certifies a stream's fitness for a report: this feed can count. A process standard certifies how an organization works: these steps were followed. A label certifies a description: here is what the provider says this dataset is. A score certifies a measurement: here is how much this record deserves to be trusted for this use. Each one is useful. None of them is the others, and only the last one is about a single record.

Data licensing

A data license is a grant of rights from the holder of a dataset to a user: the right to reproduce, share and adapt, under conditions. It is the most common form of assurance behind an AI training set, and it says nothing about whether the data is true. The Creative Commons Attribution 4.0 legal code, one widely used public license, grants those rights in section 2 and in section 5 disclaims all warranties, including "accuracy, or the presence or absence of errors" (creativecommons.org, read 14 September 2026). Collective licensing bodies and commercial data vendors write their own terms, and the pattern holds: a license is a permission, not a measurement.

NCQA Data Aggregator Validation

NCQA's Data Aggregator Validation evaluates an organization's management and exchange of clinical data. The unit is a data stream: "the validated status is conferred to the data stream," and any organization that aggregates clinical data and outputs it as CCD or FHIR files is eligible. Three activities make up the validation: a review of process standards (ingestion, coding integrity, quality assurance, governance, security), primary source verification that the output file matches the source EHR, and conformance of the output to the CCD implementation guide. Data from validated streams can be used as standard supplemental data in HEDIS reporting without primary source verification during the HEDIS audit. Validation takes 12 to 18 weeks, cohorts run in January and July, and NCQA lists a next review date for each validated stream. The program pages say nothing about consent or about how current an individual value is; the validation certifies that the stream faithfully carries what the source holds (ncqa.org program page and FAQ, read 14 September 2026).

ISO 8000

ISO 8000 is a series of standards on data quality. Three parts matter here. ISO 8000-61:2016 specifies the processes required for data quality management, used as a reference to assess process capability or organizational maturity. ISO 8000-110:2021 specifies requirements that can be checked by computer for the exchange of master data between organizations and systems, and ISO 8000-120:2016 adds requirements for representing and exchanging the provenance of that master data. The unit is the organization's process and the exchanged master data, not a record in use. ISO publishes the standards; who issues a certificate of conformance and what it says could not be verified on the standard pages, so the table says not stated (iso.org, abstracts read 14 September 2026).

Data & Trust Alliance Data Provenance Standards

The Data & Trust Alliance is a group of member companies (19 on the date read) housed in the Center for Global Enterprise, a New York nonprofit. Its Data Provenance Standards, version 1.0.0, released 9 July 2024, define 22 metadata fields in three groups, Source, Provenance and Use, that a data provider fills in to describe a dataset: who issued it, where and when the data was generated and by what method, and how it may be used, including where consent documentation lives and which privacy-enhancing technologies were applied. The unit is the dataset. The output is a description supplied by the provider; the standards page does not describe a certificate or a third-party audit (dtaalliance.org, read 14 September 2026).

Per-record scoring: the Data Trust Index

The Data Trust Index scores one record, 0 to 100, across eight weighted dimensions (Provenance 25 percent, Consent 20 percent, Recency 15 percent, Quality 10 percent, Concordance 10 percent, Validation 10 percent, Breadth 5 percent, Stability 5 percent under the default weights), maps the score to a tier, and seals it with the record so it can be replayed. It is a score, not a certification, and no third party accredits it; the methodology is published under a DOI so anyone can check it (DTI white paper, DOI 10.5281/zenodo.19601616, 2026). It is patented by SuperTruth, Inc. DTI scores any record; the published weights were calibrated in health. If a reader asks how a health-calibrated method applies to other data, that sentence is the answer: the dimensions apply to any record, the default weights were set in health, and the weights are configurable per engagement. The full article is Data Trust Index; the engine is the DTI Engine.

What none of them does

None of the five says whether one record is fit for one use. A license says you may use the dataset. A validated stream says the feed carries what the source holds. A process standard says the organization follows its procedures. A label says what the provider declares. Each stops at the boundary of the record. The question a model or a clinician actually faces is narrower and harder: should I act on this record, now, for this purpose? That is the question the comparison page puts beside data quality tools, and the question a per-record score exists to answer.

Where a per-record score fits alongside them

A per-record score is not a rival to the four programs above; it runs after them. Beside NCQA validation: the stream is valid, and the score says which records inside it are current and consented for the use at hand. Beside Data & Trust Alliance labels: the dataset is described, and the score says which rows agree with independent sources. Beside ISO 8000: the process conforms, and each record still needs a number. Beside a license: you may use it, and the score says whether you should. The guide How to verify a record before AI training walks the ten checks. The place beside the record is DataSpine, a sourced dataset with the source and vintage on every value; the agent acting on the record is scored by VIGIL.

How we checked

We searched the web on 14 September 2026 for a body that certifies data for AI at the level of the individual record and found none. The closest program we found is Fairly Trained, which certifies a company, a product or a model for training on licensed data; its FAQ says an applicant can seek "certification for an entire company, a single product or service, or an individual model," and it does not examine individual records (fairlytrained.org/faqs, read 14 September 2026). If we missed one, tell us and we will add the row.

Names and affiliation

NCQA, HEDIS, ISO, the Data & Trust Alliance, Creative Commons and Fairly Trained are named so you can compare. We are not affiliated with them and they have not endorsed us. Their names are trademarks of their owners.