What ISO/IEC 42001 Certification Adds Over a Self-Assessment
9 min read · updated August 11, 2026
ISO/IEC 42001:2023 is a management system standard, published by ISO and IEC in December 2023. You can read it, implement it and say so, or you can pay an accredited certification body to audit you against it. Those two things are sold under the same name and are not the same claim, and the difference matters mostly at the moment somebody else has to rely on it.
Three different things called compliance
When a vendor questionnaire asks whether you are “42001 compliant”, there are three possible honest answers and they are worth a long way apart.
- A gap assessment. Somebody — you, or a consultant — reads clauses 4 to 10 and Annex A, compares them to what you do, and writes down the gaps. This produces the most useful document of the three, because it is the only one that tells you what to fix. It certifies nothing.
- A self-declaration of conformity. You assert, on your own authority, that your AI management system meets the standard. This is a legitimate and long-standing form of conformity claim — first-party attestation is a recognised category — but the evidence for it is entirely yours, and a buyer who does not already trust you has been given no new reason to.
- An accredited certificate. A certification body, itself accredited by a national accreditation body, audits you and issues a certificate naming a defined scope. The claim being made is no longer only yours.
ISO itself does not certify anybody, and says so plainly on its own pages about AI management systems. There is no such thing as an “ISO-issued” certificate; there are certificates issued by bodies operating under accreditation, and there are pieces of paper issued by bodies operating under nothing at all.
The accreditation chain is the whole product
The thing a certificate buys is not the auditor’s opinion. It is the chain behind the auditor’s opinion. A certification body is accredited by a national accreditation body — UKAS in the United Kingdom, ANAB in the United States, RvA in the Netherlands, and their counterparts elsewhere — against requirements for bodies providing management system certification. Those national bodies are in turn signatories to the International Accreditation Forum’s multilateral recognition arrangement, which is the mechanism by which a certificate issued in one country is treated as meaningful in another.
For AI management systems specifically, the accreditation requirements live in ISO/IEC 42006, the standard that tells accreditation bodies what competence and audit duration to demand of a body certifying against 42001. Its arrival is what turned 42001 certification from a self-organised market into an accredited one, and it is the reason certificates issued in the first months after 42001 was published are not all the same animal as those issued later. The current status of 42006 and the rest of the family is on the published catalogue of ISO/IEC JTC 1/SC 42, the subcommittee that writes them.
The practical test when somebody shows you a certificate: find the accreditation body’s mark on it, then look the certificate up in that accreditation body’s public register. An unaccredited certificate is not fraudulent, but it is a second opinion rather than a third-party one, and the register is where the difference becomes visible in about a minute.
What the audit actually does
A management system audit is not a technical assessment of your models. Nobody red-teams your classifier. What happens instead is a two-stage examination of whether the system you have described to yourself is the system you are running.
- Stage 1. Largely documentary. The auditor reads your scope, your AI policy, your risk assessment process, your Statement of Applicability — the document required by clause 6.1.3 that lists every Annex A control and records whether it applies, with the justification — and decides whether you are ready to be audited at all.
- Stage 2. Evidence. The auditor samples: show me the impact assessment for this system, show me the record of who approved this model change, show me the last management review minutes, show me the log that says this control operated.
- Findings and closure. Nonconformities are raised as major or minor. Majors block the certificate until corrected; minors come with a corrective action plan.
- Surveillance and recertification. Certification runs on a three-year cycle with surveillance audits in the intervening years. A certificate is a statement about a system that is being kept alive, which is exactly what a snapshot self-assessment is not.
That last point is the one buyers underrate. The gap assessment tells you where you were on a Tuesday. The certificate says somebody with something to lose came back twelve months later and checked that the management review still happens, that the risk register still moves, and that the controls you said applied are still operating.
Scope is where certificates lose their meaning
Every certificate names a scope, and the scope is the part people skip. A certificate can legitimately cover “the AI management system supporting the development and operation of the X platform at the Amsterdam office” and say nothing whatever about the model you are actually buying. Read the scope statement before you read the standard number. If the system you depend on is not named or clearly included, the certificate is evidence about a different part of the company.
The other frequent misreading is treating an ISO certificate as a regulatory conformity assessment. Under the EU AI Act, the presumption of conformity in Article 40 attaches only to harmonised standards whose references have been published in the Official Journal — and ISO/IEC 42001 is an international standard, not a European harmonised one. Certification against it is useful evidence of a functioning quality and risk process, and it overlaps substantially with the quality management system required of high-risk providers, but it does not discharge that obligation by itself. See the Article 17 quality management system requirement and how harmonised standards for the AI Act are being produced for the distinction in detail.
When a self-assessment is enough
Certification costs real money and real calendar time, and there are cases where it buys nothing you need.
- You are early and the gaps are the point. A gap assessment before you have a management review, an internal audit programme or a populated risk register is not a lesser version of certification — it is the correct first step, and booking a Stage 1 before it is done wastes the audit.
- Nobody is asking. If no customer contract, tender or insurer requires third-party attestation, the certificate is marketing. Useful marketing, sometimes. Still marketing.
- The asking party accepts something else. Many security-led buyers will take a SOC 2 Type 2 report, which is a different instrument with different mechanics — see which SOC 2 trust service criteria an AI vendor has to evidence. Answer the question that was asked rather than the one you have a certificate for.
And the case where a self-assessment is not enough is narrow and easy to recognise: when the reliance is somebody else’s. A public-sector tender that scores third-party certification, a customer whose own auditors will ask how they assured you, a regulator asking for evidence of governance that does not originate with the party being governed. In each of those, the value being purchased is independence, and the only thing that supplies independence is the accreditation chain.
One practical middle path is worth naming, because it is what most organisations that end up certified actually did: run the gap assessment, operate the system for two or three quarters so that there is a year of records to sample, then certify. Certification bodies cannot audit an empty history, and a system with no evidence trail produces majors on exactly the clauses — internal audit, management review, continual improvement — that need elapsed time rather than effort.