ISO/IEC 42001 Certification: What the Audit Actually Checks
10 min read · updated August 11, 2026
A supplier hands you an ISO/IEC 42001 certificate and the question is what it evidences. The precise answer is narrower than most people assume, and knowing the boundary is what makes the certificate useful rather than decorative.
What the standard is
ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, was published in December 2023 by ISO and IEC. It is a management system standard, built on the harmonised structure shared by ISO/IEC 27001, ISO 9001 and the rest of that family, which is why the clause numbering will look familiar to anyone who has been through a 27001 audit. The catalogue entry is at ISO’s page for ISO/IEC 42001:2023.
Being a management system standard is the whole of the point and the source of nearly every misunderstanding about it. A management system standard specifies requirements for how an organisation governs an activity: how it sets policy, assigns responsibility, identifies risks, plans, operates, measures and improves. It does not specify how the activity must be performed, and it contains no acceptance criterion for an AI system’s behaviour.
The clauses an auditor samples
The auditable requirements are in clauses 4 to 10. Clauses 1 to 3 are scope, references and terms, and are not auditable. What an auditor is looking for in each:
- Clause 4, Context of the organisation. That you have identified the internal and external issues and the interested parties relevant to your AI activity, determined the scope of the management system, and—distinctively for this standard—determined the roles you play, since an organisation can be a developer, a provider and a user of AI at once and the obligations differ.
- Clause 5, Leadership. A published AI policy, top management demonstrably engaged rather than nominally sponsoring, and documented roles, responsibilities and authorities.
- Clause 6, Planning. AI risk assessment and risk treatment, objectives with plans to achieve them, and the two artefacts that carry the most audit weight: the Statement of Applicability, and the AI system impact assessment—an assessment of consequences for individuals, groups and societies, which has no equivalent in ISO/IEC 27001 and is the clause that makes 42001 an AI standard rather than a relabelled security one.
- Clause 7, Support. Resources, competence, awareness, communication, and control of documented information. Competence evidence is a common finding: it is not enough to say the team is skilled.
- Clause 8, Operation. That the planning is actually operated—risk assessments and impact assessments performed at defined points, changes controlled, externally provided processes and suppliers managed.
- Clause 9, Performance evaluation. Monitoring and measurement against something, internal audit, and management review with records.
- Clause 10, Improvement. Nonconformities identified, corrected, and their causes addressed, with records.
Clauses 9 and 10 are where a young management system usually fails, for a structural reason: they require history. An internal audit programme, a management review that has happened, and a nonconformity that was raised and closed cannot be produced on the morning of the audit. An organisation that decides to certify needs the system running for long enough to generate its own records.
Annex A and the Statement of Applicability
Annex A of ISO/IEC 42001 lists controls grouped under objectives covering policies related to AI, internal organisation, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. Annex B provides implementation guidance for each; Annex C lists potential organisational objectives and risk sources; Annex D addresses use of the management system across domains and sectors.
The controls are not a checklist to be completed. Clause 6 requires a Statement of Applicability that records, for every Annex A control, whether it is applicable, why, and—where it is not—the justification for exclusion. That document is the spine of the audit. An auditor reads it first, and then samples: picks controls you declared applicable and asks to see them operating.
The single most common weakness is an exclusion justified by inconvenience rather than by scope. “Not applicable because we do not do that” is fine when you genuinely do not; it is a finding when you do and would rather not evidence it. The data-related controls in particular—provenance, quality, preparation—are the ones organisations most often try to exclude and most often cannot, which is why datasheets and model cards end up doing so much of the evidential work.
How the audit runs
Certification is performed by a certification body, not by ISO, which publishes standards and certifies nobody. The body operates under ISO/IEC 17021-1, the standard for bodies providing audit and certification of management systems, and a scheme-specific standard, ISO/IEC 42006, sets additional requirements for bodies auditing AI management systems including auditor competence and audit duration. The typical cycle:
- Stage 1. A readiness and documentation review. The auditor checks that the management system exists on paper, that the scope is coherent, that the Statement of Applicability is complete, and that you are ready to be audited. Findings here are usually about missing documents.
- Stage 2. The certification audit proper. The auditor samples against the clauses and the applicable controls, interviews people, and tests whether the documented system is the system actually operating. Nonconformities are raised as major or minor; a major nonconformity blocks certification until it is closed.
- Certification. A certificate is issued with a defined scope statement and a validity period, conventionally three years.
- Surveillance audits. Usually annual, sampling parts of the system rather than all of it, with a full recertification audit at the end of the cycle.
Two things about the certificate matter more than the fact of its existence, and a buyer should check both. The first is the scope statement, which names which parts of the organisation and which AI systems are covered. A certificate scoped to one product line says nothing about another. The second is accreditation: whether the certification body is itself accredited by a national accreditation body operating under the international mutual recognition arrangements. An unaccredited certificate is a consultancy opinion in the shape of a certificate.
What the certificate does not say
Stated plainly, because this is the part that gets over-read in procurement:
- It does not say the model is accurate, fair or safe. No part of the audit evaluates model outputs against a performance threshold. It checks that you have a process for deciding what performance is acceptable and for acting when it is not.
- It does not demonstrate legal compliance. A 42001 certificate is not conformity with the EU AI Act, and the harmonised standards being developed for that Regulation are a separate workstream—see the CEN-CENELEC standards work. A well-run management system produces much of the evidence a regulator will ask for, which is a different claim.
- It does not cover systems outside the scope statement. Including, frequently, the model your supplier bought from somebody else.
- It is a point-in-time sample. An auditor sampling a subset of controls over a few days cannot and does not assert that nothing is wrong anywhere.
What it does say is worth having: that an accredited third party examined how this organisation governs AI, found a system that exists and operates, and will come back next year. That is a meaningful signal about organisational maturity and a weak one about any particular model. Related standards divide the ground further—ISO/IEC 23894 gives guidance on AI risk management without being certifiable, discussed in how 23894 and 42001 fit together, and the wider AI standards landscape sets out which body publishes what.