Supplier questionnaires have gained a line this year: are you certified to ISO/IEC 42001, and if not, when? The standard behind the question is 51 pages long. This guide goes through what those pages ask an organisation to do, in business terms, and what the certificate does and does not prove.
We covered the broader picture in the rulebooks arriving around AI. This article takes the standard on its own, working from the part ISO publishes for free (foreword, scope, definitions and clause 4), the structure ISO shares across its management-system standards, accredited certification bodies and their auditors, and the announcements of organisations that have certified.
What does the standard certify?
ISO/IEC 42001:2023, published in December 2023, sets requirements for an AI management system. A management system is the set of policies, roles, processes and records through which an organisation runs something deliberately rather than by habit. ISO 9001 does this for quality and ISO 27001 for information security. ISO 42001 does it for the development, provision and use of AI.
The certificate therefore says something specific: an accredited auditor found that the organisation has defined which AI it governs, assessed its risks and impact, chosen controls, kept records, checked itself and corrected what it found. It does not say that any model is accurate or fair, or that the organisation complies with the EU AI Act, and it says nothing about AI outside the scope the organisation wrote down.
ISO 42001 is intended to cover the delta: the risks that are unique to AI. So think bias, transparency, responsible use, ethics and safety. Danny Manimbo, Schellman · ISO 42001 certification FAQ, February 2025
The standard names three roles, producer, provider and user, and one organisation can hold more than one: a company that runs agents on a bought platform is a user of the platform and may be a provider of the agent. The roles shape the scope, and the scope decides what the audit covers.
The certificate covers a scope, not a company
AWS’s certificate names four services. Microsoft’s names nine Copilot and Foundry products. IBM’s covers one model family. When a supplier says it is certified, ask: for which systems, and is the one we are buying inside that scope?
What is the shape of the standard?
Pages 1 to 16 hold the scope, 26 definitions and the requirement clauses 4 to 10. Annex A, four pages, lists 38 controls under nine objectives. Annex B, 25 pages and normative, gives implementation guidance per control. Annexes C and D are informative.
Clauses 4 to 10 use what ISO calls the harmonised structure: identical clause numbers, titles and core text across all its management-system standards, so anyone who has run ISO 27001 will recognise nearly all of it. What is new for AI sits in a handful of sub-clauses, marked in the figure, and in the annexes. The full text costs CHF 225 from ISO or about EUR 250 excluding VAT from NEN, English only; the free preview stops at the end of clause 4.
What do clauses 4 to 10 require?
The table puts each clause in ordinary terms, with the records an auditor will look for. The right-hand column matters more than the middle one: a folder of policies with no records behind it fails the audit.
| Clause | What it asks | What you need to be able to show |
|---|---|---|
| 4 Context | Work out what affects your use of AI (your role, legal and ethical factors, who has a stake) and decide which AI systems the management system covers | A written scope. A list of interested parties and what they expect. Clause 4.1 also asks whether climate change is a relevant issue |
| 5 Leadership | Top management commits, issues an AI policy and assigns responsibilities | An AI policy approved at the top. Named owners for AI risk, impact assessment and the system as a whole |
| 6 Planning | Define how you will assess AI risk, treat it and assess the impact on people. Set measurable AI objectives | A risk assessment method with criteria set in advance. A risk treatment plan and a Statement of Applicability. An impact assessment process. Objectives with owners |
| 7 Support | Provide resources and competent people, make staff aware, communicate, and control your documents | Evidence of competence. Versioned, controlled documents |
| 8 Operation | Run the processes. Carry out the assessments at planned intervals and when something significant changes | The results of each assessment. Evidence that processes ran as planned and that changes were reviewed |
| 9 Evaluation | Monitor and measure, audit yourself, and have management review the results | Monitoring results. An internal audit programme and its findings. Management review records |
| 10 Improvement | Fix nonconformities, address their causes, and keep improving the system | A record of each nonconformity, the corrective action and whether it worked |
This is where you need objective evidence that your AI management system is working and it’s not just intentions. Ali Moshayedi, ISO 42001 auditor, BSI · on clause 9, BSI webinar, March 2026
What is specific to AI?
Three processes, defined in clause 6 and carried out in clause 8.
AI risk assessment (6.1.2, 8.2). Identify what the organisation’s AI systems could do to its own objectives, using criteria fixed in advance. Annex C offers a menu of risk sources.
AI risk treatment (6.1.3, 8.3). Decide which controls address those risks and record the decision in a Statement of Applicability: “documentation of all necessary controls and justification for inclusion or exclusion of controls”. It is the first thing an auditor reads.
AI system impact assessment (6.1.4, 8.4). Assess the consequences of developing, providing or using an AI system for individuals, groups and society. A risk assessment looks inward, at the organisation. An impact assessment looks outward, at the people the system touches.
The nine control objectives
Annex A groups its 38 controls under nine objectives. You select the ones your risk treatment needs, may add your own, and justify every inclusion and exclusion in the Statement of Applicability.
| Objective | Controls | What it covers, in plain terms |
|---|---|---|
| A.2 Policies for AI | 3 | An AI policy, aligned with your other policies, reviewed on a schedule |
| A.3 Internal organisation | 2 | Who is responsible for what, and how staff raise concerns about AI |
| A.4 Resources | 5 | Documenting the data, tools, computing and people each AI system depends on |
| A.5 Impact assessment | 4 | A process for assessing impact on individuals, groups and society, and records of having done it |
| A.6 Life cycle | 9 | Responsible design, verification and validation, deployment, operation and monitoring, documentation, event logs |
| A.7 Data | 5 | Where data comes from, its quality, its provenance, and how it is prepared |
| A.8 Information for interested parties | 4 | What users are told, external reporting, communicating incidents |
| A.9 Use of AI | 3 | Processes for responsible use, and a defined intended use for each system |
| A.10 Third parties and customers | 3 | Allocating responsibility across the supply chain, managing suppliers, duties to customers |
Five of the nine are new territory compared with an information-security standard: A.5 to A.9, on impact, life cycle, data, information and use. That is where the work goes.
What does certification involve?
Certification comes from a certification body that is itself accredited for ISO 42001 under ISO/IEC 42006:2025. In the Netherlands the RvA accredited BSI and DNV in January 2025 and TÜV NORD in February 2026. Some early certificates were issued under other schemes, so the accreditation mark on a certificate is worth checking.
The audit follows the ISO 27001 pattern: a Stage 1 documentation review in one or two days, a Stage 2 test of whether the system operates over one to three weeks, then a three-year certificate with annual surveillance. Those durations are Schellman’s published experience; the same firm quotes year-one audit fees from the low to the mid tens of thousands of US dollars. Stage 2 looks for records, so the system has to have run before the audit; implementers quote six to twelve months from a standing start, three to six where an ISO 27001 system exists. Treat all of these as one body’s or one trade’s figures. The larger cost is internal: the inventory, the assessments and the records.
If your scope is not 100% clear, your governance and your audit will fail. Fran Caballero, ISO 42001 auditor, BSI · BSI webinar with Darktrace, May 2026
Caballero names three failures BSI sees: scope that does not say where the AI starts and ends; metrics borrowed from ordinary IT that say nothing about drift, fairness or data accuracy; and policies downloaded to pass an audit. Before any of that comes the inventory: an auditor’s first request is a list of the AI systems in scope with their intended use.
How have the first certified organisations done it?
| Organisation | Certified | Scope | What stands out |
|---|---|---|---|
| AWS | Nov 2024, Schellman | Bedrock, Q Business, Textract, Transcribe | Governance organised along the seven AI life-cycle stages of ISO/IEC 22989. First surveillance audit, Nov 2025, no findings |
| Anthropic | Jan 2025, Schellman | AI products and services, including the Claude models | Links the management system to its Responsible Scaling Policy |
| Microsoft | Mar 2025, recertified May 2026 | Nine named Copilot and Foundry products | A risk-tiered review so senior oversight goes to higher-impact systems. Scope grew from two to three systems in year two |
| Darktrace | Jul 2025, BSI | Its AI-driven security products | Built on an existing ISO 27001 and 27018 system. Every AI change now passes an impact assessment before production |
| Metyis, Amsterdam | Jul 2025, DNV | Its AI management system | First ISO 42001 certificate issued in the Netherlands, under RvA accreditation |
Google Cloud, Workday, Snowflake, Salesforce, SAP, IBM (for its Granite models), KPMG in the US and BCG have also announced certificates; BCG counted itself in January 2026 among the first 100 organisations worldwide. As far as we could establish, no Dutch bank, insurer or public body had announced one by September 2026.
When we change an AI system, what happens is now it goes through AI impact assessments covering data quality, bias, risk and customer impact before it’s actually deployed into production. Darktrace compliance team · BSI webinar, May 2026
Three patterns run through these accounts. The scope is narrow and named. The system is built on existing ISO 27001 machinery, with the AI assessments and the five new control areas added; Darktrace’s team said it “didn’t build ISO 42001 from scratch”. And the visible operational change is a gate: an impact assessment before an AI system, or a change to one, reaches production.
The commercial effect is already visible. Microsoft’s supplier programme, SSPA, requires ISO 42001 certification for suppliers whose AI use it classes as sensitive or high-risk, according to Schellman. For a vendor, the cost of not having the certificate, or a dated plan for one, is a longer questionnaire now and exclusion from some work later. For a buyer, asking for it is the cheapest check that a supplier keeps an inventory, assesses impact and monitors after release.
How does it sit next to the EU AI Act?
ISO 42001 is not a harmonised standard under the AI Act, and certification gives no presumption of conformity. CEN-CENELEC JTC 21 wrote its own quality-management standard for Article 17, EN 18286, approved in July 2026, because Article 17 attaches to each high-risk system as a product while 42001 governs an organisation. As of September 2026 no AI Act harmonised standard has been cited in the Official Journal. 42001 was adopted as a European standard in 2026; adoption is not harmonisation.
| EU AI Act | ISO/IEC 42001 | |
|---|---|---|
| What it is | Law, in force in stages from 2025 to 2028 | A voluntary standard you can be certified against |
| Who it binds | Providers and deployers, by role and by risk tier | Whoever chooses it, within the scope they define |
| The unit | Each AI system, classified by its intended purpose | The organisation’s management system |
| What it proves | That the obligations for that system were met | That an accredited auditor found a working management system |
| Where they overlap | Risk management, data governance, documentation and logging, human oversight, monitoring after release, supplier management, communicating incidents | |
| What 42001 does not cover | Conformity assessment, CE marking and the declaration of conformity; registration in the EU database; the Article 27 fundamental rights impact assessment; Article 73 incident-reporting deadlines; the Annex IV technical file per system | |
It doesn’t mean that you’re automatically compliant, but it does mean it’s your first rung on the ladder. It’s your first step into compliance. Will Booth, Director of Cybersecurity Compliance, Darktrace · on the AI Act, BSI webinar, May 2026
The practical arrangement, for an organisation that faces both, is one management system and one file per AI system. The management system carries the policy, the assessments, the audits and the reviews; the per-system file carries what the Act asks for that system, which we set out in what the AI Act asks of a deployer.
Where does Aitonomy fit?
Most of what clauses 8 and 9 and the life-cycle controls ask for is operating evidence: what each AI system is for, who oversees it, what it did, what was checked and what changed. For an agent workforce, that is the record Aitonomy Control keeps.
What Control holds for an auditor
Per agent role · six kinds of evidence
- Intended use and scope.Each agent has a defined job, a named human owner and explicit limits on what it may do. The Scan produces the inventory of the work and systems involved before anything runs. (A.9.4; clause 4.3.)
- Human oversight.Every capability runs at a supervision level, Suggests, Drafts or Auto, promoted on evidence and reduced by rule. Each approval is recorded with its reason. (A.9.2; clause 5.3.)
- Operation, monitoring and event logs.Every action in production is recorded with the checks that ran, the reviewer and the outcome, and governance changes sit in the same history. (A.6.2.6; A.6.2.8; clause 9.1.)
- Verification and validation.A model change sends the agent back to its held-out test cases before it keeps its level; exceptions, policy breaches and quality gates are tracked over time. (A.6.2.4.)
- Third-party models.Each role uses an approved model from a provider you can change; every connection to your systems shows how it is secured. (A.10.3; A.4.)
- Correction and improvement.Accepted human corrections become proposed changes to the role; every applied change is visible and reversible. (Clause 10.)
What Control does not do is write the management system. The AI policy, the scope, the assessments, the internal audit, the management review and the Statement of Applicability remain the organisation’s own documents, and they are the ones a certification body reads first. Where an impact assessment is needed before an agent goes live, we prepare the operational input: the agent’s purpose, the data it touches, its limits and the supervision it will run under; the decision to accept the impact belongs to the customer’s accountable process owner. Aitonomy does not hold an ISO 42001 certificate and does not certify anyone; the mapping above is ours, not an auditor’s.
Take one AI system you already run and ask the standard’s questions of it. What is it for, who owns it, what could it do to the people on the other end, what did it do last week, and who checked? If the answers exist as records, certification is a question of scope and an audit date. If they do not, that is the work, worth doing whether or not a questionnaire ever asks.
Common questions
What is ISO 42001, in plain terms?+
Does ISO 42001 certification mean compliance with the EU AI Act?+
Do you need ISO 27001 before ISO 42001?+
Sources and scope
- ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. Read in the public preview. Companion standards ISO/IEC 42005:2025 (AI system impact assessment) and ISO/IEC 42006:2025 (requirements for certification bodies).
- Annex A control titles cross-checked against the NIST AI RMF to ISO/IEC 42001 crosswalk.
- Schellman, lessons learned from auditing ISO 42001 and its certification FAQ (fees, Microsoft SSPA).
- Accreditation: RvA (January 2025), UKAS (January 2026), TÜV NORD (February 2026).
- Certifications: the organisations’ own announcements, linked in the table, plus AWS’s first surveillance audit, Microsoft’s May 2026 recertification, Google Cloud, Salesforce and IBM.
- AI Act: Cloud Security Alliance on EN 18286 and ISO 42001 (April 2026); CEN-CENELEC on EN 18286 (July 2026).
- Sources checked 6 September 2026. A practical guide, not legal advice, and not a substitute for the standard itself; the plain-language descriptions are ours.
Watch and listen
- Watch: BSI, “Unlocking value with ISO/IEC 27001 and ISO/IEC 42001” (May 2026): a BSI auditor on where audits fail, and Darktrace on what certification changed.
- Watch: BSI, “AI governance and assurance” (March 2026): an ISO 42001 auditor on the clauses, the impact assessment and EN 18286.
- Watch: INCITS and NIST, “Unlocking the power of AI management systems” (2024): the workshop at the standard’s launch, with Microsoft’s Kim Lucy on why the impact assessment was added.