FAQGlobalISO/IEC 42001

ISO/IEC 42001 FAQ Certification

ISO/IEC 42001 certification is third-party assurance that a defined AIMS scope conforms to specified audit criteria; it is not certification of every AI model, output, or legal obligation.

Before selecting a certification route, stabilise the scope, operate the AIMS, complete internal audit and management review, address nonconformities, and verify the certification body's competence and accreditation claims.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ISO/IEC 42001 contains auditable requirements. An organisation can assess its own conformity or seek independent third-party certification. A certificate covers the legal entity, activities, locations, and other boundaries stated in its scope; it does not certify every AI model or output, guarantee safety or accuracy, or establish compliance with every applicable law.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How should teams handle Certification under ISO/IEC 42001?

Choose the assurance outcome first: self-assessment, a customer-requested second-party review, or independent third-party certification. Only the third option can produce an independent ISO/IEC 42001 management-system certificate, and accreditation is a separate attestation of the 's competence for a stated certification scope.

Define the exact boundary before requesting proposals. Record the legal entity, organisational units, locations, products, services, AI activities, shared processes, outsourced work, and interfaces included in or excluded from the scope. ISO/IEC 42001 applies to organisations of any size or type that provide or use products or services involving AI systems, but a certificate reaches only the documented and audited boundary.

Operate the long enough to produce representative evidence. Readiness requires more than approved policies: auditors need records showing risk and impact assessment, treatment, competence, operational controls, monitoring, internal audit, management review, and correction of nonconformities in practice.

  • Approve the scope, assurance objective, audit criteria, sites, and any justified exclusions before engaging the external body.
  • Check that the external body offers ISO/IEC 42001 management-system certification for the proposed scope. Verify the , certificate status, and any accreditation claim with the named accreditation body or an authoritative certificate register.
  • Treat consulting, readiness reviews, and internal audits as preparation, not certification decisions. Confirm impartiality arrangements before using the same provider for several services.
  • Describe the result as certification of the stated scope. Do not present it as proof that every AI system is safe, accurate, approved by ISO, or compliant with every law.
Citations
ISO/IEC 42001:2023 standard page

ISO's official listing identifies ISO/IEC 42001:2023 as a certifiable AIMS requirements standard. Clauses 4.3-4.4 define the documented scope and management system to which a conformity assessment applies.

ISO - Certification

ISO explains that external certification bodies perform certification and that ISO itself does not certify organisations.

IAF CertSearch

The International Accreditation Forum's certificate database supports checks of certificate validity, certification-body accreditation, and the accreditation body's recognition status.

Question 2

What evidence should prove Certification is current under ISO/IEC 42001?

Build a traceable evidence set for the complete audited boundary. It should cover context and scope, interested-party requirements, policy and roles, objectives, AI risk criteria, system inventory, risk and impact assessments, the , approved treatment plans and residual risks, competence, controlled documents, operational samples, supplier controls, monitoring results, internal audits, management reviews, nonconformities, and corrective-action effectiveness.

For each sample, retain the system or process covered, owner, version, period, criteria, result, exception, approval, and follow-up. Evidence from outside the proposed scope may provide context, but it cannot substitute for records from the sites and activities the certificate will name.

  • Complete a scope-relevant internal audit and management review before external assessment; the certification audit replaces neither requirement.
  • Trace each necessary control from risk or external requirement to implementation, operating evidence, effectiveness result, and residual-risk decision.
  • Log gaps as nonconformities where requirements are not met, correct them, address causes where applicable, and retain the effectiveness review.
  • Keep current copies of the application, audit plan, audit reports, nonconformity responses, certificate, scope statement, and public certification claims.
Citations
ISO/IEC 42001:2023 standard page

ISO/IEC 42001:2023 Clauses 6-10 identify the planning, operation, documented results, monitoring, internal audit, management review, and corrective-action evidence needed to demonstrate an operating AIMS.

Recommended next step

Put the certification guidance into practice

Capture owners, evidence, decisions, and review dates in one workflow record so AI governance controls and escalation points stay auditable over time.

Question 3

Who should approve Certification decisions under ISO/IEC 42001?

Top management should approve the scope and assurance objective because it is accountable for the , resources, integration into business processes, and intended results. An AIMS owner can coordinate readiness, while process, system, risk, and control owners provide evidence and correct gaps.

Internal auditors must remain objective and impartial. Procurement or assurance teams can check the external body's proposed scope, competence, impartiality, and credentials, but the organisation should verify accreditation with the named accreditation body or authoritative register rather than relying on a proposal, sales statement, or logo.

The external body makes the certification decision. Consultants, internal auditors, customers, and the organisation's management can assess readiness or conformity, but they do not issue the independent certificate.

  • Assign readiness, evidence, corrective-action, and certification-body liaison responsibilities.
  • Keep internal audit independent from the work being audited as far as the organisation's structure permits.
  • Keep approval records with the evidence rather than in disconnected email threads.
Citations
ISO/IEC 42001:2023 standard page

ISO/IEC 42001:2023 Clauses 5.1-5.3 assign leadership and AIMS responsibilities; Clause 9.2 requires objective and impartial internal audits with defined criteria and scope.

Question 4

When should Certification be reviewed under ISO/IEC 42001?

Review the certified scope whenever organisational boundaries, legal entities, sites, AI activities, products, services, outsourced processes, major suppliers, or interested-party requirements change. Assess planned changes before representing the new activity as certified, and tell the when the certification agreement requires notification.

Follow the audit and certificate cycle stated by the , including any surveillance, recertification, special-audit, suspension, or withdrawal conditions. ISO/IEC 42001 itself requires internal audits and management reviews at planned intervals but does not prescribe one universal external audit frequency or certificate term.

Before making a public claim, verify that certificate wording, legal entity, sites, activities, exclusions, standard edition, validity dates, certificate status, and certification-body details match the current certificate and actual boundary. Do not wait for an external audit to address a known nonconformity or ineffective control.

  • Keep certificate wording and public claims aligned with the audited scope.
  • Assess scope changes before new activities are represented as certified.
  • Correct known nonconformities without waiting for the next external audit.
Citations
ISO/IEC 42001:2023 standard page

ISO/IEC 42001:2023 requires planned internal audits and management reviews, controlled changes, continual improvement, and corrective action; certificate validity and surveillance arrangements additionally depend on the certification agreement.

Primary sources

References and citations

iafcertsearch.org
Referenced sections
  • The International Accreditation Forum's certificate database supports checks of certificate validity, certification-body accreditation, and the accreditation body's recognition status.
iso.org
Referenced sections
  • ISO explains that external certification bodies perform certification and that ISO itself does not certify organisations.
iso.org
Referenced sections
  • ISO/IEC 42001:2023 requires planned internal audits and management reviews, controlled changes, continual improvement, and corrective action; certificate validity and surveillance arrangements additionally depend on the certification agreement.
"requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System"
Related guides

Explore more topics

ISO/IEC 42001 AI Impact Assessment Template
ISO/IEC 42001 AI-system impact assessment template for consequences, affected people, foreseeable misuse, context, evidence, approval, and reassessment.
ISO/IEC 42001 AI Management FAQ
Plain-language ISO/IEC 42001 FAQ covering scope, policy, Annex controls, risk and impact assessment, suppliers, monitoring, certification, and legal limits.
ISO/IEC 42001 AI Policy FAQ
ISO/IEC 42001 AI policy requirements, approval, communication, evidence, alignment with other policies, and review triggers.
ISO/IEC 42001 AI System Inventory Guide
Build an ISO/IEC 42001 AI inventory covering purpose, owners, lifecycle roles, data, resources, suppliers, impacts, risks, controls, and monitoring.
ISO/IEC 42001 AI System Inventory Workflow
ISO/IEC 42001 workflow for creating, approving, maintaining, changing, and retiring AI-system inventory records with accountable evidence.
ISO/IEC 42001 AIMS Scope Decision Guide
Define an auditable ISO/IEC 42001 AIMS boundary across organisational units, AI activities, products, services, interfaces, suppliers, and customers.
ISO/IEC 42001 AIMS Scope Decision Workflow
ISO/IEC 42001 AIMS scope workflow for context, interested parties, AI activities, external dependencies, boundary approval, and change review.
ISO/IEC 42001 Compliance Guide
ISO/IEC 42001 conformance guide for Clauses 4-10, risk treatment, controls, operating evidence, internal audit, management review, and correction.
ISO/IEC 42001 Controls and Governance Model Guide
ISO/IEC 42001 governance model linking leadership, policy, risk and impact assessment, Annex controls, lifecycle roles, monitoring, audit, and improvement.
ISO/IEC 42001 Generative AI FAQ
Apply ISO/IEC 42001 to generative AI development, procurement, integration, employee use, supplier evidence, impacts, controls, and monitoring.
ISO/IEC 42001 High Risk AI FAQ
Separate ISO/IEC 42001 organisational risk criteria from legal high-risk AI classifications, with evidence, approval, and reassessment triggers.
ISO/IEC 42001 Human Oversight FAQ
Design and evidence effective human oversight under ISO/IEC 42001, including competence, information, intervention authority, testing, and review.
ISO/IEC 42001 Model Monitoring Evidence Guide
ISO/IEC 42001 monitoring evidence for AIMS performance, AI-system outcomes, impacts, control effectiveness, supplier signals, escalation, and correction.
ISO/IEC 42001 Post Market Monitoring FAQ
Distinguish ISO/IEC 42001 operational monitoring from legal post-market monitoring and connect real-world evidence to risk, review, incidents, and correction.
ISO/IEC 42001 Provider and Deployer Roles FAQ
Map ISO/IEC 42001 lifecycle responsibilities across developers, users, suppliers, customers, and third parties while keeping legal operator roles separate.
ISO/IEC 42001 Requirements Guide
ISO/IEC 42001:2023 requirements explained across Clauses 4-10, Annex A controls, Annex B guidance, evidence, audit, review, and improvement.
ISO/IEC 42001 Risk Controls FAQ
Select, justify, approve, operate, and review ISO/IEC 42001 risk controls, including Annex A comparison, the statement of applicability, residual risk, and evidence.
ISO/IEC 42001 vs EU AI Act Comparison
Compare voluntary ISO/IEC 42001 AIMS certification with binding EU AI Act roles, classifications, duties, evidence, dates, and enforcement.
ISO/IEC 42001 vs ISO/IEC 23894 Comparison
Compare certifiable ISO/IEC 42001 AIMS requirements with ISO/IEC 23894 AI risk-management guidance and see how to integrate their evidence.
ISO/IEC 42001 vs NIST AI RMF Comparison
Compare ISO/IEC 42001 AIMS requirements with the voluntary NIST AI RMF GOVERN, MAP, MEASURE, and MANAGE functions and evidence.