How should teams handle Certification under ISO/IEC 42001?
Choose the assurance outcome first: self-assessment, a customer-requested second-party review, or independent third-party certification. Only the third option can produce an independent ISO/IEC 42001 management-system certificate, and accreditation is a separate attestation of the 's competence for a stated certification scope.
Define the exact boundary before requesting proposals. Record the legal entity, organisational units, locations, products, services, AI activities, shared processes, outsourced work, and interfaces included in or excluded from the scope. ISO/IEC 42001 applies to organisations of any size or type that provide or use products or services involving AI systems, but a certificate reaches only the documented and audited boundary.
Operate the long enough to produce representative evidence. Readiness requires more than approved policies: auditors need records showing risk and impact assessment, treatment, competence, operational controls, monitoring, internal audit, management review, and correction of nonconformities in practice.
- Approve the scope, assurance objective, audit criteria, sites, and any justified exclusions before engaging the external body.
- Check that the external body offers ISO/IEC 42001 management-system certification for the proposed scope. Verify the , certificate status, and any accreditation claim with the named accreditation body or an authoritative certificate register.
- Treat consulting, readiness reviews, and internal audits as preparation, not certification decisions. Confirm impartiality arrangements before using the same provider for several services.
- Describe the result as certification of the stated scope. Do not present it as proof that every AI system is safe, accurate, approved by ISO, or compliant with every law.
ISO's official listing identifies ISO/IEC 42001:2023 as a certifiable AIMS requirements standard. Clauses 4.3-4.4 define the documented scope and management system to which a conformity assessment applies.
ISO explains that external certification bodies perform certification and that ISO itself does not certify organisations.
The International Accreditation Forum's certificate database supports checks of certificate validity, certification-body accreditation, and the accreditation body's recognition status.