Who is ISO/IEC 42001 certification for?
ISO/IEC 42001 applies to organisations that develop, provide or use artificial intelligence systems and are accountable for the consequences. It is used most often by:
- Product organisations that build, fine-tune or embed models inside a service they ship.
- Organisations supplying AI capability to others, who are asked to evidence governance during procurement or vendor review.
- Organisations using AI systems obtained from third parties in ways that affect customers, staff or the public.
- Public sector bodies and their suppliers working to emerging assurance expectations for AI.
Establishing your role is the first question, because it determines what the management system has to control. Many organisations occupy more than one role at once, developing some systems and consuming others, and the scope has to say so plainly.
What does an ISO/IEC 42001 audit assess?
Our audit examines the management system against ISO/IEC 42001:2023 and against the arrangements you have stated for yourself. We look at:
- The AI policy and objectives, and whether AI governance connects to existing risk management rather than sitting alongside it.
- Roles, responsibilities and authority for AI decisions, including who may approve a deployment and who may stop one.
- The inventory of AI systems inside the scope, and the route by which a new system enters it.
- AI risk assessment and treatment, and AI system impact assessment, including effects on individuals and groups.
- Life-cycle controls: requirements, data provenance and quality, design and development, verification and validation, deployment, operation, monitoring and retirement.
- Transparency, and the information provided to users and to affected parties.
- Human oversight arrangements, and evidence that they function in practice rather than on paper.
- Third-party arrangements where models, data or platforms are obtained from others.
- Incident handling, performance evaluation, internal audit, management review and improvement.
Certification confirms that the management system meets the standard within the certified scope. It is not approval of any particular model, product or output, and it is not a statement that a system is accurate, unbiased or safe.
How does ISO/IEC 42001 certification work?
Application and review
You describe your role, the AI systems proposed for the scope, your sites and activities, and any capability obtained from third parties. We determine the competence required across AI governance and your domain, the audit time applicable under the scheme, and whether we can take the work impartially.
Stage 1
We examine readiness for Stage 2: how the scope and role are defined, the completeness of the AI system inventory, the risk and impact assessment methods, the documented life-cycle controls, and internal audit and management review records.
Stage 2
We test implementation and effectiveness across the life cycle, sampling AI systems within the scope and examining oversight and monitoring as they operate.
Correction and corrective action
Where nonconformities are raised, you analyse cause and act. We review the response and verify effectiveness as required before a decision can be made.
Independent certification decision
Competent personnel who were not members of the audit team review the audit information and make the certification decision.
Surveillance and recertification
Surveillance audits monitor continuing conformity through the cycle. Because AI systems change quickly, surveillance pays particular attention to systems introduced, retrained or materially repurposed since the previous audit.
Each stage is described in full on our certification process page.
What evidence should you prepare for an ISO/IEC 42001 audit?
Bring the records the management system actually produces. For ISO/IEC 42001 we normally expect to see:
- A scope statement naming your role and the AI systems included.
- The AI policy and objectives, and a record of who holds accountability.
- The AI system inventory, showing owner, purpose, life-cycle stage and risk classification for each entry.
- Risk assessments and impact assessments for the systems in scope, with dates and the triggers that require review.
- Data documentation: sources, provenance, permitted use, quality checks, and the handling of training or tuning data.
- Design, development and change records, including model or prompt changes, evaluation results and release approvals.
- Verification and validation evidence, including how performance is measured and which thresholds require action.
- Records of human oversight: what was reviewed, by whom, and what followed when a system was overridden.
- Monitoring output and AI incident records.
- Assessments of third parties supplying models, data or platforms.
- Internal audit reports and management review records.
What are the most common ISO/IEC 42001 readiness gaps?
These are the issues that most often delay a Stage 2 audit or generate findings.
- No inventory. The organisation cannot list the AI systems it runs, so the scope cannot be tested. This is the most common blocker by a wide margin.
- Role left undecided. Developing, supplying and using AI call for different controls. Where the role is unstated, the controls are usually incomplete.
- Impact assessment treated as a one-off. An assessment completed at launch and never revisited does not describe a system that has since been retrained or repurposed.
- AI governance running parallel to everything else. A separate committee with no connection to risk management, procurement, change control or incident handling.
- Human oversight asserted rather than evidenced. A statement that a person reviews output, with nothing recording what was reviewed or what an override looked like.
- Third-party models treated as outside the scope. Depending on an external model does not move accountability for the outcome.
- Tools adopted outside the governance path. Teams introducing AI capability informally, which surfaces during the audit rather than before it.
ISO/IEC 42001 enquiries
Start with your AI system inventory.
Tell us your role, the systems you would place inside the scope and where they sit in their life cycle. We will explain what an ISO/IEC 42001 engagement would involve and what evidence to prepare.
Start an enquiryRelated information
- What we certify — our full certification scope.
- Certification process — every stage from application to recertification.
- ISO/IEC 27001 certification — information security management systems.
- ISO 9001 certification — quality management systems.
- Impartiality statement — how independence is protected.
- Complaints and appeals — how to raise a concern or challenge a decision.
- Do you need ISO/IEC 42001 if you already hold ISO/IEC 27001? — how the two management systems differ and can work together.
- Contact — the scoping enquiry form.
General enquiries: info@acscert.com.au. Complaints and appeals: complaints@acscert.com.au.
