Who Can Certify ISO 42001? Accredited Bodies & ISO 42006
ISO 42001 certification can only be granted by an independent, accredited certification body (CB) that employs qualified human auditors. These certification bodies must operate in accordance with ISO/IEC 42006, the dedicated standard defining requirements for bodies providing audit and certification of Artificial Intelligence Management Systems (AIMS). While management software, consultants, and internal audit teams—including platforms like DoAIRight—help an organization prepare for certification and sustain compliance, only accredited third-party certification bodies have the legal and regulatory authority to issue official ISO/IEC 42001 certificates.
What Is an Accredited ISO 42001 Certification Body?
An accredited ISO 42001 certification body is an independent third-party organization that has been formally evaluated and authorized by a recognized national accreditation body (such as ANAB in the United States, UKAS in the United Kingdom, or DAkkS in Germany).
Accreditation ensures that the certification body maintains impartiality, technical competence, and rigorous audit standards. When selecting a certification partner for your AI Management System (AIMS), choosing an accredited CB ensures that your certificate is globally recognized by enterprise clients, regulators, and stakeholders.
Key responsibilities of an accredited certification body include:
- Evaluating AIMS Conformance: Reviewing organizational compliance against ISO/IEC 42001 Clauses 4 through 10.
- Assessing Control Implementation: Auditing applicable controls across Annex A domains, including AI impact assessments (Annex A.5), data governance (Annex A.7), and third-party supplier management (Annex A.10).
- Issuing Official Certification: Granting three-year certification certificates backed by international accreditation agreements.
The Role of ISO/IEC 42006 in AIMS Auditing
Just as ISO/IEC 42001 sets the standard for how organizations build an AI Management System, ISO/IEC 42006 specifies the requirements for the bodies that audit those systems.
ISO 42006 ensures that certification bodies maintain consistent, high-quality auditing practices specific to artificial intelligence. Standard management system auditing rules (like ISO/IEC 17021-1) are not sufficient on their own to evaluate complex AI risks, algorithmic bias, machine learning lifecycles, and societal impacts.
ISO/IEC 42006 establishes standards for:
- Auditor Competence: Requiring auditors to possess deep technical knowledge of machine learning lifecycles (Annex A.6), AI safety, data management (Annex A.7), and AI ethics.
- Impact Evaluation Standards: Ensuring auditors know how to evaluate an organization's assessment of AI impacts on individuals, groups, and society (Clause 6.1.2 and Annex A.5).
- Audit Duration and Scope: Defining standard methodologies for sampling models, reviewing risk treatments (Clause 6.1.3), and testing operational controls (Clause 8).
The ISO 42001 Certification Process
To earn certification from an accredited body, an organization must pass a formal two-stage audit process conducted by human auditors:
Stage 1 Audit: Readiness & Documentation Review
The auditor assesses your management system documentation to ensure standard requirements are addressed. They verify your context of the organization (Clause 4), leadership commitment (Clause 5), planning processes (Clause 6), and support mechanisms (Clause 7).
Stage 2 Audit: Implementation & Operational Testing
Human auditors evaluate the practical execution of your AIMS. They inspect operational controls (Clause 8), review performance evaluations and internal audit records (Clause 9), and confirm that mechanisms for continual improvement (Clause 10) are functioning effectively. They also examine specific Annex A controls, such as system lifecycle management (Annex A.6) and information transparency for interested parties (Annex A.8).
If the organization demonstrates full compliance with no major non-conformities, the certification body grants the ISO/IEC 42001 certificate.
Software Platforms vs. Certification Bodies: Understanding the Difference
There is often confusion surrounding the role of AI compliance software versus certification bodies.
- Software Platforms (e.g., DoAIRight): Enable organizations to assess risk, map controls, compile evidence, run gap analyses, and sustain compliance over time. Use DoAIRight's free readiness assessment to evaluate your current posture and streamline audit preparation.
- Certification Bodies: Independent third parties that evaluate your operational evidence and issue accredited certificates.
No software tool or consultancy can self-certify an organization or grant an official ISO/IEC 42001 certificate. ISO 42006 explicitly mandates that certification decisions must be rendered by independent human audit teams who possess verified technical subject-matter expertise.
How to Select the Right Certification Body
When preparing for certification, consider the following criteria when evaluating certification bodies:
- Verify Official Accreditation: Confirm that the body is accredited by a recognized accreditation body operating under the International Accreditation Forum (IAF) Multilateral Recognition Arrangement (MLA).
- Confirm ISO 42006 Compliance: Ensure the body's audit personnel are trained and qualified under ISO/IEC 42006 specifically for AIMS scope.
- Assess Industry Expertise: Choose a certification body with experience in your specific industry and AI application type (e.g., generative AI, automated decision-making, computer vision).
- Evaluate Global Recognition: Select a body whose certificates are recognized in the geographic regions where your customers and regulators operate.
Frequently asked
Can software or AI platforms issue an official ISO 42001 certificate?
No. Official ISO 42001 certificates are issued exclusively by accredited third-party certification bodies using qualified human auditors. Software tools like DoAIRight help prepare your organization to become certification-ready, but do not grant certificates.
What is ISO/IEC 42006?
ISO/IEC 42006 is the standard specifying competence, consistency, and technical requirements for certification bodies auditing Artificial Intelligence Management Systems (AIMS) under ISO/IEC 42001.
How do I check if an ISO 42001 certification body is accredited?
You can verify accreditation by checking the accreditation certificate issued to the body by a recognized national accreditation organization (such as ANAB or UKAS) that belongs to the International Accreditation Forum (IAF).
How long does an ISO 42001 certification remain valid?
An ISO 42001 certificate is valid for three years, provided the organization successfully passes annual surveillance audits conducted by the accredited certification body.