Field Notes / Compliance
ISO 42001 Certification: The Path, The Audit Stages, And Where Adversarial Testing Becomes Evidence
ISO 42001 certifies how you govern AI. It runs on the same audit machinery as ISO 27001, which means a 27001 holder already owns most of the path. What they do not own is proof of how their models behave under attack. This is the route from decision to certificate, and the point on it where testing stops being optional.
01 What ISO 42001 covers
rganisations reach for ISO 42001 for one of two reasons. A customer asked for it during procurement, or a regulator is coming and the board wants something auditable in place first. Both are good reasons. Neither tells you what the standard actually governs, and buyers routinely arrive expecting a model safety certificate.
It is a management-system standard. It certifies the arrangement around your AI. The model itself sits outside the certificate. Under it you define an AI policy, name who owns AI risk, set out the lifecycle every AI system passes through from design to retirement, assess the impact your systems have on the people affected by their outputs, and govern the data and the suppliers feeding them. Then you prove that all of it runs. Microsoft holds certification across nine of its AI services and states plainly that customers may use that certification in their own assessment while remaining responsible for engaging an assessor to evaluate the controls inside their own organisation Microsoft Compliance .
Decide your scope first. It prices everything after it. Certify the AI systems that carry consequence: the ones customers meet, the ones that influence a decision about a person, the ones with access to data you would not want summarised in a news article. A narrow, honest scope certifies faster and survives surveillance. A sprawling one collapses under its own evidence burden in year two.
02 If you already hold ISO 27001
Start from what transfers. Both standards use the harmonised management-system structure, so clauses 4 to 10 line up: context, leadership, planning, support, operation, performance evaluation, improvement. Your internal audit programme transfers. Your management review cadence transfers. Your nonconformity and corrective action process transfers. Your document control transfers. The scaffolding is done.
| Dimension | ISO 27001 | ISO 42001 |
|---|---|---|
| What is governed | Information assets and their confidentiality, integrity and availability | AI systems across their lifecycle, and the impact of their outputs on people |
| Signature artefact | Statement of Applicability, risk treatment plan | AI policy, AI impact assessment, system lifecycle records |
| Behavioural evidence | Penetration test reports, vulnerability management records | Model evaluation results and adversarial testing findings |
| Audit mechanics | ISO/IEC 17021-1: two stages, three-year cycle | Identical, plus ISO/IEC 42006 requirements on the certification body |
| Market maturity | 96,709 valid certificates across 179,877 sites | Absent from the ISO Survey global results table |
Those two figures in the last row deserve care. The ISO Survey 2024, published in September 2025, recorded 96,709 valid ISO/IEC 27001 certificates across 179,877 sites, compiled directly from IAF CertSearch with 76 accreditation bodies and more than 2,400 certification bodies contributing ISO Survey 2024 . The prior edition reported 47,291 certificates. That jump is a methodology change in how ISO counts. The market did not double. ISO/IEC 42001 appears nowhere in the global results table, so no official worldwide count of ISO 42001 certificates exists. Treat any vendor quoting one with suspicion.
Here is the honest gap for a 27001 holder. Open your last evidence pack and look for a row about how a model behaved. There is none. Your vulnerability register tracks unpatched software, and an agent talked into calling a tool it should never have touched leaves no CVE behind. Your access matrix records who may read a database, and says nothing about what the model summarised out of that database into a customer-facing answer. A penetration test earns its place in the pack and answers a question the ISO 42001 auditor is not asking. He wants to know how the AI behaves. Nothing you already hold tells him.
03 The audit path, stage by stage
ISO/IEC 17021-1 sets the mechanics, and the accreditation-body text is unambiguous. The audit programme for initial certification is a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year before the certificate expires. The three-year cycle begins with the certification decision ISO/IEC 17021-1 .
Stage 1 examines your documented management system, evaluates whether you are prepared for Stage 2, and checks that internal audits and management reviews have been planned and performed. The first-time failure we see most often at Stage 1 is a dull one: the internal audit was scheduled and never run. Stage 2 is the harder one. Its stated purpose is to evaluate the implementation, including effectiveness, of the client's management system ISO/IEC 17021-1 . That one word, effectiveness, is what costs money. A Stage 2 auditor wants proof the control worked. A written procedure will not carry it.
Plan backwards from Stage 2 rather than forwards from the kick-off meeting. You need at least one full internal audit cycle and one management review before Stage 1. You need your AI systems inventoried, impact-assessed and running under the controls you documented for long enough to have generated records. And you need behavioural evidence for the AI systems in scope, which takes the longest to produce because testing, remediation and retesting run in sequence.
04 Where adversarial testing becomes evidence
Your auditor asks you to show that the AI risk controls are effective. Nobody writes down which test proves that, so teams supply policy documents and get a finding. The frameworks your auditor reads have already answered the question.
NIST puts security in the measurement function. MEASURE 2.7 of the AI Risk Management Framework requires that AI system security and resilience, as identified in the MAP function, are evaluated and documented NIST AI RMF 1.0 . The Generative AI Profile then names the method. Action MS-2.7-007 directs you to perform AI red-teaming to assess resilience against abuse that facilitates attacks on other systems, generative AI attacks such as prompt injection, and machine learning attacks including adversarial examples, data poisoning, membership inference, model extraction and sponge examples NIST AI 600-1 . That is a control objective and its matching test, published by a standards body, free to cite in your evidence pack.
European law points the same way. Article 15(5) of the AI Act requires high-risk AI systems to be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities, with measures addressing data poisoning, model poisoning, adversarial examples, model evasion, confidentiality attacks and model flaws AI Act Article 15 . Article 55(1)(a) goes further for providers of general-purpose AI models with systemic risk, requiring model evaluation under standardised protocols including conducting and documenting adversarial testing to identify and mitigate systemic risks AI Act Article 55 . That duty binds systemic-risk GPAI providers specifically. It does not bind every deployer. It does establish adversarial testing as the named method in European law.
In practice, three artefacts close the AI evidence gap in a 42001 pack. An AI red teaming report showing the attack paths that worked against your deployed system. An AI penetration test covering the infrastructure, APIs and permissions wrapped around the model. A retest confirming that the findings you fixed stayed fixed. Our AI security testing covers all three against the system as it runs in production, including the content it ingests, the retrieval index behind it and the actions its agents take without a human approving them.
05 What the certificate does not buy
Be precise about this with your board, because the market is not. ISO 42001 does not confer a presumption of conformity with the EU AI Act. Article 40 flows that presumption from harmonised European standards cited in the Official Journal AI Act Article 40 , and Article 42 adds a narrow second route: a cybersecurity certificate issued under a scheme adopted pursuant to Regulation (EU) 2019/881 covers the cybersecurity requirements of Article 15, and only so far as the certificate reaches them AI Act Article 42 . Neither route runs through ISO 42001. CEN and CENELEC were still working to get there: in October 2025 they adopted an exceptional package of measures to accelerate delivery of key standards under CEN-CLC/JTC 21, including a drafting group to finalise six delayed drafts, targeting availability by the fourth quarter of 2026 CEN-CENELEC 2025 . Until those land, ISO 42001 is the only AI governance standard with an accredited certification route under ISO/IEC 17021-1. That argues for certifying well. Waiting buys you nothing.
The deadlines moved, and knowing the current ones matters. The AI Act's original schedule applied Chapters I and II from 2 February 2025, the general-purpose AI obligations from 2 August 2025, and general application from 2 August 2026 AI Act Article 113 . Then Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026, three days after publication in the Official Journal Hunton 2026 . Parliament approved it on 16 June 2026 by 423 votes to 57 with 174 abstentions, fixing the high-risk deadlines at 2 December 2027 for stand-alone systems and 2 August 2028 for high-risk AI embedded in products European Parliament 2026 . The GPAI obligations under Article 55 kept their dates. They have been live since August 2025. The Omnibus did widen the AI Office's supervisory role over general-purpose AI models Hunton 2026 .
What certification does buy is real. An accredited third party has examined how you govern AI and found it working. Procurement teams accept it. Insurers read it. A regulator opening a file finds a documented risk process with dated evidence behind it rather than a scramble. The Digital Omnibus bought you twelve to sixteen months of extra runway. Use that window to build the thing properly, at your own pace, on your own timetable.
06 Your path from here
The sequence below is the one that gets organisations to a certificate without a Stage 2 nonconformity. It assumes you already hold ISO 27001. If you do not, add the management-system groundwork at the front and expect a longer run-up.
- Inventory every AI system and mark the ones that touch a customer, a decision about a person, or regulated data
- Set a scope you can defend, then write the AI policy and name the owner of AI risk
- Run an AI impact assessment on each in-scope system and record what the system reads, calls and is permitted to do
- Commission independent adversarial testing on the highest-reach system, fix what opens, and retest to prove closure
- Run one full internal audit cycle and one management review before you book Stage 1
- Select a certification body accredited against ISO/IEC 42006 and confirm which accreditation body assessed it
- Schedule retesting between surveillance audits so the evidence stays current as the systems change
The step most programmes underestimate is the fourth one, because testing, remediation and retesting run in sequence and cannot be compressed the week before an audit. Start it early and it becomes the strongest exhibit in your pack. Start it late and it becomes the reason your Stage 2 slips a quarter.
Take the free audit and you will know within days which of your AI systems carries the most exposure, what an attacker reaches through it, and exactly which piece of ISO 42001 evidence you are missing. No retainer, no obligation, and a shortlist your certification lead can act on this month. Enterprise-grade. Not enterprise-priced.
References
Sources
- Microsoft Learn. ISO/IEC 42001:2023 Artificial Intelligence Management System Standards. Microsoft Compliance offerings, 2025. learn.microsoft.com
- ISO/IEC 17021-1:2015, Section 9 (Process Requirements). Accreditation-body extract published by the International Accreditation Service. iasonline.org
- IEC Webstore. ISO/IEC 42006:2025, Requirements for bodies providing audit and certification of artificial intelligence management systems. Edition 1.0, 7 July 2025. webstore.iec.ch
- ISBL. Resumen: ISO Survey 2024. Global results sourced from The ISO Survey of Management System Standard Certifications 2024, ISO/CASCO, September 2025. isbl.eu
- NIST. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. January 2023. nvlpubs.nist.gov
- NIST. AI Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1. July 2024. nvlpubs.nist.gov
- European Commission, AI Act Service Desk. Article 15, Accuracy, Robustness and Cybersecurity. Regulation (EU) 2024/1689. ai-act-service-desk.ec.europa.eu
- EU Artificial Intelligence Act. Article 55, Obligations for providers of general-purpose AI models with systemic risk. artificialintelligenceact.eu
- European Commission, AI Act Service Desk. Article 99, Penalties. Regulation (EU) 2024/1689. ai-act-service-desk.ec.europa.eu
- European Commission, AI Act Service Desk. Article 113, Entry into force and application. Regulation (EU) 2024/1689. ai-act-service-desk.ec.europa.eu
- European Parliament. Legislative Train Schedule: Digital Omnibus on AI. 2026. europarl.europa.eu
- Hunton Andrews Kurth. EU Digital Omnibus on AI Enters Into Force. Privacy and Cybersecurity Law Blog, 2026. hunton.com
- CEN-CENELEC. Update on the decision to accelerate development of AI standards. 23 October 2025. cencenelec.eu
- Stanford HAI. 2026 AI Index Report, Responsible AI chapter. Stanford Institute for Human-Centered AI, 2026. hai.stanford.edu
- Stanford HAI. 2026 AI Index Report. Stanford Institute for Human-Centered AI, 2026. hai.stanford.edu
- European Commission, AI Act Service Desk. Article 40, Harmonised standards and standardisation deliverables. Regulation (EU) 2024/1689. ai-act-service-desk.ec.europa.eu
- European Commission, AI Act Service Desk. Article 42, Presumption of conformity with certain requirements. Regulation (EU) 2024/1689. ai-act-service-desk.ec.europa.eu