See how Trussed maps to ISO 42001 in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Compliance Guide

    Choosing an ISO 42001 Certification Auditor: What to Look For

    Select an ISO 42001 certification auditor by verifying three things: the certification body holds accreditation from an IAF MLA signatory with ISO/IEC 42001 explicitly listed in its accredited scope, the lead auditor has demonstrable AI risk competence beyond generic ISO management-system training, and the audit methodology validates operational evidence, including runtime controls such as agent permissions and monitoring, rather than relying on policy documentation alone.

    In short

    Select an ISO 42001 certification auditor by verifying three things: the certification body holds accreditation from an IAF MLA signatory with ISO/IEC 42001 explicitly listed in its accredited scope, the lead auditor has demonstrable AI risk competence beyond generic ISO management-system training, and the audit methodology validates operational evidence, including runtime controls such as agent permissions and monitoring, rather than relying on policy documentation alone.

    Four Pillars of Auditor Evaluation

    Use these four criteria as a working checklist when shortlisting and interviewing certification bodies.

    Accreditation Scope

    Confirm the certification body's accreditation explicitly covers ISO/IEC 42001, not just adjacent standards.

    Auditor Competence

    Request evidence of AI/ML-specific training, not only generic ISO 17021-1 qualifications.

    Audit Methodology

    Determine whether the audit validates operational evidence or documentation alone.

    Runtime Scope

    Verify whether agent permissions and autonomous system boundaries fall within the audited AIMS scope.

    What an ISO 42001 Certification Auditor Actually Verifies

    ISO/IEC 42001:2023 specifies requirements for an Artificial Intelligence Management System, or AIMS, published by ISO in December 2023. Certification against this standard confirms that an organization has established, documented, and operated a management system for AI risk, not that a technical security assessment or penetration test has been performed. An ISO 42001 certification auditor evaluates conformity to the standard's clauses and to the control objectives in Annex A, which cover areas such as AI system impact assessment, data management, transparency, and third-party or supplier relationships. Because ISO/IEC 42001 is a management-system standard, it does not itself prescribe specific technical implementations, such as how agent permissions should be configured. Instead, it requires the organization to define, document, and operate controls appropriate to its own AI system lifecycle, and the auditor assesses those controls against the organization's stated scope and objectives. This distinction matters when evaluating auditors, since the standard's flexibility places significant weight on how rigorously an individual auditor interprets and tests conformity.

    Accreditation Is the Non-Negotiable Starting Point

    A certification is only as credible as the accreditation behind it. Certification bodies must be accredited by a national accreditation body to issue recognized ISO/IEC 42001 certificates, and that accreditation's credibility depends on whether the accreditation body is a signatory to the IAF Multilateral Recognition Arrangement. ISO/IEC 17021-1 establishes the general requirements for bodies providing audit and certification of management systems, including baseline auditor competence requirements that apply across ISO management system standards. The International Accreditation Forum issues mandatory documents that guide accreditation bodies on scheme-specific competence and accreditation scope for individual standards, including newer ones like ISO/IEC 42001. In practice, this means enterprises should independently verify the accreditation body's IAF MLA signatory status rather than accepting it from a certification body's own marketing materials, and should confirm that ISO/IEC 42001 is explicitly listed within the certification body's current accredited scope. Accreditation held for ISO/IEC 27001 or another standard does not by itself indicate competence to certify an AI management system.

    AI-Specific Competence Beyond Generic Management-System Auditing

    ISO/IEC 17021-1 competence requirements are written generically across management system standards and do not by themselves guarantee AI-specific expertise. Accreditation bodies typically require certification bodies to demonstrate scheme-specific technical competence before a new standard such as ISO/IEC 42001 is added to their accredited scope, but the depth of that competence at the individual lead auditor level varies. Enterprises should request direct evidence of the assigned lead auditor's AI or machine learning risk training and prior audit experience, rather than assuming competence from the certification body's general accreditation. Frameworks such as the NIST AI Risk Management Framework, which structures AI risk into govern, map, measure, and manage categories, are sometimes used as a comparative reference point for AI governance maturity. This framework is separate from ISO/IEC 42001 certification requirements, but an auditor's familiarity with it can indicate a working understanding of AI-specific risk categorization that goes beyond a generic management-system audit background.

    Where Runtime AI Governance Fits Into Audit Scope

    ISO/IEC 42001 audits follow the standard sequence used for other management system standards: a Stage 1 readiness and documentation review, a Stage 2 implementation audit, and subsequent surveillance audits. Runtime elements of AI governance, including agent permissions, autonomous action boundaries, and operational monitoring, fall under the organization's internal AIMS scope. Auditors are expected to verify evidence that these controls operate as defined, not simply that policies describing them exist. This is a meaningful evaluation point when shortlisting auditors: ask whether the audit approach extends to sampling operational logs, access control configurations, and agent permission settings, or whether it relies primarily on reviewing policy and procedure documents. Audit scope statements should also be reviewed directly to confirm whether runtime AI system boundaries, such as autonomous agents or third-party model integrations, are explicitly included in the certified AIMS scope, since gaps here can leave real operational risk unassessed even after certification is granted.

    Distinguishing a Substantive Audit From a Checklist Review

    • Audit depth should be evaluated on whether findings address substantive control implementation and risk treatment evidence, not just documentation completeness.
    • Confirm the Stage 1 and Stage 2 audit plan explicitly addresses the organization's AI system lifecycle as defined in its own AIMS scope statement.
    • Clarify surveillance audit commitments upfront, since AIMS controls, particularly runtime and operational ones, may evolve faster than annual audit cycles.
    • Treat scope mismatches between the certification body's accredited scope and the organization's actual AI use cases as a certification timeline risk to resolve early.
    • Distinguish certification bodies with broad multi-standard accreditation from those with demonstrated, scheme-specific ISO/IEC 42001 competence.

    Questions to Ask Before Selecting a Certification Body

    Bring these questions directly to prospective certification bodies before signing an engagement.

    • Is your accreditation body a signatory to the IAF Multilateral Recognition Arrangement, and is ISO/IEC 42001 explicitly listed within your current accreditation scope?
    • What specific AI or machine learning risk competence, training, or experience does the assigned lead auditor hold beyond generic ISO management-system qualifications?
    • How will the audit verify operational implementation of runtime AI controls, such as agent permissions and monitoring, rather than relying solely on policy documentation?
    • How does your audit methodology evaluate Annex A control objectives in practice, including sampling approach and evidence requirements?
    • What is your process for handling audit findings related to AI system scope changes, such as new models, agents, or third-party AI components, between certification and surveillance audits?

    Preparing AI Governance Controls for Audit

    Runtime AI governance, including agent permissions, tool approval workflows, and audit logging, provides the operational evidence auditors increasingly look for beyond static policy documentation.

    Explore Runtime Governance