See how Trussed maps to ISO 42001 in 20 minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Best Practices Guide — AI Governance and Compliance

    ISO/IEC 42001 Certification: Adoption and Audit Readiness

    ISO/IEC 42001 certification requires an organization to operate an AI Management System (AIMS) that satisfies Annex SL clauses and Annex A controls, then demonstrate that operation to an accredited third-party auditor through a two-stage audit process. Readiness depends on whether documented policies are backed by operational evidence that auditors can trace to specific control clauses.

    What ISO/IEC 42001 Certification Actually Requires

    ISO/IEC 42001:2023 is the first international management system standard specifying requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS). It was developed by ISO/IEC JTC 1/SC 42, the joint technical subcommittee responsible for AI standardization, and follows the Annex SL harmonized high-level structure shared with ISO/IEC 27001. This means the core clauses cover organizational context, leadership commitment, planning, support, operation, performance evaluation, and continual improvement rather than prescribing specific AI technology requirements.

    Annex A sets out control objectives covering AI policy, defined roles and responsibilities, resourcing, data management for AI systems, AI system impact assessment, and third-party supplier relationship governance. Annex B provides implementation guidance for these controls. Crucially, the Annex A controls map to organizational processes rather than specific technical mechanisms. The standard does not dictate how logging, monitoring, or runtime enforcement tooling should work, leaving those implementation decisions to the certified organization. This flexibility is valuable, but it also means certification readiness depends heavily on how well an organization translates process requirements into operational evidence.

    Structural Element Description
    First AIMS Standard Published by ISO/IEC JTC 1/SC 42 in December 2023 as the first international standard for AI management systems.
    Annex SL Structure Shares its high-level clause structure with ISO/IEC 27001, covering context, leadership, planning, support, operation, and improvement.
    Annex A Controls Addresses AI policy, roles, data governance, impact assessment, and supplier relationships, with Annex B implementation guidance.
    Third-Party Certification Assessed by accredited bodies under ISO/IEC 17021-1 through Stage 1, Stage 2, and ongoing surveillance audits.

    How Third-Party Audits Evaluate AIMS Implementation

    Certification to ISO/IEC 42001 is performed by accredited third-party certification bodies operating under ISO/IEC 17021-1, the standard governing conformity assessment for management system certifications. The process follows a two-stage audit model that mirrors other ISO management system certifications.

    Stage 1 is a documentation and readiness review. The certification body examines whether the AIMS scope, policies, and control mappings are defined and coherent. A Stage 1 review can pass on well-written policy alone.

    Stage 2 is an implementation audit, where auditors assess whether the AIMS is actually operating as documented. This distinction matters considerably for readiness planning. Stage 2 auditors look for evidence of ongoing operation, not just documented intent. Organizations typically need operational records spanning a meaningful period before Stage 2, demonstrating that impact assessments are being conducted repeatedly, roles are being exercised, and supplier due diligence is occurring in practice.

    Once certified, organizations remain subject to periodic surveillance audits and recertification cycles to confirm the AIMS continues to operate as certified, rather than lapsing back into a documentation-only state.

    Certification scope

    Certification confirms that governance processes exist and are operating. It does not confirm that a specific AI model performs safely or accurately. Auditors assess management system processes and sampled evidence, not exhaustive real-time monitoring of every AI system in scope.

    The Gap Between Documented Policy and Runtime Evidence

    Because ISO/IEC 42001 is a management system standard, auditors assess processes and sampled records rather than continuous technical behavior. This creates a practical gap: an organization can have well-documented AIMS policies while its actual AI systems behave differently at runtime, particularly if operational evidence collection is manual, inconsistent, or not continuous.

    Runtime enforcement logs and monitoring data can serve as objective evidence for operational controls, but only if they are structured in a way that maps clearly to Annex A clause language. A log of policy enforcement decisions or access approvals is useful as audit evidence only if an auditor can trace it back to a specific control objective, such as role-based access governance or supplier oversight.

    Runtime governance platforms that provide policy enforcement, audit logging, and agent permission controls generate exactly this kind of continuous operational record. This can reduce the burden of manually assembling evidence before Stage 2 or surveillance audits, provided the evidence is organized around the standard's clause structure rather than left as raw system output.

    Readiness Gaps to Identify Before Stage 1

    A structured pre-audit gap assessment helps teams identify missing documentation or undefined processes before engaging a certification body. The following areas are commonly underprepared:

    • Conduct a gap assessment against all applicable Annex A controls to identify missing documentation or undefined processes.
    • Confirm AIMS roles and responsibilities are distinct from general security or compliance roles, as Annex A requires.
    • Verify that AI system impact assessments are operationalized and repeatable, not just described in policy.
    • Document due diligence processes for third-party and supplier AI components consistent with Annex A supplier controls.
    • Define the AIMS scope statement, including which AI systems, business units, and lifecycle phases are covered.
    • Map existing runtime monitoring or logging data to the specific Annex A clauses it is intended to support.

    Operational Practices for Maintaining Certification

    Achieving initial certification is distinct from sustaining it. Surveillance audits and recertification cycles require ongoing operational evidence rather than a single point-in-time exercise. The following practices help organizations maintain certification continuity:

    • Map overlapping clauses between the AIMS and existing management systems, such as ISO/IEC 27001, to avoid duplicate documentation.
    • Establish evidence retention and version control processes so surveillance auditors can verify continuity between certification cycles.
    • Align internal AI governance and risk committees with Annex A roles to prevent conflicting accountability structures.
    • Keep the AIMS scope statement current as new AI systems or business units are added to avoid audit boundary disputes.
    • Structure runtime enforcement and monitoring output as ongoing, clause-referenced records rather than ad hoc reports assembled before each audit.

    Frequently Asked Questions

    Does ISO/IEC 42001 certification guarantee that AI systems are safe?

    No. Certification confirms that an AI Management System exists and is operating according to its defined processes. It does not certify that any specific AI model performs safely, accurately, or without bias. Safety and performance claims require separate technical evaluation outside the scope of management system certification.

    How does ISO/IEC 42001 relate to ISO/IEC 27001?

    Both standards use the Annex SL harmonized high-level structure, which means clause numbering and core requirements are aligned. Organizations that already hold ISO/IEC 27001 certification can leverage existing documentation, roles, and processes for overlapping clauses, but the AIMS scope, AI-specific controls, and impact assessment requirements are distinct and must be addressed separately.

    What is the typical timeline from gap assessment to certification?

    Timelines vary based on organizational complexity and the maturity of existing governance processes. Organizations with established ISO management systems may achieve readiness in six to twelve months. Those building AIMS processes from scratch typically require twelve to eighteen months or more before Stage 2 audit evidence is sufficiently mature.

    What counts as valid operational evidence for Stage 2 audits?

    Auditors look for records demonstrating that AIMS processes have been executed repeatedly over time. Examples include completed impact assessment records, meeting minutes from AI governance committees, supplier due diligence logs, training completion records, and policy enforcement or audit logs from runtime governance systems, provided each record is traceable to a specific Annex A control clause.

    Can runtime governance platforms substitute for manual evidence collection?

    Runtime governance platforms can significantly reduce the manual burden of evidence collection by generating continuous, structured operational records. However, those records are only useful as audit evidence when they are organized around Annex A clause references rather than left as raw system output. The platform does not replace the need to design AIMS processes; it provides documentary support for those processes.

    Evaluate Your AIMS Audit Readiness

    Closing the gap between documented AI governance policy and operational evidence starts with understanding how runtime enforcement and audit logging map to Annex A control clauses.

    Explore Runtime Governance