See how Trussed maps to your regulation in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Compliance Guide

    ISO/IEC 42006: Requirements for AI Audit Bodies

    ISO/IEC 42006 does not impose obligations on enterprises directly. It sets requirements for the competence, impartiality, and audit processes of certification bodies that audit organizations against ISO/IEC 42001, the AI management system standard. Enterprises are affected indirectly, through the rigor and evidentiary expectations auditors apply during ISO/IEC 42001 certification audits.

    What ISO/IEC 42006 Is

    ISO/IEC 42006 is the standard that defines requirements for bodies that certify organizations against ISO/IEC 42001. It does not create a separate certification path for enterprises. Instead, it governs how certification bodies establish competence, maintain impartiality, and conduct audits when the management system under review is an AI management system.

    For enterprises, the practical effect is upstream of the certificate. The depth of auditor questioning, the types of records requested, and the scrutiny applied to operational controls all flow from the criteria ISO/IEC 42006 places on the certification body.

    How the Standards Fit Together

    ISO/IEC 42006 sits between the generic rules for management system certification bodies and the AI management system standard that enterprises seek to meet. Understanding that stack clarifies who is bound by which document.

    Standard Role
    ISO/IEC 17021-1 Generic requirements for any management system certification body
    ISO/IEC 42006 AI-specific supplement for bodies certifying against ISO/IEC 42001
    ISO/IEC 42001 The AI management system standard enterprises are certified against

    In short: enterprises certify to ISO/IEC 42001. Certification bodies must meet ISO/IEC 17021-1 and the AI-specific supplement in ISO/IEC 42006 when they offer that certification.

    Relationship to ISO/IEC 17021-1 and ISO/IEC 42001

    ISO/IEC 17021-1 sets generic requirements for any management system certification body, covering impartiality, competence, and audit process. ISO/IEC 42006 supplements it with AI-specific criteria, similar to how ISO/IEC 27006 supplements ISO/IEC 17021-1 for information security certification bodies.

    ISO/IEC 42001 remains the standard against which the organization is assessed. ISO/IEC 42006 does not rewrite 42001 controls; it shapes how a competent, impartial body plans and executes the audit of those controls in an AI context.

    What It Requires of Certification Bodies

    ISO/IEC 42006 focuses on the certification body rather than the auditee. In practice, that means stronger expectations around:

    • Competence of the body and of individual auditors assigned to AI management system engagements
    • Impartiality safeguards, including when relationships exist with AI vendors used by the organization being audited
    • Audit processes suited to AI systems, not only to generic management system documentation
    • Accreditation scope that explicitly covers ISO/IEC 42001 audits under ISO/IEC 42006 criteria, not only general ISO/IEC 17021-1 accreditation

    Bodies that claim ISO/IEC 42001 certification capability without AI-specific competence criteria are less aligned with the intent of ISO/IEC 42006.

    What This Means for Enterprises Undergoing Audit

    Enterprises do not need to certify against ISO/IEC 42006. They pursue certification against ISO/IEC 42001. ISO/IEC 42006 affects the rigor of the audit conducted by the certification body, not a separate obligation the enterprise must meet on its own.

    Expect auditors to request documented, traceable evidence rather than policy statements alone. Typical categories include AI system inventories, risk assessment and treatment records, lifecycle governance documentation, and records of ongoing monitoring activity for deployed AI systems.

    Practical takeaway: prepare operational evidence of governance before the engagement. Audits increasingly test how controls run in production, not only whether policies exist on paper.

    Evaluation Criteria When Selecting a Certification Body

    When you choose a body for an ISO/IEC 42001 audit, treat ISO/IEC 42006 as a lens for due diligence. Use the criteria below in RFPs, intro calls, and contract review.

    • Confirm the body's accreditation scope explicitly covers ISO/IEC 42001 audits under ISO/IEC 42006 criteria, not only general ISO/IEC 17021-1 accreditation
    • Ask what AI-specific competence criteria the body requires of individual auditors assigned to your engagement
    • Ask which categories of operational evidence the audit team will request, such as risk registers, monitoring logs, or governance records
    • Ask how the body manages impartiality safeguards when relationships exist with AI vendors used by the organization being audited
    • Verify the body's accreditation status and the date of its most recent review by the relevant national accreditation body

    Governance Considerations

    Because ISO/IEC 42006 raises the bar for auditor competence and process, enterprise governance programs benefit from aligning evidence collection with what a rigorous AI management system audit will examine. Inventories, risk treatment trails, lifecycle decisions, and runtime monitoring records should be attributable, current, and easy to produce under time pressure.

    Selecting a certification body that can demonstrate ISO/IEC 42006-aligned competence also reduces the risk of an audit that underweights AI-specific issues or that later fails external scrutiny of the certification itself.

    Frequently Asked Questions

    Do enterprises need to certify against ISO/IEC 42006?

    No. ISO/IEC 42006 applies to certification bodies, not to the enterprises they audit. Enterprises pursue certification against ISO/IEC 42001. ISO/IEC 42006 affects the rigor of the audit conducted by the certification body, not a separate obligation the enterprise must meet.

    How is ISO/IEC 42006 different from ISO/IEC 17021-1?

    ISO/IEC 17021-1 sets generic requirements for any management system certification body, covering impartiality, competence, and audit process. ISO/IEC 42006 supplements it with AI-specific criteria, similar to how ISO/IEC 27006 supplements ISO/IEC 17021-1 for information security certification bodies.

    What evidence should we prepare for an ISO/IEC 42001 audit?

    Expect auditors to request documented, traceable evidence rather than policy statements, including AI system inventories, risk assessment and treatment records, lifecycle governance documentation, and records of ongoing monitoring activity for deployed AI systems.

    Prepare Operational Evidence Before Your Audit

    AI management system audits increasingly test operational evidence of governance, not policy documents alone. Understand how runtime governance controls can support the evidence base auditors expect to see.

    Explore Runtime Governance