Written and maintained by CASRAI Editorial Board
Last updated
A vendor sends you a PDF. It has a logo, a certificate number, an issue date, and the words “ISO/IEC 42001:2023” across the top. Your procurement checklist has a box for AI management system certification, and this appears to tick it. The question almost nobody asks next is the one that decides whether the document means anything: who accredited the body that issued it, and against what criteria?
That question has a standard of its own. ISO/IEC 42006:2025 is not a standard an organisation gets certified against — you cannot be “ISO 42006 certified,” and any vendor claiming to be has misunderstood the document. It is the criteria document that accreditation bodies use to assess the certification bodies that issue ISO/IEC 42001 certificates. It sits one layer above the certificate in your inbox, and it is the reason some of those certificates carry international recognition and others carry none.
It also arrived late. ISO/IEC 42001 was published in December 2023. ISO/IEC 42006 was published on 7 July 2025 — a gap of roughly nineteen months during which certificates were being issued against an AI management system standard that had no AI-specific criteria document governing the auditors.
What ISO/IEC 42006 Actually Is
The following details are confirmed directly from the IEC Webstore catalogue entry for the standard (IEC is the co-publisher, alongside ISO):
- Designation: ISO/IEC 42006:2025
- Full title: Information technology — Artificial intelligence — Requirements for bodies providing audit and certification of artificial intelligence management systems
- Published: 7 July 2025
- Edition: 1.0 (first edition)
- Length: 31 pages
- Committee: ISO/IEC JTC 1/SC 42 (Artificial Intelligence)
Two lines from the published scope carry the whole argument of this guide. The first is that the document “specifies additional requirements to ISO/IEC 17021-1” — it is a supplement, not a free-standing standard. The second is the catalogue entry’s own statement that the document “can be used as a criteria document for accreditation or peer assessment.” That sentence is the entire function of ISO/IEC 42006: it exists to be applied to certification bodies, by the organisations that accredit them.
The scope also describes the purpose in customer terms — the standard is there to help conformity assessment bodies demonstrate competence when auditing and certifying AI management systems, and to provide “the necessary information and confidence to customers about the way certification has been granted.” The customer in that sentence is you, reading the PDF.
The Three-Layer Stack
AI management system certification runs on three stacked documents, and confusing them is the most common error in vendor-assurance conversations.
Layer 1 — ISO/IEC 17021-1: the generic rules for certification bodies
This is the long-standing standard setting out conformity assessment requirements for any body that audits and certifies management systems, of any kind. It governs impartiality, competence, the structure of the audit process, and the conditions under which a certificate may be granted, maintained, suspended or withdrawn. It is sector-neutral: the same document sits under quality, information security and AI certification alike.
Layer 2 — ISO/IEC 42006: the AI-specific supplement
This adds the AI-specific requirements that 17021-1 cannot provide because it predates the problem — what an audit team must collectively understand about AI systems, and how audit effort should be sized for an AI management system. It does not replace 17021-1; it is read on top of it.
Layer 3 — ISO/IEC 42001: the standard being audited
This is the only layer the certified organisation is assessed against. It is the AI management system standard itself, covering how an organisation governs its development, provision or use of AI. If you want the detail of what an organisation must do to earn the certificate, that is covered in our guide to ISO/IEC 42001 certification and what it actually certifies.
The stack explains a distinction that trips up buyers constantly. An organisation is certified against layer 3. A certification body is accredited against layers 1 and 2. Nobody is ever certified against ISO/IEC 42006.
Why the Timing Gap Matters — Stated Precisely
It is tempting to say that no ISO 42001 certificate issued before July 2025 came from an accredited body. That is too strong, and it is wrong. Accreditation bodies did begin accrediting certification bodies for ISO/IEC 42001 before ISO/IEC 42006 existed — they did it against ISO/IEC 17021-1 plus their own scheme requirements, which is a normal way to open a new certification scheme ahead of a published sector supplement.
The accurate statement is narrower and more useful:
- Before 7 July 2025, any accreditation granted for ISO 42001 certification was granted without a common, internationally agreed, AI-specific criteria document. Different accreditation bodies applied different supplementary requirements, or none.
- After 7 July 2025, a shared criteria document exists, and accreditation bodies have been moving their AI management system programmes onto it.
- Throughout both periods, certification bodies with no accreditation at all have also been issuing ISO 42001 certificates. This is the category that matters most to a buyer, and it is unaffected by the 42006 timeline.
That last category is the real exposure. An unaccredited certificate is not fraudulent — a body may genuinely have audited the organisation competently — but it has no external validation of the auditor and no standing under the international mutual-recognition arrangements that make certificates portable across borders. One compliance publisher tracking this market puts it bluntly: for an unaccredited certificate, “no accreditation body backs it, the IAF multilateral arrangement doesn’t recognise it, and enterprise vendor assessments increasingly reject it.”
A note on the recognition arrangement itself
Most write-ups on this topic, including the one quoted above, refer to the IAF Multilateral Recognition Arrangement (MLA) — the arrangement under which accredited certificates are mutually recognised between signatory accreditation bodies. That reference is now out of date. The International Accreditation Forum’s own website states that “IAF ceased operations on 01 January 2026,” and that it has been replaced, together with the International Laboratory Accreditation Cooperation (ILAC), by a single successor organisation, Global Accreditation Cooperation Incorporated, which commenced full operations on 1 January 2026 with its own multilateral recognition arrangement. The mechanism is unchanged — recognition still flows from the accreditation body, not the certification body — but if a vendor or an internal policy document cites the IAF MLA by name in 2026, that is a sign the text has not been reviewed recently.
How to Check an ISO 42001 Certificate
This is the practical payoff, and it takes about five minutes. The certificate itself is not the evidence; the accreditation body’s public register is.
- Read the certificate for two names, not one. A genuinely accredited certificate names the certification body that issued it and carries the accreditation mark or reference number of an accreditation body. If there is only one organisation named anywhere on the document, treat it as unaccredited until proven otherwise.
- Identify the accreditation body. The national accreditation bodies active in AI management system certification include UKAS (United Kingdom), ANAB (United States), RvA (Netherlands), SCC (Canada), JAS-ANZ (Australia and New Zealand), SAC (Singapore) and IAS (United States).
- Search that body’s public register for the certification body. Each publishes a searchable directory of the organisations it accredits. The RvA, for example, publishes an “All accreditations” register covering every accredited organisation and its scope.
- Check the scope, not just the listing. This is the step that gets skipped, and it is the step that matters. A certification body may be accredited for ISO 9001 and ISO/IEC 27001 and not for ISO/IEC 42001. Accreditation is granted scope by scope. Confirm that ISO/IEC 42001 specifically appears on the body’s schedule of accreditation.
- Check the dates. Compare the date on the certificate against the date the certification body’s ISO 42001 scope was added to the register. A certificate issued before the body held an accredited AI management system scope was not an accredited certificate at the moment it was issued, whatever the body’s status is today.
Step 5 is where a surprising number of certificates currently in circulation come apart, and it is not a hostile question to ask. Certification bodies that went through accreditation properly are usually happy to point you at their register entry.
The 2024–2026 Accreditation Record
CASRAI could not independently verify a body-by-body accreditation roster this session. UKAS, ANSI and ANAB accreditation pages, and ISO’s own catalogue entry, all returned access errors to automated retrieval. What follows is therefore described as a pattern rather than presented as a verified register, and readers should confirm any individual body against the relevant accreditation register directly.
The most detailed public tally CASRAI located is maintained by the compliance vendor Atoro. This is a single secondary source and CASRAI has not verified its individual entries. Taken as one publisher’s account, it describes a clear shape:
- ANAB moved first and accredited the most bodies. Atoro’s tally has ANAB accrediting its first ISO 42001 certification body in September 2024 — roughly ten months before ISO/IEC 42006 was published — and accumulating the largest roster of any accreditation body through 2025 and into 2026.
- European and UK accreditation bodies followed through late 2025 and into 2026. RvA and UKAS entries in the tally cluster from November 2025 onward, with several well-known certification bodies appearing on both registers.
- The roster is still small. Across all accreditation bodies, the tally names on the order of a dozen or so accredited certification bodies — far fewer than the number of organisations advertising ISO 42001 certification services.
That last point is the one to carry into a vendor conversation. The supply of accredited certification bodies is materially smaller than the supply of ISO 42001 certificates.
The BSI claims, kept separate
Two separate public claims about BSI are frequently merged into one, and they should not be. BSI’s own press release, dated 17 November 2025, announces accreditation by both UKAS and RvA for ISO/IEC 42001 certification, stating that BSI “has become the first Certified Body in the world accredited by the United Kingdom Accreditation Service (UKAS).” Separately, an article published by the British Measurement and Testing Association on 27 January 2026 reports BSI achieving “the world’s first accreditation for the certification of artificial intelligence (AI) management systems” from UKAS, following a UKAS pilot programme.
These are two dates, two months apart, describing overlapping but not identical claims, and CASRAI has not been able to reconcile them against UKAS’s own register. Note also that neither document mentions ISO/IEC 42006 anywhere. Both name ISO/IEC 42001 and ISO/IEC 17021-1 only. Any write-up that attributes a statement about ISO/IEC 42006 to BSI or to UKAS on the strength of these two sources has put words in their mouths.
What we deliberately are not telling you
Secondary write-ups of ISO/IEC 42006 circulate specific clause numbers for its competence and audit-time requirements, and specific minimum auditor credentials — years of IT experience, years of AI experience, education level. CASRAI could not read the standard text this session, and is not reproducing those figures, because a clause number attributed to a 31-page paywalled standard on the strength of a blog post is exactly the kind of claim that propagates uncorrected. One point does appear consistently enough across secondary reporting to be worth noting as secondary reporting: competence under ISO/IEC 42006 is assessed at the level of the audit team rather than the individual auditor, so a body can field a lead auditor with management-system depth alongside an AI specialist without requiring either to be both.
For University Procurement and Sponsored Programs
This has stopped being an abstract standards question for research institutions. University procurement offices, sponsored programs offices and research computing groups are now routinely asking AI vendors for an ISO/IEC 42001 certificate as part of vendor onboarding — and are routinely receiving one without any means of judging it.
The register check above is that means. It converts a checkbox into a verifiable fact, and it costs five minutes per vendor. Three practical recommendations:
- Write the accreditation requirement into the question, not just the certificate requirement. “Provide your ISO/IEC 42001 certificate” and “provide your ISO/IEC 42001 certificate and the accreditation body register entry for the issuing certification body’s ISO/IEC 42001 scope” produce very different response quality.
- Do not treat an unaccredited certificate as automatically disqualifying. Treat it as unverified. It may warrant additional diligence rather than rejection, particularly for a small vendor or a newly certified one — a judgement that fits within a broader framework for assessing third-party AI vendor risk.
- Remember what the certificate covers. ISO/IEC 42001 certifies a management system, within a scope the organisation defines. Even a perfectly accredited certificate says nothing about whether the specific model your researchers will use has been evaluated. The scope statement on the certificate is as important as the accreditation behind it.
The same accreditation question runs through the wider AI assurance market, including the conformity assessment and audit ecosystem covered in our overview of third-party AI auditing and who performs it.
The Same Problem, Unsolved, in Frontier AI Safety
ISO/IEC 42006 answers a question that frontier AI safety has not answered at all: who is qualified to check, and who decides that they are?
In management system certification, the answer is institutional. A certification body cannot self-declare competence; an accreditation body assesses it against a published criteria document, publishes the result on a register, and can withdraw it. Independence is not a claim the auditor makes about itself — it is a status conferred and monitored externally.
In frontier AI, when a laboratory commissions an external evaluation of a model or of its own safety framework compliance, there is no equivalent. No accreditation body assesses frontier model evaluators. No published criteria document defines evaluator competence. No register records who holds what scope, and nothing can be withdrawn.
NIKOLAI, CASRAI’s independent frontier AI safety dictionary, defines two elements on track N8 (Transparency and review) that name this gap directly. External review defines the documented assessment of a model, risk report, safeguard or framework compliance carried out by an independent party outside the developer. Evaluator independence and conflict of interest defines a documentation system for recording the financial, organisational and personal relationships between an evaluator and the developer under evaluation, together with the independence assessment used to authorise the engagement.
That second element is, in effect, a proposal to do by disclosure what accreditation does by assessment. It is worth being precise about NIKOLAI’s status here: it is CASRAI’s own independent dictionary, and it is unendorsed. Crosswalk rows on NIKOLAI element pages are shadow mappings — CASRAI’s own reading of published documents — unless an organisation has filed a Mapping Declaration. No laboratory, evaluator or regulator has endorsed the parallel drawn in this section. It is an observation, not a standard.
The observation is still worth making. The conformity assessment world spent decades building the machinery that turns “we are independent” into a checkable fact, and ISO/IEC 42006 is the most recent brick in it. Frontier AI evaluation is being asked to carry comparable weight with none of that machinery in place. Our guide to evaluator independence in the AI safety ecosystem examines that deficit in its own terms.
The Bottom Line
ISO/IEC 42006:2025 is a 31-page supplement to ISO/IEC 17021-1, published on 7 July 2025 by ISO/IEC JTC 1/SC 42, that tells accreditation bodies how to assess the certification bodies issuing ISO/IEC 42001 certificates. Nobody gets certified against it. Its practical significance to a buyer is indirect but real: it is the reason a common standard for AI management system auditors now exists, and the reason the question “which accreditation body, and is ISO/IEC 42001 on their scope?” has a checkable answer.
Ask that question before the certificate goes in the file.
Sources and Verification Status
- Verified directly: ISO/IEC 42006:2025 designation, title, publication date, edition, page count, committee and scope, from the IEC Webstore catalogue entry (publication 108460).
- Verified directly: the cessation of IAF operations on 1 January 2026 and its replacement by Global Accreditation Cooperation Incorporated, from the International Accreditation Forum’s own website.
- Verified directly: BSI’s 17 November 2025 press release, and the British Measurement and Testing Association article of 27 January 2026. Neither names ISO/IEC 42006.
- Single secondary source, unverified: the body-by-body accreditation roster and the quoted characterisation of unaccredited certificates, from a tally published by Atoro.
- Not obtainable this session: ISO’s own catalogue entry, the ANSI webstore, and the UKAS, ANAB and SCC accreditation pages all returned access errors. Clause numbers and individual auditor credential thresholds circulating in secondary write-ups have been deliberately omitted for that reason.








