ISO 42006 Is Now in the Accreditation Rules: How to Vet Your ISO 42001 Certifier Before You Sign
ISO/IEC 42006:2025 sets the rules for the bodies that audit and certify ISO 42001 AI management systems, and during 2026 accreditation bodies have been writing it into their programmes. European Accreditation made it mandatory, ANAB lists it in its AIMS requirements, and UKAS granted its first ISO 42001 accreditation in January. Your certificate is only as credible as the body that issued it, so the certifier is now a procurement decision with real criteria.
Most ISO 42001 projects spend months on the AI management system and about an afternoon choosing who will certify it. That balance is changing. ISO/IEC 42006:2025, published on 7 July 2025, is the standard that governs the bodies that audit and certify AI management systems, and a report from Bright Defense on 4 October 2026 sets out how accreditation bodies have spent this year turning it into operational rules. ISO 42006 does not change what your company must do under ISO 42001. It changes what the certification body must prove about itself, and that gives buyers, customers and your own board a concrete way to tell a credible AIMS audit from a thin one.
The adoption timeline is worth knowing because it explains why certificates in the market are uneven. Schellman became the first ANAB accredited ISO 42001 certification body on 24 September 2024, and the Dutch accreditation body RvA accredited BSI in December 2024, both before ISO 42006 existed as a final standard. The European co-operation for Accreditation then voted on 20 November 2025 to make ISO 42006 the mandatory Level 4 standard for accrediting AIMS certification bodies. UKAS granted BSI its first ISO 42001 accreditation on 15 January 2026 after a pilot, ANAB now lists ISO 42006 next to ISO 17021-1 and ISO 42001 in its AIMS requirements, ControlCase received ANAB accreditation effective 13 August 2026, and India has published a formal transition policy. In other words, some early certificates were issued under draft criteria, and some certifiers on the market are not accredited for ISO 42001 at all.
The first thing ISO 42006 tightens is competence. The audit team, taken together, must understand ISO 42001 and its Annex A controls, AI technologies and lifecycle processes, AI governance and monitoring, the legal obligations that apply to AI inside the certification scope, and the sector the client operates in. The people who review your application and make the certification decision need matching competence, not just the auditors on site. In practice this ends the assumption that any experienced ISO 27001 lead auditor can pick up an AIMS audit with a weekend of reading. If your AI scope includes a voice agent, a coding agent built on Claude Code or Cursor, or a scoring model used in hiring, you should expect the certifier to name someone who understands that kind of system.
The second change is audit time. ISO 42006 replaces a simple headcount table with a method that starts from the number of people involved in the AI lifecycle, then adds time for system complexity, regulatory exposure, sensitive uses, external relationships and any controls in your Statement of Applicability beyond the standard Annex A set. Planning and report writing should not normally cut client facing audit activity below 70 percent of the calculated time, and recertification should generally take at least two thirds of what an equivalent initial audit would need. A quote that looks remarkably cheap and short is therefore a question, not a bargain. Ask the certifier to show the calculation and explain each input.
Here is a short vetting list to run before you sign an engagement letter. Confirm the accreditation body by name and check that ISO/IEC 42001 sits inside the current accredited scope, using the register of ANAB, UKAS or your national body rather than a logo on a sales deck. Ask whether the programme operates against the final ISO 42006:2025 requirements and, if the body was accredited earlier, what its transition plan is. Request the proposed audit team and a short note on how their collective competence covers your AI systems, legal context and industry. Ask for the audit time calculation. Ask who makes the certification decision and what AI competence that person has. None of these questions is unusual, and a credible certifier will answer all of them in writing.
Expect the application stage to ask more of you, too. Because audit time and team competence now depend on your AI environment, a certifier applying ISO 42006 will want a clear AI system inventory, the roles your organisation plays for each system, the sensitive uses, the regulations in scope, outsourced AI services and your Statement of Applicability. If you already run ISO 42001 work through Vanta, Drata, Secureframe or Sprinto, export the AI inventory and supplier records from the platform rather than rebuilding them in a spreadsheet, and make sure the vendor list includes the model providers and AI tools your teams actually use, such as ChatGPT, Claude, ElevenLabs and any agent platform in production. Our ISO 42001 guide and the policy templates section cover the documents most certifiers will ask to see.
There is a European angle that makes this more than a quality question. The Digital Omnibus on AI, Regulation (EU) 2026/1744, deferred the high risk dates of the EU AI Act, but Article 50 transparency obligations have applied since 2 August 2026 and Article 50(2) reaches systems already on the market from 2 December 2026. An ISO 42001 certificate is not a presumption of conformity with the AI Act, yet buyers in Europe increasingly read it as evidence of mature governance, and European Accreditation has now made ISO 42006 the common baseline for how those certificates are issued. A certificate from a body without accredited ISO 42001 scope will carry less weight in exactly the procurement conversations where you hoped it would help.
For teams that already hold ISO 27001 or SOC 2, the lesson is familiar. A SOC 2 report is only as useful as the CPA firm behind it, and an ISO 27001 certificate from an unaccredited mill is a known red flag in vendor reviews. ISO 42001 is reaching the same stage, and ISO 42006 is what lets a customer separate the two. When you review an AI vendor yourself, apply the same test in reverse: ask who issued their ISO 42001 certificate, under which accreditation body, and whether the scope on the certificate actually covers the product you are buying.
A practical plan for this month. If you are choosing a certifier, run the vetting list above and keep the answers as evidence for your own supplier file. If you are already certified, check whether your certifier is accredited for ISO 42001 and when it moves to final ISO 42006 criteria, because your next surveillance or recertification audit may be longer and more technical than the last. And if a customer has asked for your ISO 42001 status, give them the accreditation body and scope along with the certificate number. It is a small step that answers the question a careful buyer is about to ask.
Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.
Get the next post by email
One short email when something worth knowing ships. No spam, unsubscribe anytime.
Comments
Moderation policyLoading comments...
Add a comment
Corrections and first-hand experience are the most useful things you can leave. Comments are screened automatically and reviewed by a human; see the moderation policy.