ISO AI Management System Certification Requirements

ISO/IEC 42006:2025 — Information technology — Artificial intelligence — Requirements for bodies providing audit and certification of artificial intelligence management systems

ISO

RAI-XS-GO-MANAGEM-2025
Effective: July 7, 2025
In Force(In Force)
StandardGovernance and OversightRisk ManagementSafety, Testing, and Evaluation
Export PDF

This international standard sets requirements for bodies auditing and certifying AI Management Systems, ensuring credible and consistent assessments of AI governance.

Overview

ISO/IEC 42006:2025 is a crucial international standard that establishes specific requirements for bodies engaged in the auditing and certification of Artificial Intelligence Management Systems (AIMS). This document plays a pivotal role in the broader landscape of AI governance by ensuring that the organizations responsible for assessing AI systems operate with the highest levels of competence, consistency, and impartiality. Its primary purpose is to provide a robust framework that underpins the credibility and reliability of AI management system certifications, thereby fostering trust among customers, stakeholders, and regulators in the responsible development and deployment of AI technologies. The standard is an essential companion to ISO/IEC 42001:2023, which outlines the requirements for an AI management system itself, and builds upon the foundational principles of ISO/IEC 17021-1, the general requirements for bodies providing audit and certification of management systems.

The significance of ISO/IEC 42006:2025 lies in its direct contribution to mitigating the unique challenges posed by AI, such as concerns around ethics, data quality, algorithmic bias, and transparency. By setting clear criteria for certification bodies, it ensures that auditors possess the specialized knowledge and skills necessary to conduct thorough and credible assessments of AI systems and their associated management processes. This, in turn, provides assurance that organizations achieving ISO/IEC 42001 certification have indeed implemented effective controls and practices for managing AI-related risks and opportunities. The standard's introduction reflects the growing global recognition of the need for structured governance in AI to balance innovation with accountability and societal well-being.

Definitions

For the purposes of ISO/IEC 42006:2025, several key terms and definitions are referenced from other foundational standards to ensure consistency and clarity across the ISO/IEC framework. The document explicitly refers to terms and definitions provided in ISO/IEC 17000 (Conformity assessment – Vocabulary and general principles), ISO/IEC 17021-1 (Conformity assessment – Requirements for bodies providing audit and certification of management systems – Part 1: Requirements), ISO/IEC 42001 (Information technology – Artificial intelligence – Management system), and ISO/IEC 22989 (Artificial intelligence – Concepts and terminology). These normative references establish a common understanding of critical concepts such as "Artificial Intelligence Management System (AIMS)," which refers to a set of interrelated or interacting elements of an organization intended to establish policies and objectives, and processes to achieve those objectives, in relation to the responsible development, provision, or use of AI systems.

Furthermore, the standard defines specific terms relevant to the audit and certification process itself. A "certification body" is an organization that performs audit and certification of management systems, while an "audit" is a systematic, independent, and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled. The concept of "competence" is also central, referring to the ability to apply knowledge and skills to achieve intended results, particularly for auditors assessing AI management systems. These definitions are crucial for ensuring that all parties involved in the certification process – from the certification bodies themselves to the organizations seeking certification – operate with a shared understanding of the requirements and expectations.

Governance and Institutional Framework

The development and oversight of ISO/IEC 42006:2025 fall under the purview of ISO/IEC JTC 1/SC 42, the joint technical committee responsible for standardization in the area of Artificial Intelligence. This committee, established as a collaboration between the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), serves as the focal point for AI standardization within both organizations. Its mandate encompasses the entire AI ecosystem, from foundational AI standards to data standards related to AI, trustworthiness, use cases, governance implications, and testing of AI systems. SC 42's comprehensive program of work ensures that standards like ISO/IEC 42006 are developed with a holistic understanding of AI's complexities and challenges.

ISO/IEC JTC 1/SC 42 operates through a structured framework involving various working groups and ad-hoc groups that bring together global experts from diverse fields, including technology, ethics, law, and business. This collaborative approach ensures that the standards are robust, multidisciplinary, and address a wide range of stakeholder concerns. The committee also organizes workshops and engages in international cooperation to gather insights into emerging trends and technological advancements, informing the strategic planning and road-mapping of its work program. The governance structure ensures that ISO/IEC 42006:2025, like other AI standards, is developed through a consensus-based process, reflecting international best practices and contributing to global compatibility and interoperability of AI systems.

Key Provisions

ISO/IEC 42006:2025 outlines a comprehensive set of requirements for bodies providing audit and certification of Artificial Intelligence Management Systems (AIMS). A central provision is the emphasis on impartiality, requiring certification bodies to maintain independence in all their activities and decisions to ensure trust in the certification process. Conflicts of interest must be identified and rigorously managed to uphold this impartiality. The standard also details stringent requirements for the competence of personnel, particularly auditors, who must possess specialized expertise in AI technologies such as machine learning and data analytics, in addition to general auditing skills. This ensures that assessments are conducted by individuals with a deep understanding of the unique technical and ethical considerations of AI.

Further key provisions include detailed requirements for the audit process itself, covering stages from application review and contract establishment to audit planning, conducting audits, and making certification decisions. Certification bodies must establish and maintain a robust quality management system to ensure consistency and reliability throughout the certification process. The standard also addresses legal and contractual matters, liability, financing, and the management of outsourced activities, ensuring that certification bodies have the necessary structural and resource requirements to operate effectively and credibly. These provisions collectively aim to establish a framework that guarantees the integrity and trustworthiness of AI management system certifications, thereby promoting the responsible deployment of AI worldwide.

Scope and Application

The scope of ISO/IEC 42006:2025 is specifically defined to encompass the requirements for bodies that perform auditing and certification of Artificial Intelligence Management Systems (AIMS). This means the standard primarily applies to certification bodies that offer services to assess organizations implementing AIMS based on ISO/IEC 42001. Beyond certification bodies, the standard is also relevant to accreditation bodies that are responsible for assessing and overseeing these certification bodies, ensuring they meet the high standards set by ISO/IEC 42006:2025. Furthermore, organizations seeking certification of their own AI management systems will find this standard crucial for understanding the criteria against which they will be evaluated.

It is important to note that ISO/IEC 42006:2025 does not replace ISO/IEC 17021-1, which provides general requirements for bodies providing audit and certification of management systems. Instead, it supplements ISO/IEC 17021-1 with additional, AI-specific requirements tailored to the unique challenges and characteristics of AI systems. The standard is designed to be applicable across various industries and applications where AI management systems are implemented, offering a scalable framework for responsible AI governance. Its broad applicability ensures that organizations of all sizes and sectors can benefit from a consistent and credible approach to AI management system certification, enhancing trust in AI technologies globally.

Implementation Framework

For certification bodies to effectively implement ISO/IEC 42006:2025, they must establish and maintain a robust quality management system that ensures consistency, competence, and reliability throughout the entire certification process. This involves developing clear procedures for every stage, from the initial application review to the final certification decision and ongoing surveillance. A critical aspect of implementation is ensuring that auditors possess the necessary expertise in AI technologies, including machine learning and data analytics, to thoroughly assess AI management systems. Certification bodies must have processes in place for the selection, training, and continuous professional development of their auditing personnel to meet these specialized competence requirements.

The implementation framework also necessitates that certification bodies operate in strict accordance with the impartiality requirements outlined in the standard, actively identifying and managing any potential conflicts of interest. This includes maintaining independence from organizations that provide AI consulting services. Furthermore, certification bodies must establish transparent information requirements, ensuring that public information about their operations and certified organizations is readily available to instill confidence and trust. By adhering to these guidelines, certification bodies can not only meet the requirements of ISO/IEC 42006:2025 but also contribute significantly to the trustworthy deployment of AI by providing credible and consistent certification outcomes.

Monitoring and Evaluation

Monitoring and evaluation are integral to the effectiveness and credibility of the AI management system certification process facilitated by ISO/IEC 42006:2025. Accreditation bodies play a vital role in this framework by monitoring the compliance of certification bodies with the requirements of the standard. They evaluate certification bodies to ensure they meet the high standards set for competence, impartiality, and consistency in auditing AI management systems. This oversight by accreditation bodies provides an additional layer of assurance, ensuring that the certifications issued are reliable and globally recognized.

The standard itself, through its provisions, supports robust and consistent auditing of AI-related risks and controls, which inherently includes mechanisms for monitoring the performance of certified AI management systems. While ISO/IEC 42006:2025 primarily focuses on the requirements for the certification bodies, its ultimate goal is to increase transparency and confidence for customers and regulators in the certified organizations. This implies an ongoing cycle of assessment, feedback, and improvement, where the efficacy of the certification process is continuously evaluated against its objective of promoting trustworthy and responsible AI.

Relationship to Other Instruments

ISO/IEC 42006:2025 is not a standalone document but is intricately linked to several other international standards, forming a cohesive framework for AI governance and conformity assessment. Its most direct and crucial relationship is with ISO/IEC 42001:2023, the international management system standard for Artificial Intelligence. While ISO/IEC 42001 specifies the requirements for establishing, implementing, maintaining, and continually improving an AI management system within an organization, ISO/IEC 42006 provides the specific requirements for the bodies that audit and certify these AIMS. Essentially, ISO/IEC 42006 ensures that the certification process for ISO/IEC 42001 is conducted competently and reliably.

Furthermore, ISO/IEC 42006:2025 builds upon and supplements the foundational standard ISO/IEC 17021-1:2015, which outlines the general requirements for bodies providing audit and certification of management systems. This means that certification bodies for AIMS must not only adhere to the general principles of ISO/IEC 17021-1 but also to the additional, AI-specific requirements detailed in ISO/IEC 42006. The standard also draws upon other related AI standards developed by ISO/IEC JTC 1/SC 42, such as ISO/IEC 22989:2022 (Artificial Intelligence – Concepts and Terms) for common terminology, and ISO 23894:2023 (Artificial Intelligence – Risk Management Guide) for understanding AI-related risks. It can also be integrated into broader conformity assessment schemes for AI products, processes, or services certified under ISO/IEC 17065, further demonstrating its role in a comprehensive AI assurance ecosystem.

International Alignment

ISO/IEC 42006:2025 significantly contributes to international alignment in the field of Artificial Intelligence governance by providing a globally recognized standard for the audit and certification of AI management systems. This harmonization is crucial as AI technologies transcend national borders, requiring consistent approaches to ensure their trustworthy and responsible deployment worldwide. By establishing clear and uniform requirements for certification bodies, the standard facilitates mutual recognition of certifications across different countries, thereby reducing barriers to market access for AI solutions and fostering international trade.

The standard's development through ISO/IEC JTC 1/SC 42, a joint committee involving experts from numerous member countries, inherently ensures a broad international perspective and consensus. This collaborative process helps address diverse cultural, regulatory, and technological contexts, leading to standards that are universally applicable and promote interoperability between AI systems globally. The resulting clarity and confidence in AI management system certifications support greater transparency and accountability, aligning international efforts to build trust in AI technologies and promoting a shared understanding of best practices in AI governance.

Implementation Timeline

MilestoneDateStatus
Final Draft International Standard (FDIS) Voting Terminated2025-04-16Completed
Official Publication of ISO/IEC 42006:20252025-07-07Completed
Certification Bodies Begin Developing Accreditation Programs2025-Q3In Progress
First Accreditations of Certification Bodies to ISO/IEC 420062026-Q1Ongoing
Organizations Begin Seeking AIMS Certification to ISO/IEC 42001 via Accredited Bodies2026-Q2Ongoing

Adoption and Endorsement

EntityDateStatus
International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)2025-07-07Adopted

Sources and References

SourceType
ISO/IEC FDIS 42006:2025(en)official
New international standard sets rules for auditing AI management systems - IECofficial
ISO/IEC JTC 1/SC 42 - Artificial intelligenceofficial
ISO/IEC 42001:2023 - Information technology — Artificial intelligence — Management systemofficial
ISO/IEC 17021-1:2015 - Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirementsofficial
Plain English

This international standard sets the ground rules for organizations that audit and certify Artificial Intelligence Management Systems (AIMS), ensuring these critical assessments are conducted competently and impartially. It applies directly to "certification bodies" – the organizations that evaluate whether a company's AI management practices meet the ISO/IEC 42001 standard – and to "accreditation bodies" that oversee these certifiers. Companies looking to get their AI systems certified under ISO/IEC 42001 should also understand this standard, as it dictates the quality and expertise of their auditors.

The standard, officially published on July 7, 2025, requires certification bodies to uphold several key obligations. They must: - Maintain strict impartiality, actively identifying and managing any conflicts of interest to ensure unbiased assessments. - Employ auditors with specialized expertise in AI technologies like machine learning and data analytics, in addition to general auditing skills. - Establish a robust quality management system to ensure consistency and reliability throughout the entire certification process, from application review to final decision. - Provide transparent information about their operations and certified organizations to build public trust.

While ISO/IEC 42006 doesn't carry legal penalties, its enforcement comes from market demand for credible certifications and oversight by accreditation bodies. A certification body that fails to meet these requirements risks losing its accreditation, reputation, and ability to offer valuable ISO/IEC 42001 certifications. A practical pitfall for companies seeking certification is that this standard *adds* AI-specific requirements to existing general auditing rules (ISO/IEC 17021-1). This means simply being an accredited auditor isn't enough; they need demonstrated, specialized AI competence. Organizations should verify their chosen certifier truly understands the unique complexities of AI governance.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under ISO AI Management System Certification Requirements. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalOngoing

    Applies to: Bodies certifying AI Management Systems.

    requiring certification bodies to maintain independence in all their activities and decisions to ensure trust in the certification process.
  2. #2CriticalOngoing

    Applies to: Bodies certifying AI Management Systems.

    Conflicts of interest must be identified and rigorously managed to uphold this impartiality.
  3. #3CriticalOngoing

    Applies to: Bodies certifying AI Management Systems.

    auditors, who must possess specialized expertise in AI technologies such as machine learning and data analytics, in addition to general auditing skills.
  4. #4CriticalOngoing

    Applies to: Bodies certifying AI Management Systems.

    Certification bodies must establish and maintain a robust quality management system to ensure consistency and reliability throughout the certification process.
  5. #5CriticalOngoing

    Applies to: Bodies certifying AI Management Systems.

    Certification bodies must have processes in place for the selection, training, and continuous professional development of their auditing personnel.
  6. #6CriticalOngoing

    Applies to: Bodies certifying AI Management Systems.

    This includes maintaining independence from organizations that provide AI consulting services.
  7. #7CriticalOngoing

    Applies to: Bodies certifying AI Management Systems.

    It supplements ISO/IEC 17021-1 with additional, AI-specific requirements tailored to the unique challenges and characteristics of AI systems.
  8. #8ImportantOngoing

    Applies to: Bodies certifying AI Management Systems.

    detailed requirements for the audit process itself, covering stages from application review and contract establishment to audit planning, conducting audits, and making certification decisions.
  9. #9ImportantOngoing

    Applies to: Bodies certifying AI Management Systems.

    The standard also addresses legal and contractual matters, liability, financing, and the management of outsourced activities.
  10. #10ImportantOngoing

    Applies to: Bodies certifying AI Management Systems.

    certification bodies must establish transparent information requirements, ensuring that public information about their operations and certified organizations is readily available.

© Regulations.AI — created on 12-Jun-2026 using Gemini 2.5 Flash