ISO/IEC 42006

ISO/IEC 42006 is the standard that almost no one outside the certification industry has heard of, and that determines whether an ISO/IEC 42001 certificate is worth anything. The asymmetry between its visibility and its operational weight is what makes it…

Executive summary

ISO/IEC 42006 is the standard that almost no one outside the certification industry has heard of, and that determines whether an ISO/IEC 42001 certificate is worth anything. The asymmetry between its visibility and its operational weight is what makes it interesting.

The dominant narrative on AI certification focuses on the standard being certified — ISO/IEC 42001. Organisations preparing for certification ask what controls they need, what documentation they need, what audit cycle they will face. They rarely ask what makes the certificate they receive credible. ISO/IEC 42006 is the answer to that question. It defines the requirements that certification bodies themselves must meet to issue ISO/IEC 42001 certificates that are recognised by accreditation bodies, by other certification bodies under peer assessment, and by international recognition arrangements.

This distinction matters because certification is not a service. It is a market with infrastructure. The certificate that a certification body issues to an organisation is only worth something because of what stands behind the certification body: an accreditation body that has authorised it to operate, a peer assessment system that verifies its consistency with other certification bodies, and the international recognition arrangement (IAF MLA) that allows certificates issued under one accreditation body to be recognised under others. Without that infrastructure, an ISO/IEC 42001 certificate is a private opinion. With it, the certificate has international legal and commercial standing. ISO/IEC 42006 is the technical specification that allows the infrastructure to operate consistently.

The standard supplements ISO/IEC 17021-1, the general standard that specifies requirements for bodies providing audit and certification of management systems (any management system: information security, quality, environment, energy, AI). ISO/IEC 17021-1 covers competence, impartiality, audit programmes, certification decisions, documentation, complaints handling, and similar process requirements that apply across all management system certifications. ISO/IEC 42006 adds the AI-specific requirements that ISO/IEC 17021-1 does not cover: how to evaluate auditor competence in AI domains, how to calculate audit duration for AI management systems, how to manage impartiality in engagements where the certification body or its personnel may have AI consulting or development activities, how to handle scope when an organisation operates AI systems with significantly different risk profiles.

The standard also has a feature that distinguishes it from most of the rest of the AI governance ecosystem: it is prescriptive about who is qualified to operate. ISO/IEC 42001 lets organisations select which controls apply, modify them, or exclude them with justification. The NIST AI RMF lets organisations choose how to operationalise the four functions. ISO/IEC 42006 does not give certification bodies that latitude. Auditor competence requirements are not optional. Audit duration calculation is not optional. The impartiality safeguards are not optional. A certification body that does not meet these requirements does not get accredited; an accredited body that fails to maintain them gets its accreditation suspended or withdrawn. The standard is the operational specification for an industry, and it is enforced by the accreditation system.

What ISO/IEC 42006 actually does, then, is not “set requirements for certification bodies” in the abstract. It builds the credibility infrastructure that makes the entire ISO/IEC 42001 ecosystem operational. Without ISO/IEC 42006, accreditation bodies could not consistently evaluate certification bodies. Without consistent accreditation, certificates would not be mutually recognised. Without mutual recognition, the international market for AI management system certificates would collapse into national silos. The standard is the substrate that allows the market to exist.

Its publication in July 2025 — some twenty months after ISO/IEC 42001 — is itself structurally significant. Between December 2023 and July 2025, accreditation bodies operated provisional accreditation programmes for ISO/IEC 42001 (notably ANAB, which launched its programme in January 2024) using ISO/IEC 17021-1 plus interim AI-specific requirements developed by each accreditation body. The publication of ISO/IEC 42006 consolidated those provisional approaches into a single international specification, which is what is now being adopted by accreditation bodies globally as the criteria document for ISO/IEC 42001 certification accreditation.

Obligations

ISO/IEC 42006 obligations apply to certification bodies. They operate in five operational areas, each adding AI-specific requirements on top of ISO/IEC 17021-1.

Auditor competence

The standard requires certification bodies to maintain a defined set of competencies for auditors performing ISO/IEC 42001 audits. These competencies extend beyond general management system audit competence (covered in ISO/IEC 17021-1) to include specific knowledge of AI concepts, AI lifecycle stages, AI risk sources, AI-specific control implementation, and the technical standards that surround ISO/IEC 42001 (ISO/IEC 22989, ISO/IEC 23053 for ML systems, ISO/IEC 23894 for risk management methodology, ISO/IEC 42005 for impact assessment).

The standard also requires certification bodies to maintain sectoral competence for sectors with material AI deployment: financial services, healthcare, employment, public sector, and others where AI risk profiles differ materially. An auditor performing an ISO/IEC 42001 audit in a financial services context needs to understand both the AI management system requirements and the sectoral risk context that shapes how those requirements are operationalised.

Competence is demonstrated through documented qualifications, training, supervised audits, and ongoing competence maintenance. Certification bodies maintain auditor competence registers and are required to evidence them during accreditation assessment.

Audit duration methodology

ISO/IEC 42006 specifies the methodology for calculating audit duration. The standard adopts what is referred to as Model B, a methodology based on organisational complexity, scope, and AI risk profile. The calculation produces minimum audit durations for Stage 1 audit, Stage 2 audit, surveillance audits, and recertification audits.

The Model B calculation considers: the size of the organisation in scope (number of employees and locations involved in the AI management system), the number and complexity of AI systems within the scope, the categories of AI risk that apply (drawn from ISO/IEC 23894 Annex B and the AI-related objectives of ISO/IEC 23894 Annex A), the maturity of the management system, and the integration with other certified management systems (ISO/IEC 27001 in particular, where integration can reduce certain duration components).

The consequence of this methodology is that audit duration is not negotiable in the way clients sometimes expect. A certification body cannot legitimately offer a shorter audit than Model B requires; doing so would be a nonconformity in its accreditation assessment. This is the standard’s principal protection against a race to the bottom in audit pricing, which would erode the credibility of certificates over time.

Impartiality safeguards

ISO/IEC 17021-1 already imposes impartiality requirements on management system certification bodies. ISO/IEC 42006 extends these for the AI context, where impartiality risks have specific shapes. The most important of these safeguards relate to:

  • Consulting versus certification activities. A certification body that also provides AI consulting (gap assessments, implementation support, training) must maintain operational and personnel separation between the consulting and certification arms. Auditors who certify a client cannot also have provided consulting to that client within defined cooling-off periods.
  • AI development versus certification. A certification body whose group operates AI systems that compete with or could be benchmarked against those of certification clients faces structural impartiality risks that must be managed and disclosed.
  • Personnel ownership and economic interests. Auditors and certification decision-makers cannot have ownership or material economic interests in clients they audit or certify.
  • Marketing and certification decision separation. Marketing personnel of certification bodies cannot influence certification decisions, which must be made by qualified personnel independent of commercial pressures.

The standard requires certification bodies to maintain a documented impartiality risk assessment and an impartiality committee that oversees the management of those risks. The committee must include external members who are not employees of the certification body.

Audit programme and certification cycle

The standard specifies how the certification cycle operates: Stage 1 audit (documentation review, readiness assessment, scope confirmation), Stage 2 audit (implementation audit, evidence sampling, finding generation), certification decision by qualified decision-maker independent of the audit team, certificate issuance with a three-year validity, two annual surveillance audits in years one and two, and a recertification audit in year three that revisits the full management system rather than only changes since the last audit.

The standard also covers special audit situations: scope extensions, scope reductions, transfers of certification between certification bodies, special audits triggered by significant changes or incidents, and suspension or withdrawal of certification when nonconformities cannot be resolved.

Certification documentation and use

The standard specifies the content of certification documents (the certificate itself, the audit report structure, the nonconformity reporting format) and the rules under which certified clients can use the certification mark and reference their certification status. Misuse of certification marks (claiming certification beyond actual scope, displaying expired certificates, using the mark to imply endorsement of products rather than the management system) triggers contractual remedies and, in serious cases, certificate withdrawal.

Timeline / Implementation

ISO/IEC 42006 has a publication calendar rather than a statutory implementation calendar:

  • December 2023 — ISO/IEC 42001 published. Certification bodies begin operating provisional accreditation programmes using ISO/IEC 17021-1 plus interim AI-specific requirements developed by accreditation bodies.
  • January 2024 — ANAB launches its ISO/IEC 42001 accreditation programme using interim criteria.
  • 2024–2025 — ISO/IEC 42006 progresses through its final development stages as a draft International Standard.
  • July 2025ISO/IEC 42006:2025 published. The standard becomes the criteria document for accreditation under ISO/IEC 42001.
  • July 2025–2026 — Accreditation bodies (ANAB, UKAS, ENAC, RvA, DAkkS, JAS-ANZ) transition their ISO/IEC 42001 accreditation programmes to operate under ISO/IEC 42006 criteria. Existing accredited certification bodies undergo transition assessments to confirm conformance.
  • 2026 onwards — ISO/IEC 42006 is the operative criteria document. New certification body applications are evaluated against it. Surveillance assessments of existing accredited bodies use it. IAF MD documents are developed to harmonise interpretation across signatory accreditation bodies.
  • Future review. Subject to ISO systematic review every five years. First review expected around 2030.

For organisations seeking ISO/IEC 42001 certification, the operational implication is that any reputable certification body should now be operating under ISO/IEC 42006 conformance. Procurement processes that select certification bodies should include verification of accreditation status and confirmation that the accreditation is current under ISO/IEC 42006 criteria.

How Zertia covers it

ISO/IEC 42006 is enforced through the international accreditation system rather than through direct regulatory authority.

ISO/IEC JTC 1/SC 42 (with JTC 1/SC 1 on conformity assessment). The technical committee responsible for ISO/IEC 42006 maintains the standard. Because ISO/IEC 42006 sits at the intersection of AI standardisation and conformity assessment, its development involves coordination with the broader ISO conformity assessment community.

Accreditation bodies as the principal enforcers. ANAB, UKAS, ENAC, RvA, DAkkS, JAS-ANZ and other national accreditation bodies use ISO/IEC 42006 as the criteria document when assessing certification bodies for accreditation in ISO/IEC 42001. An accreditation body that authorises a certification body to issue ISO/IEC 42001 certificates verifies, during initial assessment and on continuing surveillance, that the certification body meets ISO/IEC 42006 requirements. Failure to meet requirements results in nonconformities that, if not closed, lead to suspension or withdrawal of accreditation.

International Accreditation Forum (IAF). The IAF maintains the Multilateral Recognition Arrangement that provides international recognition of certificates issued by certification bodies accredited by IAF MLA signatory accreditation bodies. The IAF also publishes mandatory documents (IAF MD series) that provide consistent interpretation of standards across signatory accreditation bodies. As ISO/IEC 42006 implementation deepens, IAF MD documents are being developed to harmonise interpretation across accreditation bodies, ensuring that an ISO/IEC 42001 certificate issued under ANAB accreditation is recognised consistently with one issued under UKAS or ENAC.

Peer assessment. Accreditation bodies conduct peer assessments of each other under the IAF MLA. These peer assessments verify that accreditation practice is consistent across signatories. Inconsistencies in how ISO/IEC 42006 is interpreted by different accreditation bodies surface in peer assessments and trigger harmonisation work through the IAF.

The role of certification scheme committees. For AI product or service certification schemes built under ISO/IEC 17065, ISO/IEC 42006 can be used as a criteria document. Schemes such as AIUC-1 incorporate ISO/IEC 42006 elements where management system audit components are part of the scheme.

Regulation you understand is regulation you can turn into competitive advantage.

Not sure if this framework applies to your organization? Talk to us.