ISO 42006 Raises the Bar for ISO 42001 Certifiers

ISO 42006 raises certification requirements for ISO 42001 certifiers, illustrated with AI governance documents, audit checklists, a magnifying glass, certificate, calendar, and approval stamp.

Updated:

September 13, 2026

Table of Contents

    ISO 42006:2025 is tightening the rules for organizations that audit and certify ISO 42001 Artificial Intelligence Management Systems, adding AI-specific competence requirements, structured audit-time calculations and stronger expectations for certification decisions. 

    Published on July 7, 2025, the standard is now moving into accreditation programs during 2026 as demand for credible AI certification grows.

    ISO 42006 strengthens ISO 42001 certification by applying requirements to certification bodies, requiring AI expertise and risk-based audit time, with accreditation bodies adopting it during 2026.
    ISO 42006 Raises the Bar for ISO 42001 Certifiers (2)

    The change affects certification bodies rather than companies seeking ISO 42001 certification directly. ISO 42001 defines the AI management system an organization must operate, while ISO 42006 sets additional requirements for the third parties that audit and certify those systems. 

    Accreditation bodies in the United States, United Kingdom, Europe and other markets are now incorporating the newer standard into their AIMS accreditation frameworks.

    What Is ISO 42006 And Why Does It Matter For ISO 42001 Certification?

    ISO 42006 is the international standard for bodies that audit and certify Artificial Intelligence Management Systems against ISO 42001. 

    It supplements ISO 17021-1 with AI-specific rules designed to demonstrate that certification bodies have the competence, consistency and reliability needed to perform credible third-party AIMS certification.

    ISO 42006 sets AI-specific requirements for credible and consistent ISO 42001 certification, illustrated with an AI chip, configuration controls, and approval checkmark.
    What Is ISO 42006

    ISO published ISO 42001:2023 on December 18, 2023 as the first international management system standard specifically for AI. 

    It requires organizations to establish, implement, maintain and continually improve an AIMS covering AI risks, governance and organizational controls.

    ISO 42006 addresses the other side of that relationship. It defines additional expectations for the certification organization assessing whether the AIMS actually meets ISO 42001 requirements.

    That distinction has become more important as ISO 42001 moves from an AI standard into a vendor assurance requirement. Enterprise customers increasingly depend on certificates when evaluating AI suppliers, which raises the importance of who performed the audit and how the certification body demonstrated competence.

    ISO says ISO 42006 is intended to increase consistency and confidence in AIMS certification while giving customers more information about how certification was granted.

    When Did ISO 42006 Become Part Of The ISO 42001 Certification System?

    ISO 42006 became an International Standard on July 7, 2025, after development began in 2023 and the final draft completed formal approval in April 2025. Accreditation activity for ISO 42001 had already started before publication, meaning some early certification programs were built against draft requirements and the existing ISO 17021-1 framework.

    Schellman announced on September 24, 2024 that it had become the first certification body accredited by ANAB for ISO 42001, almost 10 months before final ISO 42006 publication.

    The Dutch accreditation body RvA accredited BSI for ISO 42001 certification in December 2024, placing an accredited AIMS certifier in the European market seven months before the standard reached final publication.

    The standards infrastructure then matured quickly.

    The European co-operation for Accreditation voted on November 20, 2025 to make ISO 42006:2025 the mandatory Level 4 standard for accrediting management-system certification bodies that certify AIMS. The decision was announced after its General Assembly meeting in Vienna.

    UKAS granted BSI its first accreditation for ISO 42001 certification on January 15, 2026, following an AIMS accreditation pilot involving several certification bodies.

    ANAB now lists ISO 42006:2025 alongside ISO 17021-1 and ISO 42001 as part of its accreditation requirements for AIMS certification bodies.

    What Competence Does ISO 42006 Require From ISO 42001 Auditors?

    ISO 42006 requires AIMS certification bodies to demonstrate that audit teams possess knowledge spanning artificial intelligence, management systems, auditing, AI governance and the technical activities within the certification scope. The standard focuses on collective audit-team competence rather than assuming a conventional management-system auditor can evaluate every AI environment without specialist expertise.

    ISO 42001 auditor skills include AI technologies, Annex A controls, AI governance, relevant laws, technical knowledge, and auditing practices, shown beside an auditor holding a tablet.
    What Skills Must ISO 42001 Auditors Have

    Auditors need sufficient understanding of ISO 42001 and the other normative documents involved in certification. Audit teams collectively need knowledge covering the controls in ISO 42001 Annex A and how those controls are implemented.

    The competence requirements extend into AI concepts and lifecycle processes. Certification personnel may need knowledge of AI technologies, governance structures, management practices, monitoring methods and the technical environment being assessed.

    Legal knowledge receives specific attention as well. Audit teams need awareness of legal obligations relevant to AI within the certification scope, while personnel responsible for application review and certification decisions need corresponding competence.

    Sector knowledge matters where the client’s AI operates in specialized environments. Auditors may need to understand industry-specific terminology, risks, practices, software development processes and trustworthy-AI expectations.

    The requirement fits the broader move toward formal AI governance under ISO 42001, where an audit may need to test more than the existence of policies. Organizations increasingly maintain AI inventories, impact assessments, governance roles, supplier records and lifecycle evidence that require technical and organizational interpretation.

    How Does ISO 42006 Change ISO 42001 Audit Time?

    ISO 42006 introduces a structured method for calculating AIMS audit duration rather than allowing certification bodies to base audit time solely on conventional organization size. The starting point considers personnel involved in the AI lifecycle, while additional factors account for AI system complexity, regulatory exposure, sensitive uses, external relationships and the controls included in scope.

    The standard distinguishes between organizations acting as AI producers, providers or developers, AI users and organizations performing multiple AI roles.

    Audit time must then account for factors including:

    1. Regulatory frameworks within the AIMS scope. Multiple legal or regulatory regimes can increase the effort required to evaluate the management system.
    2. The number of AI systems. Larger AI portfolios can require additional audit work, particularly when different technologies or methods are involved.
    3. High-risk or sensitive AI uses. Systems connected to healthcare, safety, personal rights or similarly sensitive purposes can require greater scrutiny.
    4. Third-party relationships. External AI providers and other agreements within the AIMS scope can increase assessment complexity.
    5. Additional AIMS controls. Controls included in the Statement of Applicability beyond the standard Annex A control set can affect audit duration.

    ISO 42006 states that the calculated audit time should generally be treated as a minimum after applicable adjustment factors are considered. Reasons for deviations need to be documented.

    Planning and report writing should not normally reduce physical or remote client-facing audit activity below 70% of calculated audit time. Recertification audits should generally represent at least two-thirds of the audit time that an equivalent initial certification would require at that point.

    The result is a certification model in which two organizations with similar employee counts can require very different audit effort when their AI portfolios, regulatory exposure or system risks differ substantially.

    How Are Accreditation Bodies Applying ISO 42006 In 2026?

    Accreditation bodies are turning ISO 42006 from a published standard into operational criteria for ISO 42001 certifiers during 2026. ANAB lists the final standard in its AIMS accreditation requirements, European Accreditation has made it mandatory for member accreditation programs, and national bodies are creating transition policies for certification bodies already operating in the market.

    ISO 42006 application in 2026: ANAB uses it for AIMS accreditation, European accreditation made it mandatory, and national bodies are issuing transition policies.
    How Is ISO 42006 Being Applied In 2026

    ANAB continues expanding its ISO 42001 accreditation program. Armanino Certified LLC and ControlCase Assessments hold ANAB accreditation for ISO/IEC 42001, with the ControlCase grant effective August 13, 2026.

    ANAB’s applicant list includes additional certification bodies seeking accreditation, showing that the market is still developing rather than consisting of a fixed group of early providers.

    ANAB is running dedicated training on ISO 42006 for certification-body personnel and accreditation professionals during 2026, another indication that the standard is moving from publication into operational implementation.

    The European co-operation for Accreditation has taken a particularly explicit position. Its November 2025 resolution made ISO 42006 mandatory as the Level 4 standard used when accrediting certification bodies for AIMS.

    India’s National Accreditation Board for Certification Bodies has published a formal transition policy for ISO 42006:2025 during 2026, showing that the transition is extending beyond U.S. and European accreditation markets.

    Does ISO 42006 Make Every ISO 42001 Certificate Accredited?

    ISO 42006 does not automatically make every ISO 42001 certificate an accredited certificate. ISO publishes the standards but does not accredit individual certification bodies.

    Accreditation bodies assess certification organizations against applicable requirements, while companies seeking ISO 42001 certification need to check the accreditation status and scope of the certifier they select.

    ISO explicitly notes that ISO 42006 can be used as a criteria document for accreditation or peer assessment.

    That makes the distinction between certification and accreditation important.

    An organization seeking certification is evaluated against ISO 42001. The certification body itself can be evaluated by an accreditation body against ISO 17021-1, ISO 42006 and the applicable accreditation-program requirements.

    ISO 42006 is therefore not a second certification that the AI company earns. It is part of the assurance infrastructure behind the organization issuing the ISO 42001 certificate.

    What Does ISO 42006 Mean When Choosing An ISO 42001 Certifier?

    Companies selecting an ISO 42001 certification body should now examine more than price and audit availability. ISO 42006 makes auditor competence, accreditation scope, AI expertise and appropriate audit duration central indicators of certification quality, giving procurement teams more concrete criteria for distinguishing a credible AIMS audit from a lightly documented certification exercise.

    Organizations can check several attributes before signing an engagement:

    1. Confirm the certification body’s accreditation. Verify the accreditation body and whether ISO/IEC 42001 appears within the current accredited scope.
    2. Ask which certification criteria apply. Determine whether the certification program is operating against final ISO 42006:2025 requirements.
    3. Review proposed audit-team competence. The team should collectively understand the AI technologies, organizational roles, legal context and industry involved in the AIMS scope.
    4. Examine audit-time calculations. A very short audit should be explainable against personnel, AI systems, sensitive uses, regulatory frameworks and supplier complexity.
    5. Check certification independence. The organization performing certification needs to maintain the impartiality expected of third-party management-system certification.
    6. Review the certificate scope carefully. Certification applies to the defined AIMS scope and should not be interpreted as proof that every AI product or model operated by the company has been independently certified as safe.

    This scrutiny becomes more important as ISO 42001 certification becomes part of vendor reviews. Procurement teams need confidence in both the organization holding the certificate and the conformity-assessment process behind it.

    Does ISO 42006 Change ISO 42001 Requirements For Certified Companies?

    ISO 42006 does not rewrite the requirements organizations must meet under ISO 42001. ISO 42001 remains the management-system standard for companies developing, providing or using AI, while ISO 42006 governs the competence and operation of certification bodies performing the third-party audit and certification process.

    Organizations can still experience practical changes during certification.

    A certification body applying ISO 42006 may ask more detailed questions during application review so it can determine the required audit competence and duration. Organizations may need clearer information about their AI roles, system inventory, sensitive applications, regulatory obligations, outsourced services and Statement of Applicability.

    A more technically capable audit team may examine the implementation of AI controls with greater depth. That can place additional pressure on organizations whose AIMS documentation is mature but whose operational evidence remains incomplete.

    Companies preparing for ISO 42001 compliance therefore need evidence that governance processes operate in practice, rather than preparing only policies for the certification audit.

    How Does ISO 42006 Connect To EU AI Act Readiness?

    ISO 42006 can improve confidence in ISO 42001 certification used during EU AI Act preparation, but it does not turn an ISO certificate into proof of legal compliance. The standard governs the quality of AIMS certification, while the EU AI Act imposes separate obligations based on an organization’s role and the classification of individual AI systems.

    The connection is still commercially important.

    ISO 42001 can organize governance evidence around risk management, documentation, monitoring, human oversight, supplier controls and accountability. Stronger requirements for the certification bodies evaluating those management systems can make the resulting certificate more useful during customer and regulatory due diligence.

    The EU timeline moved during 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026 and deferred high-risk obligations for stand-alone Annex III systems to December 2, 2027. AI embedded in Annex I regulated products moves to August 2, 2028.

    That deferral followed concerns that harmonized standards and conformity-assessment infrastructure would not be ready for the original August 2, 2026 high-risk date. Article 50 transparency obligations apply from August 2, 2026, and Article 50(2) reaches systems already on the market from December 2, 2026. The extra runway gives organizations more time to build the governance evidence an AIMS audit examines.

    European Accreditation’s decision to make ISO 42006 mandatory within AIMS accreditation is especially relevant in this context. It creates a common accreditation requirement as European companies increase their use of management-system evidence alongside AI Act compliance work.

    Companies using ISO 42001 for EU AI Act compliance planning still need separate work for system classification, technical documentation, conformity assessment, transparency and other legal duties that fall outside management-system certification.

    What Should Companies Do Before An ISO 42001 Certification Audit?

    Companies preparing for ISO 42001 certification should expect certification bodies to gather more detailed information about their AI environment as ISO 42006 becomes embedded in accreditation programs. Preparation should cover the actual AIMS scope, AI lifecycle roles, regulatory exposure and operational evidence so the certifier can assign competent auditors and calculate appropriate audit time.

    1. Define the AIMS scope precisely. Record which products, business units, locations, AI systems and organizational roles fall within certification.
    2. Document AI lifecycle roles. Determine whether the organization acts as an AI producer, developer, provider, user or performs multiple roles.
    3. Maintain an accurate AI inventory. Include the systems and third-party AI dependencies that fall within the management-system scope.
    4. Map regulatory obligations. Record the laws and sector requirements affecting AI systems within the AIMS.
    5. Complete the Statement of Applicability. Document which ISO 42001 Annex A controls apply and how they are implemented.
    6. Maintain operational evidence. Keep risk assessments, impact assessments, monitoring records, approvals, supplier reviews, incident records and management reviews current.
    7. Complete the internal audit. Test the AIMS before the certification body performs its external assessment.
    8. Verify the certification body. Confirm its accreditation status, ISO 42001 scope and the criteria used to qualify the proposed audit team.

    What Costs Could ISO 42006 Add To ISO 42001 Certification?

    ISO 42006 can increase certification effort where an organization has numerous AI systems, several regulatory regimes, sensitive AI applications, extensive outsourcing or additional controls.

    The standard provides mechanisms for adding audit time as complexity rises, but ISO has not published a universal price increase or industry-wide cost estimate for ISO 42001 certification under the newer requirements.

    Certification bodies face their own implementation expenses. They may need AI specialists, auditor training, competence evaluation processes, revised audit-time methodology and accreditation assessments.

    Clients can experience those costs indirectly through audit pricing.

    The effect should vary significantly. An organization using a small number of lower-risk AI systems may require much less audit effort than an AI provider operating several high-risk systems under multiple regulatory frameworks.

    The standard therefore ties certification effort more closely to the actual complexity of an organization’s AI environment rather than creating a single flat audit model.

    What Remains Unclear About ISO/IEC 42006 Adoption?

    The main unresolved issue is how consistently ISO 42006 will be implemented across accreditation markets. Major accreditation bodies are incorporating the standard, but transition schedules, accreditation capacity and the number of qualified certification bodies continue to develop during 2026, creating differences in availability between countries and certification providers.

    The market is still young. Early ISO 42001 accreditation existed before ISO 42006 reached final publication, while newer applicants are entering under a more mature conformity-assessment framework.

    Auditor capacity is another question. ISO 42006 expects knowledge spanning AI technology, management systems, legal obligations, industry context and ISO 42001 controls. Certification bodies will need enough qualified personnel to meet growing certification demand without weakening those competence requirements.

    Buyer behavior remains uncertain as well. Accredited ISO/IEC 42001 certification is becoming a stronger assurance signal, but procurement teams still vary in how closely they verify accreditation scope, auditor qualifications and certificate boundaries.

    The direction is clearer than the final market structure. ISO 42006 is turning the quality of the certifier into a more visible part of the ISO 42001 assurance decision.

    How Bright Defense Helps Organizations Prepare For ISO 42001 Certification

    Bright Defense helps organizations prepare the governance, security evidence and control documentation needed before an independent certification body performs an ISO 42001 audit.

    The work can include defining AI governance responsibilities, documenting AI systems and suppliers, reviewing security controls, collecting evidence, assessing gaps and preparing for internal audit activity. ISO 42006 makes that preparation increasingly important because certification bodies are expected to assign competent teams and adjust audit effort to the complexity of the AIMS.

    Bright Defense does not issue the ISO 42001 certificate. Certification remains the responsibility of an independent certification body operating under the applicable certification and accreditation requirements.

    Sources Cited In This ISO 42006 Report

    1. ISO — ISO 42006:2025, Information Technology — Artificial Intelligence — Requirements For Bodies Providing Audit And Certification Of Artificial Intelligence Management Systems (July 7, 2025).
    2. IEC — ISO 42006:2025 (July 7, 2025).
    3. ISO — ISO 42001:2023 Artificial Intelligence Management Systems (December 18, 2023).
    4. European co-operation for Accreditation — Highlights Of The 59th General Assembly (November 27, 2025).
    5. European co-operation for Accreditation — Resolution 2025 (59) 06 On Mandatory Application Of ISO 42006:2025 (November 20, 2025).
    6. UKAS — UKAS Grants First Accreditation For Artificial Intelligence Management Systems (January 15, 2026).
    7. BSI — RvA Accreditation For ISO/IEC 42001 Certification (December 2024).
    8. ANAB — ISO 42001 Artificial Intelligence Management Systems Accreditation Requirements (2026).
    9. ANAB — Applicants For Management Systems Accreditation (2026).
    10. ControlCase — ControlCase Announces ISO/IEC 42001 Accreditation For AI Management Systems (August 13, 2026).
    11. Business Wire — Armanino Achieves ISO 42001 Accreditation (December 2025).
    12. NABCB — Policy On Transition To ISO 42006:2025 For AIMS (2026).
    13. Official Journal Of The European Union — Regulation (EU) 2026/1744, Digital Omnibus On AI (July 24, 2026).
    14. ICAEW — New Standard For Firms Certifying AI Management Systems (August 1, 2025).
    15. BSI — BS ISO 42006:2025 Requirements For Bodies That Audit And Certify AI Management Systems (July 31, 2025).
    16. Schellman — Schellman Becomes First ISO 42001 ANAB Accredited Certification Body (September 24, 2024, updated June 4, 2026).

    Tamzid is a cybersecurity researcher with 5+ years of experience across SaaS, security, compliance, and blockchain. Certified through Cisco, Fortinet (NSE 1), and the Basel Institute on Governance in OSINT, he grounds his security and compliance writing in primary sources and verified data.

    Get In Touch

      Group 1298 (1)-min