AI Regulation Tracker / Standards and assurance
ISO 42006 Sets the Rules for Who Gets to Certify Your AI Management System
Published July 7, 2025, ISO/IEC 42006:2025 is the standard that certification bodies have to meet before they can audit and certify an organization to ISO/IEC 42001. It is what turns a 42001 certificate from a logo into something a procurement team can actually trust.
Most of the attention in AI governance goes to ISO/IEC 42001, the standard an organization gets certified against for running an AI management system. Fair enough, that is the certificate people want on the wall. But a certificate is only as good as the body that issued it, and until recently there was no purpose-built standard governing those bodies for AI. That gap is what ISO/IEC 42006:2025 fills. It was published on July 7, 2025, and it is the rulebook for the certifiers themselves.
Here is how ISO describes it in the standard's own abstract. ISO/IEC 42006:2025 "specifies additional requirements to ISO/IEC 17021-1" and, when implemented, "supports the demonstration of competence, consistency and reliability by bodies performing auditing and certification of an artificial intelligence management system (AIMS) according to ISO/IEC 42001." Read that plainly. ISO/IEC 17021-1 is the general standard for any body that certifies management systems. 42006 does not replace it. It sits on top of it and adds the AI-specific requirements that a generic certification standard was never written to cover.
What it actually requires of a certifier
The substance of 42006 is about competence, staffing, and conduct. On competence, the standard works at the level of the audit team rather than the individual. The point is that the team as a whole has to cover the scope of the AI management system it is auditing, and collectively understand the controls in Annex A of ISO/IEC 42001 and how an organization would actually implement them. One analysis of the standard puts the practical effect this way: the certifier can field "a lead auditor with management-system experience, an AI specialist, and a domain expert" rather than pretending a single generalist can competently judge an AI estate.
Beyond competence, 42006 addresses the machinery that makes a certificate mean something: how much audit time is required, how impartiality is protected, and how the certification decision is made. As one independent guide to choosing a certifier summarizes it, ISO/IEC 42006 "is the scheme standard that governs how certification bodies audit AI management systems. It defines auditor competence, audit duration rules, and impartiality requirements specific to AI certification." That is the whole game. Without minimum audit time and real independence, a certificate is just a rubber stamp, and buyers have no way to tell a rigorous audit from a cursory one.
Read the status precisely: this is a standard, not a law
I want to be exact about what 42006 is and is not, because it is easy to overstate. It is a voluntary international standard. It creates no statutory duty, it is not enforced by a regulator, and no company is compelled by law to use a certifier accredited to it. What gives it teeth is the accreditation system. Accreditation bodies adopt 42006 as the criteria a certification body must satisfy to be accredited to certify organizations to ISO/IEC 42001. Once that happens, a certifier that wants recognized accreditation has to meet it, and a certificate issued outside that accredited scope carries far less weight.
The date matters too. This is not breaking news. The standard has been in force for roughly a year. The reason it is worth your attention now is that the 42001 certification market has matured to the point where certificates are actually showing up in vendor questionnaires and procurement files, and the practical question buyers face is no longer "is this vendor certified" but "is the certificate accredited, and to what scope." 42006 is the standard that question turns on.
Why this matters for US firms and procurement
In the United States, the accreditation body that matters here is ANAB, the ANSI National Accreditation Board, which lists ISO/IEC 42006:2025 as required criteria for certification bodies seeking accreditation to certify AI management systems. That gives US buyers a concrete verification path. If a vendor tells you they are ISO/IEC 42001 certified, the accredited version of that claim means the certificate came from a body ANAB (or a peer accreditation body such as UKAS) has assessed against 42006.
The trap to avoid is treating a certificate as self-proving. A body can print an ISO/IEC 42001 certificate without being accredited for it, and the document will look the same. The defensible move for a procurement or vendor-risk team is to check the certifier's accredited scope on the accreditation body's public registry and confirm that ISO/IEC 42001 is actually listed. If the scope does not list 42001, the certificate is not accredited for it regardless of the marketing. And if you are the one getting certified to satisfy customer RFPs or investor diligence, pick an accredited certifier from the start. A certificate that cannot survive that scope check is a liability dressed up as an asset.
Questions professionals are asking
What is the difference between ISO 42001 and ISO 42006?
ISO/IEC 42001 is the standard an organization gets certified against for running an AI management system. ISO/IEC 42006:2025 is the standard the certification body must meet to be allowed to audit and issue those 42001 certificates. One is for the organization being certified; the other is for the certifier.
Is ISO/IEC 42006 a law or is it mandatory?
No. It is a voluntary international standard published July 7, 2025, not legislation, and no regulator enforces it. It becomes operative through the accreditation system: accreditation bodies such as ANAB adopt it as the criteria a certifier must satisfy to be accredited to certify organizations to ISO/IEC 42001.
What does ISO 42006 require of a certification body?
It builds on ISO/IEC 17021-1 and adds AI-specific requirements. In ISO's words it supports the demonstration of competence, consistency and reliability by bodies auditing and certifying an AIMS per ISO/IEC 42001. In practice that means team-level competence covering the ISO/IEC 42001 Annex A controls, minimum audit time, and impartiality rules built for AI.
How does this affect a US company buying from a certified AI vendor?
It gives you a way to test the certificate. In the US, ANAB accredits certification bodies against ISO/IEC 42006. Check the certifier's accredited scope on the accreditation body's public registry and confirm ISO/IEC 42001 is listed. If it is not, the certificate is not accredited for 42001, whatever the marketing says.
We are getting ISO 42001 certified for RFPs. Why does 42006 matter to us?
Because a certificate from a body that is not accredited to 42006 may not hold up when a customer or investor checks the accredited scope. Choosing an accredited certifier from the start means the certificate you rely on in procurement and diligence survives scrutiny instead of becoming a problem.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any standard or accreditation requirement applies to your situation with qualified counsel and your accreditation body.