ISO/IEC 42006: rules for the bodies that certify you

Lesson 2 of 5 in Certification, Audit, and Integrated Management Systems: ISO/IEC 42006.

Here is the problem 42006 solves. By 2024, certification bodies with deep 27001 practices were fielding 42001 enquiries — and staffing them with information-security auditors who had never met a training pipeline, a drift metric, or a fairness trade-off. An auditor who cannot tell a validation set from a test set cannot judge whether your A.6 lifecycle controls are real. Certification would have become a stamp for whoever wrote the neatest documents.

ISO/IEC 42006:2025 (published 7 July 2025) closes that gap. It layers additional requirements on top of ISO/IEC 17021-1 specifically for bodies auditing and certifying AI management systems. You will never implement 42006 yourself — but you should read it the way you would read the exam board’s rules before an exam: it tells you what your certification body is obliged to bring, and gives you standing to push back when they do not.

Audit team competence in AI

The audit team — collectively, not each individual — must demonstrate competence across the territory the AIMS covers: machine learning fundamentals (how models are trained, validated, and monitored), data management (provenance, quality, bias in acquisition and preparation), AI-specific risk (drift, adversarial inputs, opacity, automation), and the regulatory context the client operates in. A team of pure ISMS auditors does not qualify just because 42001 shares the Harmonized Structure with 27001 — the clauses rhyme, but the evidence behind them does not.

Technical areas and use of technical experts

42006 has the CB carve its AIMS work into technical areas — segments of AI activity (by sector, by AI role, by technology) demanding distinct competence — and staff each engagement accordingly. Where the audit team lacks a needed specialism (say, safety assurance for a medical-imaging model), the CB brings a technical expert into the team. Technical experts advise; they do not audit alone and do not classify findings — the auditors remain accountable for conclusions. If your AI is exotic and the CB proposes no expert, that is a question to ask before contract signature.

Audit time determination

Audit duration cannot be a sales variable. 42006 requires the CB to determine audit time from documented drivers: the number and complexity of AI systems in scope, the organisation’s role(s) (a provider developing models needs deeper lifecycle sampling than a pure deployer), the data and supply-chain complexity, sites, and the maturity of any existing management systems. A CB quoting suspiciously few audit days for a multi-model AI provider is either cutting corners or planning to sample almost nothing — both are your problem when the certificate’s credibility is questioned later.

Multi-site sampling

Organisations with many sites do not get every site audited every cycle — CBs sample. 42006 constrains how: sampling must reflect where AI-relevant activity actually happens (the ML engineering hub matters more than a sales office), and centrally controlled processes can justify lighter site coverage only if central control is demonstrated, not asserted. Expect the sites doing model development, data labelling, and deployment operations to anchor the sample.

Scope statement precision

The certificate must say precisely what is certified: which legal entities, which sites, which AI activities and roles (developer, provider, deployer per the organisation’s context). 42006 pushes CBs to reject vague scopes like ‘the management of AI’. This is consumer protection for certificate readers: a certificate scoped to ‘the AIMS governing development of the fraud-detection platform at the Dublin site’ tells you exactly what was audited — and, just as loudly, what was not.

Key terms: ISO/IEC 42006, technical expert, audit time determination, multi-site sampling, certification scope

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.