Article · Governance & Risk
Do you need ISO 42001 certification to run AI agents?
No, nothing obliges you to. The question comes up in boardrooms anyway, and almost always through one of two doors: a tender asking for certifications without naming them, or a large customer sending its supplier questionnaire. What is worth settling before spending a euro is what a certificate of this kind actually attests, because it is not what most people assume, and because the certificate your provider will show you rarely covers what you need covered.
A note on method: I describe the standard by what its own scope declares and by how it gets used, without quoting clauses. The text is paid and reproducing it would not help anyone decide. I do not cite numbered articles of the European regulation either, for the same reason as in every other compliance piece on this site.
What ISO/IEC 42001 is, and who it reaches
It is an international standard published on 18 December 2023, in its first edition. It specifies the requirements and provides guidance for establishing, implementing, maintaining and continually improving an AI management system within the context of an organization. National adoptions arrived later and carry their own year, so the Spanish reference and the international one do not share a date.
There is a detail in its scope that tends to surprise a board. It is applicable to any organization, regardless of size, type and nature, that provides or uses products or services that utilize AI systems. This is not a standard for AI manufacturers. If your company only consumes agents that a third party operates, it still sits inside the kind of organization the standard addresses.
And it is certifiable by an independent third party. What gets audited and certified is the organization’s AI management system, as a third-party conformity assessment activity. The consequence I give as my own reading, because the standard does not put it that way, and it settles everything that follows. Certification does not attach to an agent or to a particular model. No certificate says your reconciliation agent is accurate, or that the model underneath it is any good, or that a specific use is lawful. It says a management system exists, that it covers a declared scope, and that somebody outside has checked it.
Four things the market sells as one
When an executive asks whether “we need to be certified”, they are almost always mixing four things worth separating before deciding anything:
- Complying with the obligation that applies to you given how you use AI.
- Being able to show it when asked, with documentation and records.
- Having a management system that produces that repeatably, with an owner and a cadence, instead of heroic efforts before each audit.
- Holding a certificate from a third party stating that the system exists and works.
All four can be held separately. I have seen companies with point 1 settled and point 2 living in one person’s head, and I have seen point 4 certificates over management systems that governed none of the uses that actually mattered. The step that creates real value is the third. The fourth is the one you can postpone.
On the relationship with the European regulation you have to be precise, because this is where the sales argument stretches furthest and because the European Commission has been explicit. The application of standards remains voluntary, and a provider can choose any other framework to demonstrate compliance with the regulation. The harmonised standards referenced in the Official Journal of the European Union are the ones that provide legal certainty, and ISO/IEC 42001 is not among them. The Commission itself has noted that, although the standard helps set up an AI management system, its goals and definitions are not aligned with the quality management system the regulation requires, which is why it asked for a new standard focused on regulatory compliance. Per the Commission, the first harmonised AI standards were expected during 2026, and only then does the review start that decides whether their references get published in the Official Journal. Certification gives you no presumption of conformity, and anyone selling it as if it did has not read the Commission. What obliges you and which category your use falls into is covered in the EU AI Act and AI agents, against the EU regulatory framework for AI, and I will not repeat it here.
What you already have, and what the standard adds on top
If you have deployed agents with judgement, along the lines of AI agents for business, most of the material is already built and already written up elsewhere in this house: scoped permissions and limits of action in AI agent permissions and controls, the framework deciding what gets audited and who answers in AI agent governance, the per-case trace in auditing AI agent decisions, the evaluation set in AI agent evaluation, and the competence perimeter of the people involved in the AI literacy obligation.
A management system does not add new controls. It adds the frame around the ones you already have: a written and approved policy, a declared scope stating which uses are in and which are out, a maintained inventory of those uses, named responsibilities, an impact assessment for each use before it goes live, internal audit on a calendar, management review, and corrective actions tracked to closure.
Put differently, it is the difference between having the controls and having the machinery that keeps those controls in place two years from now, with a different team and a different model underneath. That is the real work, and it is the part you cannot buy ready-made.
The question almost nobody asks: what scope does that certificate cover
This is why I am writing the piece. When a third party operates the process, the certificate and the regulatory role are two independent axes, and confusing them is expensive.
- Your provider is certified and your process is inside its scope. It serves as evidence for their side of the split. For yours it attests nothing.
- Your provider is certified and your process is not inside its scope. Then the certificate logo covers precisely nothing you care about, and this is the most common of the three cases.
- You are certified and a third party operates the process. Your management system has to govern what that third party does, including how its records reach you and what happens when it swaps models.
It is the same pattern I have described for the competence of people, applied to a different object: subcontracting the operation splits the duty, it does not remove it. Which role each party occupies before the regulator is a separate question, and I settle it in AI Act provider or deployer. The certificate does not move that role, and it does not move who pays when the damage happens anyway, which is in who pays when an AI agent makes a mistake.
Out of all this comes a short clause I would add to the ones I already review in AI managed services: the exact scope of the operator’s certificate, with your process named inside it, and the right to see the audit report rather than only the diploma. The equivalent question for the buying stage is in choosing an AI agent provider.
Two audits that are not the same
Worth keeping apart, because different people ask for them and they are prepared differently. One reconstructs a specific case end to end and answers what the agent looked at, which rule it applied, and why it escalated. The other looks at no cases at all: it looks at whether the management system exists, whether it is used, and whether it corrects what it finds. The first can be asked for by your customer, your financial auditor, or the regulator. The second is done by the certification body. Having the first settled does not get you through the second, and passing the second does not replace the first for a single day.
When it is worth it
It is worth it when someone is already asking for it in writing, in tenders or supplier questionnaires; when you sell something with AI inside it to third parties and the certificate removes friction on every deal; or when you have several uses scattered around the company and nobody can list them. That last case is the most honest of the three, because the value lies less in the diploma than in what building the system forces you to inventory.
It is not worth it yet when you run a single scoped back-office process with its limits, its trace, and its owner. There the certificate adds an annual fee and an audit cycle without changing your real risk. What I would do in that scenario is build the management system anyway, let it run for a year, and certify it when somebody demands it in writing. Building and certifying are two decisions, and only the second can be postponed at no cost.
Frequently Asked Questions
Is ISO 42001 certification mandatory?
No. It is an international standard of voluntary application, and applying standards to demonstrate conformity is voluntary too. What can make it mandatory in practice is the market: a tender that requires it, or a large customer that puts it in the supplier questionnaire. That is a legitimate commercial reason, and it is worth calling it by that name rather than presenting it as a legal requirement.
Does my operator’s certificate work for me?
Only if your process sits inside that certificate’s declared scope, and even then it attests their side and not yours. Ask for the scope in writing and check that your operation is named in it. If it is not, the certificate covers nothing you care about, however serious the body that issued it.
Does certification make me compliant with the AI Act?
No, and this comes from the European Commission, not from me. Although the standard helps set up an AI management system, its goals and definitions are not aligned with the quality management system the regulation requires, which is why the Commission asked for a new standard for that. The presumption of conformity attaches to the harmonised standards referenced in the Official Journal, and ISO/IEC 42001 is not among them.
What do I ask for before accepting a certificate in a bid?
Three things: the full declared scope rather than the cover page, the name of the certification body and its accreditation, and the last audit report or at least the list of open non-conformities. If they show you the diploma and resist the rest, you already have the answer you were looking for about that provider.