Your ISO 42001 certificate is only as credible as the body that issues it, and that bar has just been raised. In 2025, ISO published ISO/IEC 42006:2025, a standard that sets the specific requirements a certification body must meet to audit and certify AI management systems. In other words, there is now a standard for the certifiers themselves.

Choosing the right one is no longer about price and speed; it is about accreditation, AI competence, and whether the certificate will actually be trusted by the customers and regulators you are trying to reassure. This guide, from the AI Governance Certification Institute (AIGCI), sets out how to choose an ISO 42001 certification body you will not regret.

Choose an ISO 42001 certification body that is accredited by a recognised accreditation body, holds ISO 42001 within its accreditation scope, and can prove genuine AI audit competence under ISO/IEC 42006:2025, because those three things are what make the resulting certificate trustworthy.

What a certification body is and the standard it must now meet

A certification body is the independent organization that audits your AI management system against ISO/IEC 42001:2023 and issues your certificate. It is not the same as an accreditation body, which sits above it and confirms that the certifier is competent to do the job. Two standards govern the certifier itself:

  • ISO/IEC 17021-1. The general standard for bodies that audit and certify management systems of any kind.
  • ISO/IEC 42006:2025. The new AI-specific layer on top, setting additional requirements for certifying AI management systems.

This matters because a body can be experienced at certifying, say, information security, and still lack the AI-specific competence that ISO/IEC 42006 now requires. For the detail of what that standard demands of certifiers, see the ISO 42006 requirements.

The short version: your ISO 42001 certification is delivered by certification bodies held to ISO/IEC 42006, and a good one will happily talk about how it meets it.

What ISO/IEC 42006 changes for you as a buyer

You will never be audited against ISO/IEC 42006 yourself; it applies to the certifier, not to you. But it changes what you can reasonably expect and demand. Before 42006, a buyer had to take a certification body's AI competence largely on trust.

Now there is a published benchmark, which means you can ask a simple, powerful question: how do you meet ISO/IEC 42006? A body that can answer clearly has done the work; a body that deflects has told you something important.

In effect, the standard gives buyers leverage that did not exist a year ago, and the best certifiers welcome the scrutiny.

Five criteria that separate a strong certifier from a weak one

Evaluate any candidate against these five points. A strong body clears all of them; a weak one falls down on at least one.

Criterion

What good looks like

Red flag

Accreditation

Accredited by a recognised body such as UKAS or ANAB

No accreditation, or a vague claim of it

ISO 42001 in scope

ISO 42001 explicitly listed in its accreditation scope

Accredited for other standards but not this one

AI competence

Auditors who understand bias, model governance, and AI risk

Generalist auditors with no AI depth

Impartiality

Clear separation between consulting and certifying

Offers to both fix and certify your system

Recognition

Accredited certificate accepted internationally

A certificate that only holds locally

Treat this table as a scorecard. If a body cannot give you a confident, specific answer on any row, keep looking.

The five criteria are not equally easy to fake: a slick brochure can imply competence, but accreditation scope and auditor experience are verifiable facts, so weight the things you can check over the things you are told.

Why accreditation is the criterion you cannot compromise on

Accreditation is what turns a certificate from a private opinion into a recognised assurance. An accreditation body such as UKAS in the United Kingdom or ANAB in the United States independently assesses a certification body against ISO/IEC 17021-1 and ISO/IEC 42006, and confirms it is competent and impartial.

Crucially, you must check that ISO 42001 sits within the body's accreditation scope, not just that the body is accredited for something. A body accredited only for ISO 9001 or ISO 27001 cannot give you a recognised ISO 42001 certificate.

Accreditation also buys you reach. Because accreditation bodies recognise each other through international arrangements, as the accreditation forum explains, an accredited certificate is accepted across borders rather than only where it was issued.

An unaccredited certificate may cost less and arrive faster, but it will not carry that weight, and in a procurement conversation that difference is everything.

The pool of accredited certifiers is still small, so choose carefully

Because ISO/IEC 42001:2023 is new, accredited certification only became available through 2024 and 2025. ANAB in North America opened accreditation first, with a small number of certification bodies accredited by late 2025, and UKAS granted its first ISO 42001 accreditation in the same period. That youth cuts both ways for a buyer:

  • Fewer choices. The set of genuinely accredited bodies is still limited, so shortlist early rather than assume abundance.
  • More noise. In a young market, unaccredited certificates and attestations dressed up as certification are more common, so the accreditation check matters more here than for a mature standard.

The practical takeaway is to verify accreditation and ISO 42001 scope for yourself, on the accreditation body register, rather than taking a sales claim at face value. A body that is genuinely accredited will make that verification easy.

The AI competence test a good certifier must pass

This is the criterion most buyers overlook, and the one ISO/IEC 42006 exists to protect. Certifying an AI management system is not the same as certifying a security or quality system. A capable ISO 42001 auditor needs to understand, and probe, things that a generalist would miss:

  • How bias enters a model through its training data, and how you test for it.
  • What transparency and explainability mean for the decisions your AI makes.
  • How human oversight is designed, and whether it actually works in practice.
  • How the AI system lifecycle is governed, from data to deployment to retirement.

A body with a strong information-security heritage understands management systems, which is a real advantage, but you should still confirm it grasps these AI-specific concerns. Ask for auditor profiles and their AI experience. A confident certifier will share them; a hesitant one tells you what you need to know.

Accredited versus unaccredited: what you are really paying for

It is tempting to treat certification as a commodity and pick the cheapest option. The difference between an accredited and an unaccredited certificate is exactly the difference between something a customer will accept and something they will question.

Aspect

Accredited certification body

Unaccredited body

Independent oversight

Assessed by an accreditation body

No independent oversight

ISO 42006 competence

Held to the AI-specific standard

No guarantee of AI competence

Recognition

Accepted across borders

Limited, often questioned

Weight in procurement

Treated as credible evidence

Treated with caution

Real cost

Higher fee, lower risk

Lower fee, higher risk

The unaccredited route can look attractive on a spreadsheet and expensive in a sales cycle, when a prospect asks who accredited your certifier and the answer is nobody. Remember that the whole point of certifying is to be believed by someone else; a certificate that your buyers do not recognise fails at the one job you bought it to do.

Questions to ask before you sign

Come to every evaluation with the same short list. The answers, and the ease with which they are given, reveal more than any brochure.

  1. Are you accredited for ISO 42001 specifically, and by which accreditation body?
  2. Can I see that ISO 42001 is listed in your accreditation scope?
  3. What AI-specific competence do your auditors hold, and can I see profiles?
  4. How do you keep certification and any consulting strictly separate?
  5. What is your view on ISO/IEC 42006, and how do you meet it?
  6. How many ISO 42001 audits has your team actually completed?

You are not looking for perfect answers to every question. You are looking for straight, specific ones. Evasion on accreditation or AI competence is the clearest possible signal to walk away.

Red flags that a certification body is the wrong choice

Some warning signs are worth treating as deal-breakers:

  • No accreditation, or accreditation that does not include ISO 42001 in scope.
  • An offer to both consult on and certify your management system, which compromises impartiality.
  • Auditors with no demonstrable AI experience beyond a general management-system background.
  • A price or timeline that looks too good, usually a sign of a light-touch, unaccredited process.
  • Reluctance to discuss ISO/IEC 42006 or to show accreditation scope on request.

How choosing a body fits the wider certification journey

Selecting a certifier is one decision inside a larger project. It comes after you have built and internally audited your AI management system and before the Stage 1 and Stage 2 audits that lead to your certificate. If you want the full picture of where this step sits, our guide on how to get certified walks through the whole journey.

The practical point is timing: choose your body early enough to plan the audit, but only once your management system is genuinely ready to be assessed. Engaging a certifier before your AIMS is ready wastes money on a Stage 1 audit you are not prepared to pass, while leaving it too late can delay a certificate your customers are already asking for.

Frequently asked questions

Does the certification body have to be accredited?

For a certificate that customers and regulators will trust, yes. Accreditation, with ISO 42001 in scope, is what makes the certificate recognised. An unaccredited certificate is a private attestation with limited weight.

What is ISO/IEC 42006?

It is the 2025 standard that sets the requirements a body must meet to audit and certify AI management systems. It adds AI-specific competence and rigour on top of the general certification standard, ISO/IEC 17021-1.

Can the same firm help us prepare and then certify us?

No reputable, accredited body will do both, because it compromises impartiality. Preparation and certification should come from different sources. Use a consultant or trained internal team to prepare, and an accredited certification body to certify.

How do I check a body's accreditation scope?

Ask the body directly, and confirm it against the accreditation body's public register. The scope should list ISO 42001 explicitly. If you cannot verify it, treat the certificate as unaccredited.

Does the cheapest certification body ever make sense?

Rarely. A low price often reflects a lighter, unaccredited process, and a certificate that does not hold up in procurement costs far more than it saves. Compare accredited bodies on value and fit, not headline price.

Should we use the body that already certifies our ISO 27001?

Often, yes, if they are accredited for ISO 42001 as well. A body that already knows your organization and holds both standards in scope can run integrated audits, which saves time and cost. Just confirm ISO 42001 is genuinely in their accreditation scope and that their auditors have real AI competence, rather than assuming their security accreditation carries over.

Arrive ready, whichever body you choose

The strongest position in any certification-body conversation is being genuinely ready, with a management system that will pass and a team that can answer the auditor's questions. AIGCI does not certify organizations; it prepares the people who build the systems that get certified.

Our ISO 42001 Lead Implementer training equips your team to prepare an AI management system that stands up to any accredited certifier, so you choose a body from a position of strength. To see how the institute supports organizations on the path to certification, read more about the institute.