The Loom · #5

ISO 42001 Audits Just Got Harder. Is Your Evidence Ready?

A new standard for AI auditors, ISO 42006, is raising the bar for what counts as real evidence — right as more companies chase the ISO 42001 badge.

Published September 25, 2026 · written and approved by RiskWoven, sources checked when published

Scorecard comparing a 2024 ISO 42001 certificate with a 2026 certificate from a body accredited to ISO 42006

Thread

On 22 September 2026, Aurigo Software announced ISO/IEC 42001 certification for its AI management system, covering how it builds AI features, assesses risk before deployment, and monitors live models — the latest name on a growing list of companies claiming the standard. What the press release doesn't say: the audit behind that certificate is not the one companies faced a year ago. ISO/IEC 42006, published 7 July 2025, sets new rules for the certification bodies themselves — the auditors who get to say a company governs its AI properly. It requires audit teams to collectively demonstrate competence across AI technologies, ISO 42001's Annex A controls, and the legal obligations tied to a company's specific AI use, and it ties planned audit time to system complexity and regulatory exposure rather than a flat schedule. Accreditation bodies in the UK and Europe began recognising ISO 42006 through late 2025 and into 2026.

Pattern

If you're a 20-to-500-person company weighing ISO/IEC 42001 certification — because an enterprise customer's security questionnaire now asks for it, or because a competitor just announced theirs — ISO 42006 changes what "getting certified" actually costs and requires. Before, a certification body could price an AI management system audit like any other ISO audit: a flat number of days per employee count. Now the certifying body has to show its own accreditor how it calculated the audit time for your specific AI footprint — how many people touch your AI lifecycle, how complex your systems are, whether you operate in a regulated sector, whether sensitive data or external AI vendors are in scope. A company with three AI features bolted onto a SaaS product gets a shorter, cheaper audit than one running AI across hiring, credit decisions, and customer support. The audit team itself also has to prove, to its own accreditor, that it collectively understands your AI's technology and your legal exposure, not just management-systems auditing in general. In practice: the paperwork-only "policy in a binder" approach that may have passed a lighter first-round audit in 2024 or 2025 is a weaker bet for a company being audited now, and a weaker bet still at next year's surveillance audit.

Knot

Coverage of ISO 42001 certification announcements, including Aurigo's, reads like a trophy case: another logo, another proof point for the sales page. What that framing misses is that the certificate itself is starting to mean different things depending on when it was issued and who issued it. A 2024-vintage ISO 42001 certificate, audited before ISO 42006 existed, was reviewed under a general-purpose ISO 17021-1 process with no AI-specific competence requirement on the auditor. A 2026-vintage certificate, audited by a body accredited under ISO 42006, was reviewed by a team that had to demonstrate AI-specific knowledge to its own accreditor before it could even offer the audit. Both companies can put the same badge on their website. A buyer reading a security-questionnaire answer of "ISO 42001 certified" has no way to tell which one they're looking at without asking a follow-up question: which certification body issued it, and is that body accredited against ISO 42006. Most procurement teams aren't asking that yet. The companies that get asked first will be the ones whose customers' security teams read the standards documents instead of the press releases — on current form, a small and growing group.

Stitch

This week: if your ISO 42001 certificate, or the certification body you're evaluating, predates 2026, ask two questions — which accreditation body stands behind your certifier, and has that accreditor recognised ISO 42006 yet. If you're heading into a first audit, ask the prospective certification body to show how they calculated your audit time under ISO 42006, not just a quote. RiskWoven's ISO 42001 readiness page walks through the Annex A controls an AI-specific audit team will actually test, so your evidence is ready before the auditor asks the harder version of the question.

Quick check

  1. Do you know which accreditation body stands behind your ISO 42001 certification body?
  2. Has your AI system inventory been updated in the last 90 days?
  3. Could you produce risk assessments completed before your last AI feature shipped?

Answer no to any of these? The free 12-question scan shows where to start.

Sources

  1. Aurigo Software press release, GlobeNewswire, 22 Sep 2026
  2. BrightDefense, "ISO 42006 Raises the Bar for ISO 42001 Certifiers"
  3. AI Compliance Vendors, "ISO 42006 Explained: Auditor Accreditation for ISO 42001"
  4. Certification Bodies, "Accredited ISO 42001 Certification Arrives in the UK!"
  5. ISO, "ISO/IEC 42001 explained"
Share on LinkedInRun the free 12-question scan
Post text to copy
Another company just announced ISO/IEC 42001 certification. Before reading that as "they're covered," know this: the standard for auditing AI management systems — ISO/IEC 42006 — was published in July 2025, and it changes who's allowed to certify you and how hard they have to look.

Two ISO 42001 certificates issued a year apart can reflect very different levels of scrutiny. If you're pursuing this certification because a customer's security questionnaire demands it, the question isn't "are we certified" — it's "which body certified us, and were they held to the new bar."

We break down what changed, and what to ask your certifier this week: riskwoven.com/loom

#AIGovernance #ISO42001 #Cybersecurity