ISO/IEC 42001 and the EU AI Act are becoming the shared vocabulary of AI governance. It is worth being precise about what the certificate carries, where it stops, and what a leader should build instead of a thicker binder.
Willy Tai · governed AI for regulated operations · July 2026
Somewhere this quarter, a board is asking management to get the firm certified to ISO/IEC 42001. The question behind the question is simpler and heavier: are we safe to run AI, and can we prove it? The certificate cannot carry that weight. It was never designed to. Knowing exactly what it does carry is where credible AI governance starts.
ISO/IEC 42001:2023 is a management system standard, the same species as ISO 27001 for information security. It asks whether the organisation has an AI management system: context, leadership, planning, support, operation, performance evaluation and improvement, with 38 controls in its Annex A grouped under nine objectives that run from AI policy and impact assessment through the system life cycle, data, transparency to interested parties, and third-party relationships. An accredited body audits it in two stages, and the certificate runs on a three-year cycle with annual surveillance. Singapore has adopted it as SS ISO/IEC 42001:2024, and the Singapore Accreditation Council opened an accreditation programme for its certifiers in February 2025.
Read that description closely. The audit certifies the management system. It does not certify a model, a product, or any particular answer a system gave a customer. A firm can hold the certificate and still ship a model that quietly discriminates, provided the process surrounding the shipping was orderly and documented. That is not a defect in the standard; a management system standard exists to test the scaffolding. The defect is in what buyers project onto it. When a vendor tells you their certificate means their AI is safe, they are describing a document that makes no such claim.
The EU AI Act entered into force in August 2024 and applies in phases. The bans on prohibited practices took effect in February 2025. Obligations on general-purpose model providers began in August 2025, with transparency duties following in August 2026. The heaviest tier, the high-risk system obligations, was pushed back in May 2026 under the EU's digital omnibus agreement, to late 2027 for standalone high-risk systems and 2028 for AI embedded in regulated products. At the time of writing that deferral is politically agreed and awaiting formal publication, which is itself a lesson: the dates move, and anyone quoting last year's timeline with confidence has stopped checking. Penalties top out at €35 million or 7 percent of global turnover.
The Act's compliance machinery runs through Article 40. A provider that builds to a harmonised standard cited in the EU's Official Journal earns a presumption of conformity. Those harmonised standards are being drafted now by CEN and CENELEC's joint technical committee, JTC 21. As of this writing, none has been cited. The quality-management standard being drafted specifically for the Act, prEN 18286, maps its own annex explicitly to ISO 42001's controls, which tells you how the two instruments are meant to fit together: 42001 is the governance backbone an organisation wraps around all of its AI, and the harmonised standards will be the product-conformity layer for the systems the law calls high-risk.
So the precise statement, the one that survives a regulator's follow-up question, is this: ISO 42001 supports readiness for the EU AI Act and substitutes for none of it. A certificate is not a presumption of conformity, and today nothing else is either, because the standards that would grant one do not yet exist in citable form. Anyone selling certification as compliance is selling something the law does not currently offer.
Most organisations meet these instruments in one of two postures. The first treats the certificate as a finish line. Governance is a compliance cost, the work product is a binder, and the binder lives beside the decisions rather than inside them. This posture passes the surveillance audit and fails the incident, because the incident never asks to see the binder. The second posture treats the standard as an operating mandate. The impact assessments decide which systems are worth building. The life-cycle controls become engineering practice. The management review asks where AI is creating value the firm can defend, and where it is creating risk nobody has priced. The analyst evidence keeps pointing the same direction: a minority of firms treat governance this way, and studies from PwC and McKinsey suggest that minority captures a disproportionate share of AI's value. Governance run properly is not the tax on the return. It is part of how the return is earned.
Singapore's own trajectory makes the direction of travel clear. The AI Verify Foundation's Global AI Assurance Pilot in 2025 put independent testers inside seventeen real GenAI deployments, and its published conclusion emphasised human experts at every stage of the testing life cycle. From late 2026, an accreditation programme for AI testing firms follows. The centre of gravity is moving from attestations about process toward technical evidence about systems. The firms that will lead this market are the ones already organised around evidence.
My own frame comes from internal audit, because an AI system under governance is an operation like any other, and an auditor tests an operation against objectives. Four sets, in practice.
Every one of those objectives needs evidence, and the evidence has to survive re-performance, because re-performance is what an auditor does. That constraint, applied early, changes the architecture. Decisions get computed in code that can be re-run. Model outputs carry citations or do not ship. Consequential actions stop for a named human. Every action lands in a tamper-evident log that can be replayed. The systems on this site are built to that constraint, and each one demonstrates it live: break the log and the chain tells you where, replay the decisions and they reproduce exactly.
The regulatory picture will keep shifting. Deadlines have already moved once, the harmonised standards are unfinished, and the mapping between management standards and legal obligations is still being drafted. What does not shift is the question that follows every AI incident, which is some form of show me. Show me how this answer was produced. Show me who approved it. Show me that the log you are showing me has not been edited. A certificate answers none of those questions. A replayable evidence trail answers all of them, and it does so regardless of which standard is eventually cited in which journal.
So get the certificate; it disciplines the scaffolding and it will shortly be table stakes. Then treat it as the starting line it is, and build the thing the certificate quietly assumes: a system whose decisions are computed, cited, approved and logged well enough to pass the audit that matters. That audit is never the scheduled one. It is the one that begins the morning after something goes wrong.