ISO/IEC 42001 Evidence in AI Procurement

A practical guide to using ISO/IEC 42001 evidence in supplier due diligence without treating management-system certification as proof of product performance or suitability.

ISO/IEC 42001:2023 is an international standard for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (AIMS). In procurement, that makes ISO/IEC 42001 potentially valuable governance evidence — but it should not be treated as a substitute for product-specific, security, privacy, performance or deployment evidence.

AI TrustMark does not reproduce the copyrighted requirements of the standard. This guide uses only the public description of the standard and focuses on how buyers should evaluate certification evidence.

1. Verify the certificate before relying on it

Do not stop at a logo or supplier statement. Record:

  • the certified legal entity;
  • certificate number and current validity;
  • certification body;
  • accreditation status where relevant;
  • the stated certification scope;
  • sites, business units or activities included;
  • exclusions or limitations visible on the certificate.

The key procurement question is whether the certificate actually covers the organisation and activities relevant to the service being bought.

2. Understand what management-system evidence can support

A management-system certification can be relevant to questions such as:

  • whether the organisation has assigned AI governance responsibilities;
  • whether AI risks are managed through defined processes;
  • whether controls are reviewed and improved over time;
  • whether there is a structured approach to policies, objectives and oversight;
  • whether AI management is embedded organisationally rather than handled ad hoc.

Those are important supplier-assurance signals, particularly where the procurement depends on sustained governance over a multi-year service.

3. Do not turn ISO/IEC 42001 into a product-performance claim

A management-system certificate does not by itself demonstrate that a particular AI product:

  • is accurate enough for the buyer's use case;
  • is secure in the proposed architecture;
  • meets the buyer's privacy requirements;
  • complies with every applicable law;
  • has acceptable bias or fairness outcomes;
  • has suitable human oversight;
  • is operationally resilient in the buyer's environment.

Those points require separate evidence appropriate to the product, deployment and intended use.

4. Ask how the certified management system governs the named product

Where ISO/IEC 42001 is relevant, connect organisational assurance to the proposed service. Useful questions include:

  • Is the product within the certified scope?
  • Which internal governance process applies to it?
  • Who owns product-level AI risk?
  • How are model and provider changes reviewed?
  • What triggers reassessment or escalation?
  • How are incidents, customer feedback and performance findings fed back into governance?

This helps distinguish certification that is directly relevant to the procurement from certification that covers a different business area.

5. Combine management-system evidence with product evidence

A proportionate evidence pack may combine ISO/IEC 42001 evidence with:

  • architecture and dependency documentation;
  • privacy and data-flow evidence;
  • NCSC-aligned security evidence;
  • task-specific evaluation results;
  • incident and resilience evidence;
  • human-oversight controls;
  • verified customer/deployment evidence;
  • contractual change and monitoring controls.

See the AI Supplier Due-Diligence Checklist.

6. Treat scope and currency as material facts

Certification evidence can become stale or cease to apply after acquisition, restructuring, scope changes or expiry. Record validity and scope as dated evidence and establish a refresh trigger during the contract.

If the supplier relies on certification as part of an award decision, consider requiring notification of suspension, withdrawal, scope reduction or material changes to the certified management system.

7. Separate independent assurance layers

Different assurance mechanisms answer different questions. ISO/IEC 42001 focuses on an organisational AI management system. Product and procurement assurance may still need to test the actual product, dependencies, evidence and use case.

AI TrustMark Bronze, Silver and Gold are separate assessment-depth concepts and are not UKAS accreditation or ISO certification. See When TrustMark vs UKAS.

How AI TrustMark fits

AI TrustMark can verify the existence, scope and relevance of supplier evidence and separately assess product and operational evidence. It does not issue ISO/IEC 42001 certificates and does not present an AI TrustMark as an accredited ISO certification.

The public guide explains how to interpret evidence. Organisation-specific ISO crosswalks, certificate verification, evidence-gap analysis, product assurance, tender matrices and procurement packs remain professional services.

Return to the AI Procurement Knowledge Base or use the AI Procurement Route Finder.