ISO publishes ISO/IEC 42001:2023. It does not certify anyone. An external certification body audits your AI management system (AIMS) in two stages, then keeps auditing for the life of the certificate. "Compliant" or "aligned" is a claim you make about yourself. "Certified" means a body issued a certificate you can look up.
The requirements sit in clauses 4 to 10 (scope, leadership, risk and impact assessment, operation, internal audit, management review, improvement). Annex A lists 38 reference controls. You pick which ones you need in a Statement of Applicability; you do not have to implement every control.
For AI agents, auditors care about records more than policy PDFs. Useful evidence usually includes:
- which agent acted, and on whose behalf
- which tool, action, and resource
- allow, deny, or allow-with-approval, plus the policy version
- who approved a sensitive call, when a human had to sign off
A.6.2.8 (event logging) is the control agent teams ask about most. In paraphrase, logging has to be on at least while the system is in use. For an agent, that is each tool call.
Disclosure: I work at Permit.io. We wrote a walkthrough of the certification process, Annex A, and where agent authorization logs can (and cannot) sit as evidence. Permit does not make anyone certified; only a certification body can.
Top comments (0)