ISO 42001

ISO 42001 in Production: What the Auditor Actually Tests

2026Nextvise

An ISO/IEC 42001 certificate is a real achievement. It is also not the same thing as being able to defend a decision your AI made last Tuesday. Knowing the difference is what keeps the certificate from becoming a false sense of security.

ISO 42001 is a management system, not a checkbox

ISO/IEC 42001 is the first international standard for an AI management system (AIMS). The word that matters is system. It is not a one-time test you pass; it is a way of running AI governance continuously: an AI policy, risk and impact assessments, the Annex A controls, defined roles, internal audits, and management review, all of it operated over time.

And all of it is evidence-driven. An AIMS audit does not grade your intentions. It tests documented records: that the controls exist, that they run, that decisions and reviews are logged, that the system is actually operating the way the policy says.

What the certificate proves, and what it doesn't

Here is the gap. Certification is a point in time. A certificate says: on the day the auditor looked, the management system was in place and operating. Between audits, your AI keeps making decisions, thousands of them.

A surveillance audit, a customer's due-diligence team, or a regulator can later point at one of those decisions and ask: which control governed this output, who reviewed it, and where is the record? "We're ISO 42001 certified" describes the system. The question is about the decision.

The certificate proves the system exists. It does not, by itself, produce the per-decision evidence, and that is precisely the evidence an AIMS is supposed to be generating in the first place.

Where defensibility fits

The two are not in competition; they complete each other. ISO 42001 tells you to run an evidence-producing management system. Defensible AI is what that evidence looks like at the level of a single decision, every output checked against the control that governs it, signed, and retained.

Do that continuously and the AIMS audit gets easier, not harder: the records the auditor asks for already exist, because you generated them at runtime instead of reconstructing them the week before Stage 2. (We unpack the distinction between compliant and defensible in What Defensible AI Means in a Regulated Environment.)

The standard we build to

Nextvise is the infrastructure for Defensible AI. It produces the per-decision, signed, retained evidence an AIMS is meant to generate, continuously, not once a year, and escalates anything that does not hold to a named human, on the record.

An ISO 42001 certificate proves your system exists. A Nextvise record proves what it decided.

― basis: ISO/IEC 42001 (AI management system) · Annex A controls · Stage 1 / Stage 2 certification & surveillance audits

Get Audit-Ready
← Back to Insights