The auditor is part of the assurance surface
AI certification can be no more credible than the competence, independence, scope, and evidence practices of the bodies that issue it.
Certification turns a long inquiry into a short signal. A buyer sees a mark and infers that someone competent examined the organization, tested its management system, and found the stated requirements satisfied. The compression is valuable. Markets could not repeat every audit before every transaction. But compression creates a new dependency: trust migrates from the organization being assessed to the institution that issues the mark.
ISO/IEC 42006:2025 makes that dependency explicit. The standard sets additional requirements for bodies that audit and certify AI management systems under ISO/IEC 42001. Its public description emphasizes competence and rigor in assessing organizations that develop, deploy, or provide AI systems. The auditor is not outside the assurance system. The auditor is one of its critical components.
That point becomes urgent as demand for AI assurance grows faster than shared practice. A certificate can become a procurement shortcut, a board-level reassurance, or a public claim. If audit quality varies invisibly, identical marks may conceal different scopes, samples, expertise, and thresholds for nonconformity.
Competence is specific
General audit skill does not automatically establish AI competence. An auditor may need to understand data lineage, evaluation design, model change, human oversight, impact assessment, security boundaries, monitoring, and the difference between a model and the larger system in which it acts. No individual must master every specialty, but the audit body must assemble and disclose the competence required by the scope.
Sector knowledge matters too. A technically sound model-control review may miss how a clinical workflow transfers judgment, how an employment screen affects notice and appeal, or how a public agency’s authority constrains automation. Assurance must examine whether the management system governs the actual use, not merely whether its documentation contains recognizable control language.
A certificate does not remove the need for judgment. It concentrates judgment in the certifier.
Sampling is another competence. Auditors cannot inspect every decision, dataset, and change. They choose records, teams, incidents, and controls from which to infer how the organization operates. Those choices determine what the audit can reveal. A sample optimized for orderly evidence will systematically miss the exceptions, overrides, and failed controls that most need attention.
The audit should therefore state its boundaries. Which entities, products, locations, lifecycle stages, and uses were covered? Which were excluded? What period did the evidence represent? Did the work assess a management system, a product, a deployment, or all three? A broad logo beside a narrow scope is a predictable source of false confidence.
Independence needs an operating model
Independence is not a ceremonial declaration. The organization being audited usually pays the certifier. It may also purchase readiness consulting, choose among competing bodies, and decide whether to publish adverse findings. These arrangements do not invalidate certification, but they create incentives that the assurance system must manage rather than deny.
Separation of consulting and certification functions, rotation where appropriate, conflict disclosures, review of auditor decisions, accreditation oversight, and accessible complaint procedures all help. So does preserving the evidence behind the conclusion. If a certification body cannot reconstruct why it accepted a control, later oversight is limited to trusting the very judgment under question.
ISO/IEC 42006 builds on the wider conformity-assessment architecture rather than inventing an isolated AI badge. That is institutionally important. Mature assurance markets rely on layers: standards define requirements, certification bodies assess, accreditation bodies evaluate certifiers, and complaint or surveillance processes test whether confidence remains deserved.
AI adds pressure to every layer because the object changes quickly. Models update, providers alter services, organizations expand use, and new evidence changes accepted practice. A point-in-time audit can become stale while the certificate remains visually current. Surveillance and recertification rules should respond to material change, not merely the calendar.
Assurance claims must remain contestable
A certified organization should be able to explain what the certificate establishes and what it does not. Buyers should be able to inspect scope and validity. Affected parties should have a path to raise evidence that certified processes are not operating as described. The certifier should have rules for investigation, corrective action, suspension, and withdrawal.
Withdrawal is especially important because certification creates reliance. Quietly allowing a mark to lapse may leave cached reports, sales material, and procurement records suggesting that assurance continues. Status should be verifiable, time-bounded, and linked to the exact certified scope and version of the applicable requirements.
The management-system foundation, ISO/IEC 42001, uses continual improvement rather than a promise of perfect systems. Certification should be read the same way. It can support confidence that an organization has governed processes for identifying and treating AI risks. It is not proof that every system is safe, every decision is fair, or every control worked.
Procurement teams should resist turning the mark into a binary substitute for due diligence. They should ask whether the certified scope covers the service purchased, whether the relevant deployment is included, what material changes have occurred, and what complementary product or outcome evidence is needed. Certification is evidence in a decision, not the decision itself.
Certifiers should publish enough aggregate information to let the market learn: common nonconformities, recurring evidence gaps, and the kinds of material change that force additional review. Confidentiality can protect individual clients without making the assurance process itself invisible. A market cannot improve a practice it is forbidden to observe.
The assurance industry will shape which claims become easy to buy and which failures become visible. Its own governance deserves the same attention it asks organizations to apply to AI. Competent auditors, explicit scope, preserved evidence, managed conflicts, and contestable conclusions are not administrative details. They are the surface on which the certificate stands.
— Dispatches · Summit Cognitive
Continue from here
Turn the argument into a practice.
Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.