AI Accountability Audit vs ISO/IEC 42001: what each one is

ISO/IEC 42001 specifies requirements for an AI management system, and certification attests that the management system meets the standard. An AI Accountability Audit is a different instrument: a fixed-scope, independent audit of how a company adopts and governs AI, issued as a signed Statement with a public identifier and reissued annually under the same methodology. A company can hold both. They answer different questions.

01 · The standard

What ISO/IEC 42001 is

ISO/IEC 42001:2023 was published in December 2023 by the International Organization for Standardization and the International Electrotechnical Commission. It is the first international standard for AI management systems. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation, and it applies to any organisation that provides or uses AI-based products or services, whatever its size or sector. The standard's stated aim is the responsible development and use of AI systems. Adoption is voluntary.

ISO does not certify organisations. Certification is performed by independent certification bodies, and those bodies may in turn be accredited by a national accreditation body. The standard is published at ISO/IEC 42001.

02 · The audit

What an AI Accountability Audit is

An AI Accountability Audit is an independent, fixed-scope audit of how a company adopts and governs AI. It measures six dimensions: workflow automation, tool deployment, AI literacy, governance and oversight, investment spend, and outcome tracking, through seven sessions held with the CEO and six function heads. kn0w issues the result as a signed Statement carrying a public identifier, benchmarked against a peer cohort, with standing maintained through three Quarterly Reviews and confirmed annually. The category is defined in full at What is an AI Accountability Audit?.

03 · How they compare

How they compare

ISO/IEC 42001 certificationAI Accountability Audit
What is examinedThe AI management system: the organisation's policies, objectives and processes for managing AIHow the company adopts and governs AI, measured across six dimensions on evidence supplied by the company
What is conferred or issuedA certificate that the management system meets the standard, with a defined scopeA signed Statement with a public four-part identifier, benchmarked against a peer cohort
Who performs itAn independent certification body, which may be accredited by a national accreditation bodykn0w, as independent Issuer, under a published methodology
CadenceMaintained through the certification body's audit cycleReissued annually; standing maintained through three Quarterly Reviews across the twelve-month cycle
What a board submitsThe certificate and its scope statementThe Statement itself

04 · Holding both

When a company holds both

The two instruments answer different questions. Certification answers whether the organisation's management system meets a published standard. The Statement records what AI is actually running, who is accountable for it, what is spent on it and what is measured, at a point in time, against a peer cohort. One attests to a system; the other records a state.

A company can hold both, and the pairing is coherent: the management system governs how AI is meant to be run, and the issued Statement is independent evidence of how it is being run. APRA's April 2026 letter to industry lists recognised control frameworks among its minimum expectations on AI risk, alongside assurance capable of independently examining AI systems. What the letter expects is set out at What does APRA's AI letter to industry expect?.

05 · Frequently asked questions

Frequently asked questions

Does ISO certify companies against ISO/IEC 42001?

No. ISO develops and publishes the standard. Certification is performed by independent certification bodies, and those bodies may in turn be accredited by a national accreditation body.

Is an AI Accountability Audit a certification?

No. Certification attests that a management system meets a published standard. An AI Accountability Audit measures how a company adopts and governs AI across six dimensions and is issued as a Statement, benchmarked against a peer cohort.

Do regulators require ISO/IEC 42001?

Adoption of the standard is voluntary, and certification is a choice an organisation makes rather than a regulatory filing. Where regulators have set expectations on AI risk, such as APRA's April 2026 letter, they have referenced recognised frameworks and independent examination of AI systems without prescribing a particular standard or instrument.

Can a company hold both?

Yes. They examine different things and are produced by different parties. A certificate demonstrates the management system; an issued Statement records the company's AI posture. The methodology behind the Statement is published at kn0w.co/methodology and a sample is at kn0w.co/sample-statement.

Which does a company need first?

It depends on the question being asked of the company. A customer questionnaire or tender that names ISO/IEC 42001 points to certification. A board, investor or regulator asking what AI is running, who is accountable for it and what evidence exists points to an issued record of the current state. The two are produced by different parties and one does not substitute for the other.

Published 24 August 2026. Verified against ISO and certification-body primary sources on 24 August 2026.