Back to Frameworks

ISO/IEC 42006:2025

International
v2025 (first edition, 2025-07)
7 domains
56 controls

ISO/IEC 42006:2025 sets the additional requirements to ISO/IEC 17021-1 for certification bodies auditing and certifying artificial intelligence management systems to ISO/IEC 42001: impartiality rules that bar consultancy in AI, information security, data protection and risk management to certification clients and bar internal audits under any name; liability cover in proportion to clients' turnover; Table 1's six knowledge and skill areas (general AIMS requirements; AIMS standards and schemes; AI legal obligations; AI terminology, principles, practices, tools and techniques; the client's sector; the client's products, processes and organization) defined for auditing, for reviewing and deciding, and for application review and audit-time determination, with the audit team collectively covering every ISO/IEC 42001 Annex A control and able to trace incidents with serious negative effects on affected persons back to the AIMS; and the 17021-1 process clauses supplemented for AIMS: audit programme, scope, audit time under the normative Annex A, multi-site sampling, integrated systems, planning and remote audits, the two-stage initial audit, decisions, surveillance, recertification, special audits, suspension and withdrawal, appeals, complaints and records. Used by accreditation bodies as the criteria document for AIMS certification programmes.

Verified

ISO/IEC 42006:2025 is a compliance framework from International with 7 domains and 56 controls. The largest domains are Clause 7: Resource requirements – ISO/IEC 42006:2025 (22 controls), Clause 9: Process requirements – ISO/IEC 42006:2025 (19 controls), Clause 5: General requirements – ISO/IEC 42006:2025 (5 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Annexes A to C – ISO/IEC 42006:2025

1 controls
Controls in the Annexes A to C – ISO/IEC 42006:2025 domain of ISO/IEC 42006:20251 controls
CodeTitle
iso-iec-42006-2025::AAnnex A (normative): Audit time

Clause 10: Management system requirements for certification bodies – ISO/IEC 42006:2025

3 controls
Controls in the Clause 10: Management system requirements for certification bodies – ISO/IEC 42006:2025 domain of ISO/IEC 42006:20253 controls
CodeTitle
iso-iec-42006-2025::10.1Management system options
iso-iec-42006-2025::10.2Option A: general management system requirements
iso-iec-42006-2025::10.3Option B: management system in accordance with ISO 9001

Clause 5: General requirements – ISO/IEC 42006:2025

5 controls
Controls in the Clause 5: General requirements – ISO/IEC 42006:2025 domain of ISO/IEC 42006:20255 controls
CodeTitle
iso-iec-42006-2025::5.1Legal and contractual matters
iso-iec-42006-2025::5.2.2.1No consultancy in AI, information security, data protection or risk management for ISO/IEC 42001 clients
iso-iec-42006-2025::5.2.2.2Activities that are not conflicts of interest
iso-iec-42006-2025::5.2.2.3Activities that are conflicts of interest, and no internal audits
iso-iec-42006-2025::5.3.2Liability cover proportionate to clients' turnover

Clause 6: Structural requirements – ISO/IEC 42006:2025

1 controls
Controls in the Clause 6: Structural requirements – ISO/IEC 42006:2025 domain of ISO/IEC 42006:20251 controls
CodeTitle
iso-iec-42006-2025::6Structural requirements

Clause 7: Resource requirements – ISO/IEC 42006:2025

22 controls
Controls in the Clause 7: Resource requirements – ISO/IEC 42006:2025 domain of ISO/IEC 42006:202522 controls
CodeTitle
iso-iec-42006-2025::7.1.1Competence requirements of ISO/IEC 17021-1 plus the AIMS technical competence of 7.1.2 and 7.1.3
iso-iec-42006-2025::7.1.2Generic technical competence requirements and Table 1
iso-iec-42006-2025::7.1.3.1.1Auditing: general AIMS skills of every audit team member and of the team collectively
iso-iec-42006-2025::7.1.3.1.2Reviewing reports and deciding: general AIMS knowledge
iso-iec-42006-2025::7.1.3.2.1Auditing: knowledge of ISO/IEC 42001, documentation structures, normative documents and schemes; Annex A controls collectively
iso-iec-42006-2025::7.1.3.2.2Reviewing reports and deciding: knowledge of the standards and schemes
iso-iec-42006-2025::7.1.3.2.3Application review, team selection and audit time: knowledge of the standards and schemes
iso-iec-42006-2025::7.1.3.3.1Auditing: knowledge of the legal obligations applying to AI
iso-iec-42006-2025::7.1.3.3.2Reviewing reports and deciding: knowledge of AI legal obligations
iso-iec-42006-2025::7.1.3.3.3Application review, team selection and audit time: knowledge of AI legal obligations
iso-iec-42006-2025::7.1.3.4.1Auditing: AI terminology, principles, practices, tools, methods and techniques
iso-iec-42006-2025::7.1.3.4.2Reviewing reports and deciding: AI terminology, principles, practices, tools, methods and techniques
iso-iec-42006-2025::7.1.3.4.3Application review, team selection and audit time: AI terminology, principles, practices, tools, methods and techniques
iso-iec-42006-2025::7.1.3.5.1Auditing: knowledge of the client's business sector
iso-iec-42006-2025::7.1.3.5.2Reviewing reports and deciding: knowledge of the client's business sector
iso-iec-42006-2025::7.1.3.5.3Application review, team selection and audit time: knowledge of the client's business sector
iso-iec-42006-2025::7.1.3.6.1Auditing: knowledge of the client's products, processes and organization
iso-iec-42006-2025::7.1.3.6.2Reviewing reports and deciding: knowledge of the client's products, processes and organization
iso-iec-42006-2025::7.2.2Demonstration of knowledge and experience
iso-iec-42006-2025::7.3Use of individual external auditors and external technical experts
iso-iec-42006-2025::7.4Personnel records
iso-iec-42006-2025::7.5Outsourcing

Clause 8: Information requirements – ISO/IEC 42006:2025

5 controls
Controls in the Clause 8: Information requirements – ISO/IEC 42006:2025 domain of ISO/IEC 42006:20255 controls
CodeTitle
iso-iec-42006-2025::8.1Public information
iso-iec-42006-2025::8.2.2AIMS certification documents
iso-iec-42006-2025::8.3Reference to certification and use of marks
iso-iec-42006-2025::8.4.2Access to the documentation of the organization
iso-iec-42006-2025::8.5Information exchange between a certification body and its clients

Clause 9: Process requirements – ISO/IEC 42006:2025

19 controls
Controls in the Clause 9: Process requirements – ISO/IEC 42006:2025 domain of ISO/IEC 42006:202519 controls
CodeTitle
iso-iec-42006-2025::9.1.2Audit programme
iso-iec-42006-2025::9.1.3Scope of certification
iso-iec-42006-2025::9.1.4Determining audit time
iso-iec-42006-2025::9.1.5Multi-site sampling
iso-iec-42006-2025::9.1.6Multiple management systems
iso-iec-42006-2025::9.2.1Determining audit objectives, scope and criteria
iso-iec-42006-2025::9.2.2Audit team selection and assignments
iso-iec-42006-2025::9.2.3Audit plan
iso-iec-42006-2025::9.2.4Deployment of remote audit
iso-iec-42006-2025::9.3.2Initial certification audit
iso-iec-42006-2025::9.4Conducting audits
iso-iec-42006-2025::9.5Certification decision
iso-iec-42006-2025::9.6.2Surveillance activities
iso-iec-42006-2025::9.6.3Re-certification
iso-iec-42006-2025::9.6.4Special audits
iso-iec-42006-2025::9.6.5Suspending, withdrawing or reducing the scope of certification
iso-iec-42006-2025::9.7Appeals
iso-iec-42006-2025::9.8Complaints
iso-iec-42006-2025::9.9Client records

What is ISO/IEC 42006:2025 and who does it apply to?

ISO/IEC 42006:2025 is a compliance framework from International with 7 domains and 56 controls. ISO/IEC 42006:2025 sets the additional requirements to ISO/IEC 17021-1 for certification bodies auditing and certifying artificial intelligence management systems to ISO/IEC 42001: impartiality rules that bar consultancy in AI, information security, data protection and risk management to certification clients and bar internal audits under any name; liability cover in proportion to clients' turnover; Table 1's six knowledge and skill areas (general AIMS requirements; AIMS standards and schemes; AI legal obligations; AI terminology, principles, practices, tools and techniques; the client's sector; the client's products, processes and organization) defined for auditing, for reviewing and deciding, and for application review and audit-time determination, with the audit team collectively covering every ISO/IEC 42001 Annex A control and able to trace incidents with serious negative effects on affected persons back to the AIMS; and the 17021-1 process clauses supplemented for AIMS: audit programme, scope, audit time under the normative Annex A, multi-site sampling, integrated systems, planning and remote audits, the two-stage initial audit, decisions, surveillance, recertification, special audits, suspension and withdrawal, appeals, complaints and records. Used by accreditation bodies as the criteria document for AIMS certification programmes. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 42006:2025 actually require?

ISO/IEC 42006:2025 has 56 controls organised across 7 domains. The largest domains are Clause 7: Resource requirements – ISO/IEC 42006:2025 (22 controls), Clause 9: Process requirements – ISO/IEC 42006:2025 (19 controls), Clause 5: General requirements – ISO/IEC 42006:2025 (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 42006:2025 do I already cover?

ISO/IEC 42006:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO/IEC 42006:2025?

Start your ISO/IEC 42006:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 42006:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 56 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 688 frameworks.

Get Started Free →

Free forever — no credit card required