cd /news/ai-policy/iso-42001-for-engineering-teams-what… · home › topics › ai-policy › article
[ARTICLE · art-141044] src=dev.to ↗ pub= topic=ai-policy verified=true sentiment=· neutral

ISO 42001 for Engineering Teams: What It Actually Asks You to Prove

A developer examined ISO/IEC 42001, the voluntary international standard for AI management systems published in December 2023, to determine what it actually requires of engineering teams. The analysis concludes that certification hinges on evidence rather than paperwork: auditors verify that controls around AI-assisted changes are reviewed, tested and approved by pulling timestamped records tied to specific decisions. The standard complements the EU AI Act and SOC 2 rather than replacing either, with early certifications including BCG and Pega.

by read4 min views1 publishedSep 28, 2026

Originally published on the Dromeas blog. In short: ISO 42001 is a voluntary, certifiable standard for managing AI systems. For engineering teams it's mostly about evidence: showing how AI-assisted changes are reviewed, tested and approved. It complements the EU AI Act and SOC 2 rather than replacing them.

Framework Type Question it answers
ISO 42001 Voluntary certification (3 years, with surveillance audits) Is your AI governed?
EU AI Act Law, with penalties Does your AI meet legal obligations in the EU?
SOC 2 Attestation Do your security controls work?

ISO 42001 keeps turning up in the same sentence as SOC 2 and the EU AI Act, usually on a slide that implies you need all three by next quarter. I wanted to know what it really asks of the people who write and ship code, so I sat down with it.

Short version: it's less about paperwork than I expected, and a lot more about evidence.

ISO/IEC 42001 is the international standard for an "AI management system." ISO published it in December 2023, and it's still the current edition. If you've been through ISO 27001, the shape will feel familiar: a set of clauses on how you run the system (the usual plan, do, check, act loop), plus an Annex A with 38 controls across nine areas. You pick the ones that apply and justify your choices in a Statement of Applicability.

The important bit: it's not a spec for how your model should behave. It's about how your company governs the AI it builds, buys or uses. Who's accountable, how you assess risk, where your data comes from, how you watch things once they're live, and what happens when something goes wrong. It applies whether you're building AI products or just letting your engineers use AI tools.

It's early. BCG announced in January that it was among the first 100 organizations certified worldwide. Pega got certified in February for Pega Cloud and its GenAI features. I couldn't find a reliable global count of certified companies, and I'd be a bit wary of anyone who quotes one.

The trajectory looks a lot like SOC 2 a few years back. AI vendors selling into enterprise are the first to feel it, because it starts showing up in security questionnaires. If that's you, it's worth knowing what it'll ask before a customer asks first.

Certification happens in two stages. The first is a document review: your AI policy, your risk register, your Statement of Applicability. The second is the one that catches people out. The auditor checks that your controls actually run, which usually means interviews, watching processes, and pulling samples. They'll pick a feature or a date and ask you to show them the control working then.

For an engineering team, the Annex A areas that land on your desk are roughly these: The general rule auditors follow will sound familiar if you've done SOC 2. A record that was produced independently, timestamped and tied to a specific decision counts for a lot more than a policy saying the process happens. Policy says what should happen. Evidence shows it did.

We've written about the EU AI Act before. It's law, with real penalties, and it applies if you serve the EU market. ISO 42001 is voluntary. You get certified by a third party, the certificate lasts three years, and there are surveillance audits in between.

They cover a lot of the same ground (data governance, risk, human oversight, transparency), but one doesn't satisfy the other. If you're building a high-risk system under the Act, a 42001 certificate is useful supporting evidence. It doesn't replace the legal obligation.

SOC 2 is a different question again. It tells a customer your security controls work: access, encryption, incident response. It says nothing about how you govern the AI itself. Some analysts are already describing ISO 42001 plus SOC 2 Type II as the new baseline for AI vendors selling to enterprise. That's one view, not a rule, but it gives you a sense of where things are heading. Three audits, three different questions: is your AI governed, are your security controls working, is your infrastructure secure.

We don't certify anyone. That's accredited third-party work, and it should stay that way.

What we do produce is the kind of record the Stage 2 auditor goes looking for. Every pull request and trunk commit gets reviewed. Every tagged release gets a verdict across six checks (quality, security, compliance, testing, docs, instrumentation), grounded in the actual diff and stamped with a date. If an auditor asks "show me what was verified before this release shipped," that's already sitting there. More on how we handle frameworks on our compliance page.

— Manos

Sources: ISO/IEC 42001:2023 · BCG, Jan 27, 2026 · Pega via Businesswire, Feb 3, 2026 · Konfirmity, Annex A controls · ISMS.online, ISO 42001 vs EU AI Act · Vanta, EU AI Act & ISO 42001 · Knowlee, ISO 42001 vs SOC 2 vs ISO 27001

── more in #ai-policy 4 stories · sorted by recency
── more on @iso 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/iso-42001-for-engine…] indexed:0 read:4min 2026-09-28 · —