Why we will never certify you
You can prepare for ISO/IEC 42001 and you can be certified against it, but the same organisation cannot do both and remain credible. Certification comes from a UKAS-accredited body independent of the consultant. Here is the dividing line, how consultants cross it without noticing, and why we stay on one side of it.
Sooner or later every firm working towards ISO/IEC 42001 asks the obvious commercial question: can you just certify us at the end? The answer is no, and it is not modesty or a gap in our offering. It is the structure of the standard. Certification is a conformity assessment, and conformity assessment only means something when the party assessing is independent of the party who built what is being assessed.1
If the person who designed your AI management system also signs the certificate, you have not been certified. You have been given a document by someone marking their own work, and any competent client, insurer or regulator who reads it will treat it accordingly.
§ 01The rule that makes the boundary
The requirements for bodies that audit and certify management systems are set out in ISO/IEC 17021-1. Two of its principles do the work here. The first is impartiality: a certification body must identify, analyse and manage threats to impartiality, including any relationship with the organisation it certifies. The second is that certification bodies are themselves assessed — in the UK, by UKAS — before they can issue accredited certificates.2
Put plainly: to be certified you need a body that is accredited and independent. That body then conducts its own audit, on its own evidence, and reaches its own conclusion. Everything you do with a consultant before that point is preparation — worthwhile, sometimes essential, and never a substitute.
The standard you are being certified against is ISO/IEC 42001, the AI management system standard. It sets out what the system must contain — scope, leadership, planning, support, operation, performance evaluation, improvement — in the familiar management-system shape. It tells you what good looks like. It does not tell you who is allowed to confirm you have got there.3
We can build the system with you, test it with you and tell you honestly where it would fail. We cannot be the person who then says it passed — that would make our opinion worth nothing to the only people who matter. — the reason we prepare and stop
§ 02How consultants drift across the line
Almost nobody crosses this boundary deliberately. Firms drift, usually for one of four reasons, and each is worth recognising in a proposal before you sign it:
- The unaccredited certificate. A consultant issues a "certificate of compliance" or "attestation" in their own name. It looks like a certificate, uses the standard's name, and has no accreditation behind it. Ask which accreditation body assessed the issuer.
- The in-house audit dressed as certification. The consultant writes your documents, then performs the "stage 2 audit", then signs off. The audit may be competent, but it is a review by the author. It is not certification.
- The referral with a fee. The consultant recommends a certification body and takes commission on the engagement or the certificate. Independence is now compromised in both directions, and it is usually undisclosed.
- The combined offer. One organisation advertises prepare-and-certify as a package. Where the two functions sit inside one legal entity with shared management and commercial interest, the impartiality safeguard is hard to demonstrate, whatever the organisation chart shows.
1. Is the certification body you would recommend accredited by UKAS for ISO/IEC 42001? 2. Do you have any financial interest in that body, or receive any fee from the certification itself? 3. Will the auditor who assesses us have had any hand in writing our system? 4. Who signs the certificate, and in whose name is it issued? Any hedging on any of the four is your answer.
§ 03Why this matters commercially, not just ethically
It is tempting to file all this as professional ethics and move on. It matters commercially in three ways we see in reviews.
Enterprise clients read the certificate. Larger clients do not just want a PDF; their procurement teams check who issued it. An unaccredited attestation is worse than nothing, because it invites a question you cannot answer and casts doubt on the rest of your documentation. A certificate from an accredited body closes the conversation.
Insurers and tenders ask the same question. Where AI governance appears in a tender, in professional indemnity underwriting or in a client's supplier assessment, the follow-up is always the same: who certified this, and are they independent of whoever built it. A firm that can answer cleanly moves on; a firm that cannot spends the next three weeks explaining.
A clean boundary produces a better system. When the person preparing you is not the person who will assess you, the incentive points at reality rather than at paperwork. Our readiness work is deliberately adversarial: we try to break the system before an auditor does, and we tell you where it cracked. If we were also the certifier, that honesty would cost us the certificate fee, and you should not trust an adviser whose honesty has a fee attached.4
§ 04What we actually do
We prepare. We never certify. In practice that means: we scope the AI management system against ISO/IEC 42001 with you; we draft the policies, the risk method, the register and the evidence trail; we run internal-style audits and record what we find; we produce the gap analysis your management team needs; and we sit through the certification audit as your support, not as its author. Where we find gaps, we say so in writing, dated, whether or not that is comfortable.
We also do not take referral fees from certification bodies, and we will not recommend one as a favour. If you ask us which body to use, we will tell you what to look for — accreditation, sector experience, auditor competence, and a scope statement that matches your actual work — and let you choose. If a firm wants a single supplier who will do both, we are the wrong firm, and we would rather tell you that on the first call than at the end of a project.
If that boundary is the kind of thing you want in a supplier, the AI governance and 42001 readiness engagement is where it starts, and our security page sets out how we handle your material. If you are earlier in the journey — no register, no policy, tools already in use — the AI audit is the honest starting point, and our note on shadow AI explains why that inventory comes first.
- Probative Co is an independent compliance practice, not a law firm, and nothing here is legal advice. We are not a certification body and we do not issue certificates. ↩
- ISO/IEC 17021-1 sets the requirements for bodies providing audit and certification of management systems, including impartiality and the management of threats to it: iso.org — ISO/IEC 17021-1. In the UK, UKAS accredits certification bodies. ↩
- ISO/IEC 42001, information technology — artificial intelligence — management system: iso.org/standard/42001. ↩
- For regulated firms, an AI management system sits alongside existing obligations; the SRA's guidance and rules on outsourcing, supervision and risk management are relevant to how the system is operated in a law firm. sra.org.uk ↩
Send three files.
We'll tell you what a reviewer would flag.
- No charge and no obligation — you keep the findings either way
- Turned around in ~48 hours, encrypted transfer only
- Most firms find at least one issue they did not know they had