Founding clients · 2026 Free 2026 guide: private AI in law — deployment, costs, evaluation and a 90-day plan. Read it → Ask about a founding place
Probative Co / Insights / certification independence
FIELD NOTE AI GOVERNANCE · ISO/IEC 42001

Why we will never certify you

You can prepare for ISO/IEC 42001 and you can be certified against it, but the same organisation cannot do both and remain credible. Certification comes from a UKAS-accredited body independent of the consultant. Here is the dividing line, how consultants cross it without noticing, and why we stay on one side of it.

By the managing director 7 min read September 2026 Filed under AI governance

Sooner or later every firm working towards ISO/IEC 42001 asks the obvious commercial question: can you just certify us at the end? The answer is no, and it is not modesty or a gap in our offering. It is the structure of the standard. Certification is a conformity assessment, and conformity assessment only means something when the party assessing is independent of the party who built what is being assessed.1

If the person who designed your AI management system also signs the certificate, you have not been certified. You have been given a document by someone marking their own work, and any competent client, insurer or regulator who reads it will treat it accordingly.

§ 01The rule that makes the boundary

The requirements for bodies that audit and certify management systems are set out in ISO/IEC 17021-1. Two of its principles do the work here. The first is impartiality: a certification body must identify, analyse and manage threats to impartiality, including any relationship with the organisation it certifies. The second is that certification bodies are themselves assessed — in the UK, by UKAS — before they can issue accredited certificates.2

Put plainly: to be certified you need a body that is accredited and independent. That body then conducts its own audit, on its own evidence, and reaches its own conclusion. Everything you do with a consultant before that point is preparation — worthwhile, sometimes essential, and never a substitute.

The standard you are being certified against is ISO/IEC 42001, the AI management system standard. It sets out what the system must contain — scope, leadership, planning, support, operation, performance evaluation, improvement — in the familiar management-system shape. It tells you what good looks like. It does not tell you who is allowed to confirm you have got there.3

We can build the system with you, test it with you and tell you honestly where it would fail. We cannot be the person who then says it passed — that would make our opinion worth nothing to the only people who matter. — the reason we prepare and stop

§ 02How consultants drift across the line

Almost nobody crosses this boundary deliberately. Firms drift, usually for one of four reasons, and each is worth recognising in a proposal before you sign it:

four questions to put to any consultant

1. Is the certification body you would recommend accredited by UKAS for ISO/IEC 42001? 2. Do you have any financial interest in that body, or receive any fee from the certification itself? 3. Will the auditor who assesses us have had any hand in writing our system? 4. Who signs the certificate, and in whose name is it issued? Any hedging on any of the four is your answer.

§ 03Why this matters commercially, not just ethically

It is tempting to file all this as professional ethics and move on. It matters commercially in three ways we see in reviews.

Enterprise clients read the certificate. Larger clients do not just want a PDF; their procurement teams check who issued it. An unaccredited attestation is worse than nothing, because it invites a question you cannot answer and casts doubt on the rest of your documentation. A certificate from an accredited body closes the conversation.

Insurers and tenders ask the same question. Where AI governance appears in a tender, in professional indemnity underwriting or in a client's supplier assessment, the follow-up is always the same: who certified this, and are they independent of whoever built it. A firm that can answer cleanly moves on; a firm that cannot spends the next three weeks explaining.

A clean boundary produces a better system. When the person preparing you is not the person who will assess you, the incentive points at reality rather than at paperwork. Our readiness work is deliberately adversarial: we try to break the system before an auditor does, and we tell you where it cracked. If we were also the certifier, that honesty would cost us the certificate fee, and you should not trust an adviser whose honesty has a fee attached.4

§ 04What we actually do

We prepare. We never certify. In practice that means: we scope the AI management system against ISO/IEC 42001 with you; we draft the policies, the risk method, the register and the evidence trail; we run internal-style audits and record what we find; we produce the gap analysis your management team needs; and we sit through the certification audit as your support, not as its author. Where we find gaps, we say so in writing, dated, whether or not that is comfortable.

We also do not take referral fees from certification bodies, and we will not recommend one as a favour. If you ask us which body to use, we will tell you what to look for — accreditation, sector experience, auditor competence, and a scope statement that matches your actual work — and let you choose. If a firm wants a single supplier who will do both, we are the wrong firm, and we would rather tell you that on the first call than at the end of a project.

If that boundary is the kind of thing you want in a supplier, the AI governance and 42001 readiness engagement is where it starts, and our security page sets out how we handle your material. If you are earlier in the journey — no register, no policy, tools already in use — the AI audit is the honest starting point, and our note on shadow AI explains why that inventory comes first.


  1. Probative Co is an independent compliance practice, not a law firm, and nothing here is legal advice. We are not a certification body and we do not issue certificates.
  2. ISO/IEC 17021-1 sets the requirements for bodies providing audit and certification of management systems, including impartiality and the management of threats to it: iso.org — ISO/IEC 17021-1. In the UK, UKAS accredits certification bodies.
  3. ISO/IEC 42001, information technology — artificial intelligence — management system: iso.org/standard/42001.
  4. For regulated firms, an AI management system sits alongside existing obligations; the SRA's guidance and rules on outsourcing, supervision and risk management are relevant to how the system is operated in a law firm. sra.org.uk
A
The Probative Co review desk

Led by our AML associate — a former MLCO with twelve years in legal-sector compliance — and our managing director, who spent a decade building AI inside law firms. Together they set the methodology and sign every finding. Independent specialists are engaged per engagement; their profiles reflect that experience.

// start here

Send three files.
We'll tell you what a reviewer would flag.

  • No charge and no obligation — you keep the findings either way
  • Turned around in ~48 hours, encrypted transfer only
  • Most firms find at least one issue they did not know they had
Book the free 3-file check → Talk to us about cost Or write to — replies usually the same day.
← More field notes on the insights page Ask us where you actually stand