ISO 42001: Stage 2 Inspects What Your Architecture Already Emits
ISO 42001, published December 2023, is the first international standard for managing AI responsibly, and its central demands map onto the seven properties more directly than any other framework buyers ask about: defined roles, recorded decisions, and human oversight are properties 1, 2, and 5 verbatim (synthesis mapping). It is also the framework practitioners who hold the certificate rate "the bare minimum." A system that emits attribution, an audit trail, and gate decisions as a byproduct of normal work hands Stage 2 something to inspect; a policy binder hands it a binder. Certification is a two-stage audit by an accredited body: Stage 1 reviews documentation and design over 1-2 days, Stage 2 tests operating effectiveness over 3-9+ days, and the certificate runs three years with annual surveillance audits of 2-5+ days (Schellman).
The audit splits into a documents phase and an evidence phase
The architecture only helps with the second. Stage 1 reads what you wrote; Stage 2 tests whether you do it.
| Phase | Duration | What gets inspected |
|---|---|---|
| Stage 1 | 1-2 days | Scope of the AI management system (AIMS), your role relative to the AI (provider, producer, or user), policies, risk and impact assessment methodologies, statement of applicability, roles and governance structures |
| Stage 2 | 3-9+ days | Operating effectiveness: operational performance (Clause 8), risk and impact management, conformity with in-scope Annex A controls, plus monitoring, internal audit, management review, and corrective action |
| Surveillance | 2-5+ days, annually | Sampling-based recheck of continued conformity |
Areas of concern flagged at Stage 1 become formal nonconformities at Stage 2 if unaddressed. Stage 2 typically follows within 4-12 weeks and must follow within six months, or Stage 1 may need repeating (Schellman).
Three Annex A controls read like the seven properties, so the work emits their evidence
Stage 2 is where a system built to the reference architecture pays, and the mapping is close enough to be near-verbatim. Annex A.3 wants defined, assigned accountability for AI systems; that is attribution, an AI identity scoped to the initiating human so every action has a named accountable person. A.6.2.8 requires event logs of AI system activity; that is the audit trail, the append-only session log written as the work runs. A.9 wants human oversight with the ability to intervene; that is segregation of duties, the recorded gate decisions and the always-available human-review path. Clause 8 is tested on whether the AIMS operated in practice, and a system that produces evidence as a byproduct of normal work answers it continuously rather than by sampling. The full control-by-control split lives on the framework mapping page.
The precedent that this works end to end: Intercom engaged its auditors, Schellman, early, before scaling, and confirmed that its AI-approved pull requests and the evidence they produce meet SOC 2, HIPAA, ISO 27001, ISO 42001, and AIUC-1, among others (Intercom). One auditor, one body of evidence, five frameworks.
Roughly two-thirds of the standard is documents and meetings no architecture produces
ISO 42001 is a management-system standard, and the architecture covers only the operational third of it (synthesis mapping). The standard requires an AI risk assessment (clause 6.1.2) and an AI system impact assessment (clause 6.1.4) covering ethical, societal, and legal impacts: bias, transparency, unintended consequences, with ISO 42005
as the impact-assessment guide. Their results determine which Annex A controls you implement and feed the operations and improvement clauses. The AI policy (A.2), interested-party communication (A.8), internal audits, and the management review cycle are likewise yours.Organizations already ISO 27001 certified can reuse the risk framework, internal audit process, and continual improvement machinery, but Schellman is blunt that 42001 requires thinking "beyond the traditional information security risks." No event log writes your impact assessment. Plan the AIMS as a real workstream.
Practitioners rate it "a sticker for the marketing department"
Credit the skeptics, because they have the certificate and the field reports. The first organic post-certification account on Reddit came from an engineer at a 50-60 person cloud SaaS who got the company certified as a side project: one finding from a major audit firm, and his verdict was "I feel like I got scammed... The whole thing was very basic" (r/cybersecurity, November 2025). The top reply: "ISO has too much focus on policy documentation and not enough specific testing." Another commenter going through certification: it will be "cool on a sticker for the marketing department." A third: "It's the bare minimum. Which really has to make you think when there are companies that can't get it." Practitioners also note that no real ISO 42001 audit report circulates publicly; the firms doing them are "sitting on their treasure."
The skeptics are right about the floor and say nothing about the ceiling. A two-stage audit verifies that your management system does what your documents say it does. If the documents describe a policy binder, a binder passes. If they describe a system where every AI change carries an attributed identity, a replayed session log, and a recorded gate decision, Stage 2 inspects that, and the seven properties are what produce it. The standard tests what you bring it. The sticker critique is an argument against treating 42001 as the goal, not against the audit mechanics.
One more practitioner objection deserves a flag rather than a rebuttal: GRC commentators argue ISO 42001 (and NIST AI RMF) "treat audit as a log of human actions" and were not written for systems that chain tool calls and spawn subagents. That gap is real, and standards in motion covers what is moving to fill it. Meanwhile the EU AI Act's August 2026 deadline is the forcing function pushing European buyers toward 42001 regardless, and demand is rising faster than the standard is maturing.