GovCompass

AI certification: what exists and what it proves

By Michel Venniker· Last updated August 2026

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

Status of time-bound facts in this article: 1 August 2026. Verify the official sources before relying on the conformity assessmentconformity assessmentThe pre-market process demonstrating a high-risk AI system meets the EU AI Act's requirements, leading to CE marking and registration.Open full entry → status.

Scope note: this article covers certification in governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry →, riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry →, controlcontrolThe concrete, testable measure that reduces a specific risk, and through that risk protects the principle behind it. Also called a risk management measure, risk response, or risk treatment. Always traceable to the risk it addresses: under EU AI Act Art. 9 every control must map back to a specific risk, and controls recorded separately from their risks is a recognized compliance failure. It works in one of three types: preventive, detective, or corrective. See risk, control types, evidence.Open full entry →, and assurance. Technical practitioner certifications from cloud vendors and dedicated AI security credentials follow a separate track and are not compared here.

Why the word certification causes trouble

Organizations increasingly ask suppliers, candidates, and each other for AI certification without first asking what is being certified. The term covers three fundamentally different assessment objects, and treating them as interchangeable produces weak procurement decisions, misplaced assurance, and unrealistic expectations of what a certificate proves.

This article uses certification as an umbrella term for convenience. In strict terms the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → establishes a conformity assessment procedure, not a certification scheme, and that difference matters as soon as anyone relies on the outcome.

One principleprincipleOne of the seven responsible-AI values a governed system should live up to (fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, human oversight). A principle is abstract: it states an outcome, not a lever you can pull. It becomes governable by naming the harm that would breach it, assessing the risk that harm carries, and placing controls against that risk. Held this way, a principle becomes a pillar. See pillar, harm, risk.Open full entry → runs through all three layers. A certificate reports an assessment of a defined scope at a defined moment. It is not evidenceevidenceThe concrete proof that a control is designed, implemented, and working: a test report, an audit trail, an impact assessment, a monitoring log. Each link in the governance chain produces an artifact, and together they are what an organization hands to its own board, a regulator, a customer, or an affected person to show, not say, that a system is governed. Its absence is itself the failure: a risk register without test results, or a mitigation claimed without validation, is a governance gap, not a paperwork one. The closing link of the governance chain. See control, governance.Open full entry → that an organization remained in control afterward.

Three objects, three forms of assessment

Most confusion comes from one mistake: treating credentials for people, standards for organizations, and legal assessment of AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → as points on a single scale. They answer different questions.

A person certificate states that an individual passed an exam and, in some schemes, proved experience. A management system certificate states that an organization runs a governance system that an independent body audited. A conformity assessment records that a specific AI system went through the procedure the law prescribes before it may reach the EU market, which is a precondition rather than a discharge of the providerproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry →'s other obligations.

None of the three substitutes for another. An organization with a certified management system can still deploy a non-compliant AI system, and a certified professional proves nothing about the organization that employs them.

Three assessment objects in AI certificationA person, an organization's AI management system, and an AI system are assessed separately. Each has its own assessor, its own basis of authority, and its own result. The bottom row shows what continues after the assessment for each object: credential maintenance, surveillance audits and internal evidence, and post-market monitoring with reassessment after substantial modification.AI CERTIFICATIONThree objects, three forms of assessmentEach has its own assessor and its own basis of authority. None substitutes for another.PersonWHAT IS ASSESSEDIndividual competence, and in someschemes documented experience.WHAT AUTHORIZES THE ASSESSORAccreditation of the body and itsscheme against ISO/IEC 17024.RESULTA personal credentialOrganizationWHAT IS ASSESSEDThe AI management system: policy,roles, risk, monitoring, improvement.WHAT AUTHORIZES THE ASSESSORAccreditation under ISO/IEC 17021-1and ISO/IEC 42006, scope included.RESULTAn ISO/IEC 42001 certificateAI systemWHAT IS ASSESSEDOne high-risk AI system against therequirements of the EU AI Act.WHAT AUTHORIZES THE ASSESSORThe provider under Annex VI, or anotified body listed in NANDO.RESULTCE marking, and a certificateunder Art. 44 on the second routeWHAT CONTINUES AFTER THE ASSESSMENTCredential maintenance:continuing education and,in some schemes, recertification.Surveillance and recertificationaudits, and the organization's ownevidence in the intervals.Post-market monitoring, seriousincident reporting, reassessmentafter substantial modification.Holding controls is not the same as being in control.GOVCOMPASS.AI

Personnel certification for governance, risk, and audit roles

The person layer has grown quickly and now splits by role.

The IAPP AI GovernanceAI governanceGovernance extended for AI: the same organizational steering at the highest level, widened to cover what makes AI different (it works in probabilities rather than fixed rules, learns from data, and can act at a speed and scale no human reviewer can match). It inherits the existing governance structure and brings AI inside the disciplines the organization already runs, rather than creating a parallel system in a silo. It operates on two levels, design and execution. See governance, governance design, execution level, responsible AI.Open full entry → Professional, or AIGP, covers the governance arc: foundations, applicable law, development, and deployment. It has no prerequisite, which makes it accessible to privacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry →, legal, compliance, and risk professionals moving into AI governance.

ISACA built three AI credentials as extensions of existing designations rather than as standalone exams. Advanced in AI Audit, or AAIA, requires an active CISA or another qualifying designation and targets auditors. Advanced in AI Security Management, or AAISM, launched on 19 August 2025 and requires an active CISM or CISSP. Advanced in AI Risk, or AAIR, launched on 15 April 2026 and requires one of roughly 25 qualifying designations, including CISA, CISM, CRISC, CDPSE, and CISSP. The design signals that ISACA treats AI as too role-specific for a single exam. ISACA also issues an Artificial Intelligence Fundamentals Certificate with no prerequisite, which it lists separately from its certifications.

The ISO/IEC 42001ISO/IEC 42001The international requirements standard for AI management systems, published in 2023 and certifiable. It defines how an organization establishes, implements, maintains, and continually improves a management system for AI. Certification against ISO/IEC 42001 does not create a legal presumption of conformity with the EU AI Act. See AI management system, harmonized standard.Open full entry → credentials sit in a different category than their names suggest. Foundation, Internal Auditor, Lead Implementer, and Lead Auditor programs are issued by training and certification organizations such as PECB and BSI. ISO itself sets neither the course duration nor the provider credentialing.

The better providers make the distinction visible in their own scheme. PECB uses a single Lead Auditor exam and then awards one of four credentials based on documented experience. Provisional Auditor requires no experience. Auditor requires two years of professional experience including one year in AI, plus 200 hours of audit activity. Lead Auditor requires five years including two years in AI, plus 300 hours. Senior Lead Auditor requires ten years including seven years in AI, plus 1,000 hours. Every level requires signing the code of ethics. PECB states that it holds ISO/IEC 17024 accreditation from several accreditation bodies, and for any specific credential the question is whether that scheme falls within the current published scope of the accreditation.

One consequence deserves stating plainly, because it is widely misread. No individual issues certificates. A Senior Lead Auditor title is a statement about a person; only an accredited certification body can certify an organization.

Maintenance is where these credentials separate themselves from a course record. AIGP holders must submit 20 hours of continuing professional education for each two-year term and pay a maintenance fee, which IAPP membership covers. ISACA requires at least 10 CPE hours annually and 30 over a three-year period for AAIA and for AAISM, an annual maintenance fee, and continued active status of the prerequisite designation. The AI credential lapses when the underlying CISA, CISM, or CISSP lapses.

Course certificate or professional certification

Six questions separate a professional certification from a course certificate. Are there eligibility requirements? Is competence assessed independently of the trainer? Is experience verified? Is there a code of conduct? Must the credential be maintained? Is the certification scheme itself accredited?

Mature schemes answer yes to most of these but rarely to all. AIGP requires no prior experience, for instance, while requiring an exam and continuing education. The six questions form a profile, not a checklist with a pass mark.

Universities, consultancies, vendors, and training institutes all issue AI certificates. A course certificate records that the provider judged a participant to have completed a defined program and, where applicable, to have passed its assessment. That can rest on a serious curriculum and real learning. What it does not do is demonstrate independently verified competence or experience. When a supplier, a candidate, or a job applicant presents a credential, that is the distinction to establish first.

AI management system certification: ISO/IEC 42001 and ISO/IEC 42006

ISO/IEC 42001:2023 is the first international management system standard dedicated to AI, and the standard organizations are certified against in practice. It follows the structure of ISO 9001 and ISO/IEC 27001 and covers governance, roles, risk management, supplier management, monitoring, and continual improvement. The certificate describes the organization's management system. It says nothing about the compliance of any individual AI system, and it does not create a presumption of conformity with the EU AI Act.

A second standard decides how much that certificate is worth, and it is far less known. ISO/IEC 42001 specifies what an organization must implement. ISO/IEC 42006 specifies what a certification body must be capable of before it may certify anyone against ISO/IEC 42001.

ISO/IEC 42006:2025 was published on 7 July 2025 by ISO/IEC JTC 1/SC 42 and supplements ISO/IEC 17021-1. It covers competence requirements for certification personnel, rules on audit time, and provisions on impartiality and liability. Accreditation against it is still being put in place, since accreditation bodies and certification bodies need time to build schemes, scopes, and transitions. Certification by a body without that accreditation is not void, but it carries less independent weight.

The question to ask a certification body is therefore twofold. Has it been accredited for ISO/IEC 42001 certification under ISO/IEC 17021-1 and ISO/IEC 42006, and does its published scope cover this service? If not, what evidence supports its competence and impartiality?

AI Act conformity assessment, not certification

Assessment of AI systems in the EU follows public law rather than a voluntary certification scheme. Article 43 sets a conformity assessment that a provider must complete before a high-risk system reaches the market, and the market-facing result is a CE markingCE markingThe mark affixed to products (including high-risk AI systems) indicating conformity with applicable EU requirements.Open full entry → with an EU declaration of conformitydeclaration of conformityThe provider's signed statement that a high-risk AI system meets the AI Act's requirements, drawn up before the system is placed on the market.Open full entry →.

The route depends on the system. For most stand-alone high-risk systems listed in Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry →, the provider performs the assessment itself under the internal control procedure in Annex VI, and no certificate is issued at all. A notified bodynotified bodyAn independent conformity-assessment organization designated to verify that a high-risk AI system meets the AI Act before it reaches the market.Open full entry → under Annex VII becomes mandatory for biometric systems under Annex III point 1 where the provider has not applied harmonized standardsharmonized standardA European standard developed on request of the European Commission. Under Article 40 of the EU AI Act, compliance with harmonized standards published in the Official Journal gives a presumption of conformity with the requirements those standards cover. Harmonized standards for the AI Act are still in development. See conformity assessment, EU AI Act.Open full entry → or common specifications, and for high-risk AI embedded in Annex I products through the applicable sectoral legislation.

On that second route a certificate does exist. Article 44 governs it, and the terms are instructive. Validity is capped at five years for systems covered by Annex I and four years for those covered by Annex III, extendable only after a re-assessment. Where a notified body finds that a system no longer meets the requirements, it must suspend or withdraw the certificate or impose restrictions, unless the provider takes corrective action within the deadline set. The law therefore treats a certificate as a live status that has to be maintained, not as a finding that stays true.

The supporting infrastructure is still forming, and one distinction matters here. CEN-CENELEC published EN 18286, the quality management system standard for AI Act purposes, in July 2026. It is the first European AI standard to reach publication. Publication is not citation. The presumption of conformity under Article 40 attaches only once the Commission cites the reference in the Official Journal, and as of July 2026 that had not happened, so no standard yet carries that effect.

On the assessment side, no notified bodies were listed in the NANDO database for AI Act conformity assessment as of April 2026. Regulation (EU) 2026/1744 introduced a code system in Annex XIV for this purpose, so that a notification states precisely which categories and types of AI system a body may assess.

Timing changed in July 2026. Regulation (EU) 2026/1744, the Digital OmnibusDigital OmnibusAn EU amending package that adjusts parts of the EU AI Act, including the application dates for high-risk obligations. As of July 2026 it has been adopted by the European Parliament and the Council and awaits publication in the Official Journal; verify the current status and dates against the official text. See EU AI Act.Open full entry → on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It moves the application of Chapter III, Sections 1, 2, and 3 to 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and to 2 August 2028 for those classified under Article 6(1) and Annex I. The reason the legislator gives is the one described above: standards, common specifications, and national competent authorities were not ready in time.

The same regulation builds a bridge for assessment capacity. Notified bodies already notified under the product legislation in Section A of Annex I may assess high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry → against the requirements in Chapter III, Section 2, provided their compliance with parts of Article 31 was assessed during their existing notification. Those bodies must apply for designation under the AI Act by 28 January 2028.

How to judge a certificate

Three questions settle the value of any AI credential, and none of them concerns the logo.

First, which object does it cover: a person, a management system, or an AI system. Second, who made the assessment. Third, what qualifies or authorizes that assessor to make the decision.

The third question has a concrete answer per layer. For a person, it is accreditation of the certification body and its scheme against ISO/IEC 17024. For a management system, it is an accredited certification body working under ISO/IEC 17021-1 and ISO/IEC 42006, with a published scope that covers the service. For an AI system, it is the provider itself where internal control is permitted, or a notified body designated by a member state and listed in NANDO with an explicit AI Act scope.

Two practical checks follow for anyone assessing someone else's certificate. Read the scope statement first. A management system certificate names the legal entity, the sites, and the services it covers, and a group certificate does not automatically extend to the subsidiary you are contracting with or to the AI service you are buying. Second, remember that obligations do not travel with the certificate. A supplier's ISO/IEC 42001 certificate says something about that supplier's governance. It does not discharge your own duties as a deployerdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry →.

Frameworks are a separate case. NIST AI RMFNIST AI RMFThe AI Risk Management Framework of the US National Institute of Standards and Technology, published as version 1.0 in 2023. It is a voluntary framework built around four functions: govern, map, measure, and manage. In a layered setup, it serves as the risk method inside a management system such as ISO/IEC 42001. See ISO/IEC 42001, ISO/IEC 23894.Open full entry →, ISO/IEC 23894ISO/IEC 23894The international guidance standard for AI risk management, published in 2023. It applies the general risk management principles of ISO 31000 to AI and is guidance, not a certifiable requirements standard. It complements the NIST AI RMF as a risk method within a broader management system. See NIST AI RMF, ISO/IEC 42001.Open full entry →, and the OECD AI PrinciplesOECD AI PrinciplesThe intergovernmental principles for trustworthy AI adopted by the OECD in 2019 and updated in 2024. They set value-based expectations such as transparency, accountability, and human-centered values, and have shaped later frameworks and legislation. See responsible AI.Open full entry → carry no certification scheme at all, so no organization can hold a certificate against them, although training providers may issue their own course certificates based on them. COBIT sits in between: there is no organizational certification, but the framework owner issues person-level certificates.

What a certificate does not prove

Each conclusion is bounded by its own scope and its own date. A personnel certification reports an assessment of a person's competence against the rules of its scheme. A management system certificate reports that a defined organizational system was audited against a standard. A conformity assessment reports that a particular AI system went through the procedure the law prescribes.

For a management system certificate, external audits sample both design and operation. They test on a sample, in a window, against a scope statement. What they do not do is relieve the organization of producing and reviewing evidence between audit moments.

Something continues after every assessment, and it differs per object. A person maintains a credential through continuing education and, in some schemes, recertification. An organization faces surveillance and recertification audits and carries its own evidence in the intervals. A provider runs post-market monitoringpost-market monitoringProvider-side duty to systematically collect and act on experience from systems in use, the product-regulation half of continuous monitoring.Open full entry → under Article 72, reports serious incidentsserious incidentAn AI incident causing (or nearly causing) death, serious harm to health, property, fundamental rights or infrastructure. It triggers regulatory reporting duties for high-risk systems.Open full entry → under Article 73, and needs a new conformity assessment when a system is substantially modified.

Holding controls is not the same as being in control, and no certification body will make the second claim for you.

Frequently asked questions

What is the difference between AI certification and AI Act conformity assessment?
Certification is a voluntary assessment by an accredited body against a published standard. Conformity assessment under the EU AI Act is a legal procedure that a provider must complete before placing a high-risk AI system on the market, and its market-facing result is a CE marking rather than a certificate.
Does ISO/IEC 42001 certification make an organization EU AI Act compliant?
No. ISO/IEC 42001 is a management system standard, not a technical specification for individual AI systems, and certification against it does not create a legal presumption of conformity with the AI Act.
What is ISO/IEC 42006?
It is the standard that sets requirements for the bodies that audit and certify AI management systems against ISO/IEC 42001. It governs the auditor, not the organization under audit.
Which AI certification should I take?
Start from your role rather than from the market. Auditors extend an existing audit designation, security managers extend a security designation, and professionals entering AI governance from privacy, legal, or compliance usually start with a governance credential that has no prerequisite.
Can an individual AI system be certified under the EU AI Act?
On the third-party route, yes. A notified body assessing a system under Annex VII issues a certificate under Article 44, valid for at most five years for Annex I systems and four years for Annex III systems, and subject to suspension or withdrawal. On the internal control route under Annex VI, which covers most stand-alone high-risk systems, no certificate is issued. In both cases the system carries a CE marking and an EU declaration of conformity.
What is the difference between a certificate and a certification?
A course certificate records completion of a learning program. A professional certification is a formal competence decision under a defined certification scheme, normally involving an independent examination and requirements for maintaining the credential. Some schemes also verify experience, and some are themselves accredited.
Does the AI Act require an organization to certify its staff?
No. Article 4 requires providers and deployers to take measures that support the development of AI literacy among their staff and among others who operate AI systems on their behalf. As amended by Regulation (EU) 2026/1744, the article states that this obligation does not require anyone to guarantee a specific level of AI literacy in any individual. Certification is one way to build competence, not a legal requirement.
Can you be certified against the NIST AI RMF?
No. The framework is voluntary and carries no certification scheme. A training provider can issue a course certificate based on it, which is a different claim.
Continue withAccountability
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.

Control-level compliance: the EU AI Act as an instrumented system

Analysis

Control-level compliance means satisfying the EU AI Act through engineered, evidenced controls rather than policy documents. The technical articles translate directly into system controls: automatic, retained logs (Art. 12, 19), a stop function to a safe state (Art. 14(4)(e)), input masking before the model as a GDPR and Art. 26(4) control, configurable block policies (Art. 26), risk scoring and incident reporting within deadline (Art. 9, 73), and workspace isolation with role-based access (Art. 14, 26). Compliance at this level is an instrumented system, not a policy as PDF.