MICKAI®ArticlesWhat ISO/IEC 42001 Certification …
Article · 18 August 2026

What ISO/IEC 42001 Certification Requires, and Why On-Premise AI Makes It Easier to Pass

ISO/IEC 42001 requires an audited AI management system, and on-premise AI turns several Annex A controls into evidence generated automatically.

Author
Micky Irons
Published
18 August 2026
Follow Micky Irons
LinkedInX
iso 42001ai management systemon-premise aiai complianceai governance
What ISO/IEC 42001 Certification Requires, and Why On-Premise AI Makes It Easier to Pass

ISO/IEC 42001 certification requires an organisation to build, operate and continually improve an AI management system, and to evidence a defined set of Annex A controls covering data provenance, logging, AI system impact assessment, transparency and accountability. On-premise AI makes certification easier because several of those controls are proven by records the system produces automatically when the model runs on hardware you own and log. An auditor can inspect real provenance trails and event logs instead of accepting a cloud vendor's attestation. The management system work still has to be done, but the technical evidence is generated at source rather than requested from a third party.

The question matters in 2026 because regulated buyers are being asked to certify AI governance at the same moment the rules beneath them tighten. ISO/IEC 42001, published in December 2023, has become the reference framework that auditors and procurement teams cite when they ask how an organisation controls its AI. Where the model runs, and who holds the logs, now decides how much of the certification evidence sits under your own control.

What does ISO/IEC 42001 actually require?

ISO/IEC 42001 is a management system standard, structured like ISO 27001. The core clauses require leadership commitment, a defined scope, risk and impact assessment, documented objectives, operational controls, monitoring, internal audit and management review. Certification is granted by an accredited body after a two-stage audit and is maintained through surveillance audits.

The substance for AI teams sits in Annex A. Its controls include data quality and provenance for training and operation, logging and event recording, AI system impact assessments, transparency to affected parties, allocation of responsibilities, and management of third-party and supplier risk. To pass, you show both that a policy exists and that the control operates in practice with records to prove it.

How does running AI on your own hardware change the evidence?

Three Annex A control areas move from paperwork to primary evidence when the AI runs on infrastructure you own. Data provenance is recorded because the data never leaves your estate, so lineage is a fact of the system rather than a claim about someone else's. Logging is complete because every inference, input and model version is written to a ledger you hold. Impact assessment is grounded because the real inputs, outputs and decisions are available for inspection.

When the same workload runs through a public cloud AI service, that evidence is mediated. You inherit the provider's shared-responsibility model and its retention policy, and you certify against records you cannot independently reconstruct. On-premise operation collapses that gap.

What can an auditor check on operator-owned hardware?

An auditor can run a simple test: pick a past decision and ask the operator to reproduce it. On owned hardware the answer is a reconstruction from the local ledger, showing the input, the model version, the time, the identity that invoked it and the output, all sealed. The named check is point-in-time reconstruction with an unbroken log chain.

They can also verify log continuity, confirm that data did not egress the boundary, and confirm that identities acting on the system are attested rather than asserted. These are the questions Annex A logging and accountability controls are written to answer, and they are answerable directly.

Which controls does public cloud AI make harder to evidence?

Regulated buyers frequently cannot use ChatGPT, Claude or Gemini for sensitive workloads, and certification is one reason. Under the US CLOUD Act, data held by a US-based provider can be subject to lawful access requests regardless of where the servers sit, which complicates the data governance and cross-border controls an ISO/IEC 42001 auditor examines. Provenance and logging evidence produced by a provider is also evidence you do not fully control, which weakens the accountability chain.

This is an architectural point, not an accusation. Cloud AI services are engineered for scale and convenience. Certification rewards a different property: the ability to prove, from records you hold, exactly what the system did.

Which 2026 rules make this necessary?

ISO/IEC 42001 does not stand alone. DORA, in force since January 2025, imposes operational resilience and third-party oversight on financial entities. NIS2 extends cybersecurity duties to essential and important entities across the economy. GDPR governs personal data throughout. The EU AI Act adds AI-specific obligations, and the timeline shifted: the high-risk Annex III obligations, once due on 2 August 2026, were deferred by the Digital Omnibus to 2 December 2027, with embedded Annex I high-risk systems moving to 2 August 2028 and Article 50 transparency duties largely unchanged. We read that as a build window, not a reprieve. An AI management system certified to ISO/IEC 42001 is the scaffold that carries all of these.

When the intelligence runs on hardware you own and log, ISO/IEC 42001 evidence stops being a vendor's promise and becomes a record you can produce on demand.

How does a Sovereign Intelligence Operating System evidence these controls?

Mickai is a Sovereign Intelligence Operating System, a SIOS. It runs offline on operator-owned hardware behind a zero-egress inbound perimeter, so data provenance and residency are structural. Every action is written to a tamper-evident audit ledger sealed with post-quantum signatures under FIPS 204 (ML-DSA), which makes the log independently verifiable years after the fact. Identity is hardware-attested and bound to the audit chain, so the actor behind each decision is proven rather than asserted. Sensitive outputs can be checked by cross-model consensus before they are relied upon. The underlying sovereign models are ours and run wholly within the boundary. This architecture is protected by 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD and patent pending. The result maps the Annex A controls an auditor tests directly onto records the system already keeps.

Frequently asked questions

Does ISO/IEC 42001 require on-premise AI?

No. ISO/IEC 42001 is technology neutral and can be certified whether AI runs in the cloud or on your own hardware. On-premise operation makes certain controls easier to evidence, because data provenance, logging and impact assessment records are produced automatically inside a boundary you control rather than requested from a provider.

Is ISO/IEC 42001 certification mandatory?

No. It is a voluntary certification rather than a law. In practice it is increasingly demanded by procurement teams and auditors as proof of AI governance, and it supports compliance with binding regimes such as GDPR, DORA, NIS2 and the EU AI Act without replacing any of them.

Does ISO/IEC 42001 satisfy the EU AI Act?

Not on its own. ISO/IEC 42001 gives you the management system, risk process and controls that the EU AI Act's obligations build on, so it makes conformity work far easier. It is not a substitute for the Act's specific high-risk requirements, whose main obligations now fall due on 2 December 2027 following the Digital Omnibus deferral.

Can you certify to ISO/IEC 42001 while using ChatGPT or Claude?

Yes, certification is possible, but some Annex A controls become harder to evidence. Provenance and logging depend on the provider's records and shared-responsibility model, and cross-border data questions under the US CLOUD Act add scope. Running the model on operator-owned hardware removes that dependency and keeps the evidence in your hands.

How long does ISO/IEC 42001 certification take?

Timelines vary with organisation size and AI maturity, and typically run over several months across gap analysis, implementation, the two-stage audit and closing findings. The technical evidence stage is usually faster when logging and provenance are generated automatically at source, because there is less to assemble by hand before the auditor arrives.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/iso-42001-certification-on-premise-ai. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles
18 Aug 2026
How Telecoms Operators Meet the Telecommunications Security Act With AI That Never Leaves the Network
Telecoms operators meet the Telecommunications Security Act code of practice with AI that runs inside the security-critical boundary on operator-owned hardware. A zero-egress perimeter keeps network configuration and signalling data within operator control, so nothing sensitive crosses out to a public cloud service.
18 Aug 2026
Can energy operators run AI on grid and OT data on-premise to satisfy the Cyber Assessment Framework?
Yes. Energy operators can run forecasting and anomaly detection on grid and OT data entirely on their own hardware, and this satisfies the Cyber Assessment Framework more cleanly than cloud analytics, because telemetry never leaves the audited perimeter and no third-party processor exists to assess.
18 Aug 2026
How Airports Meet EASA Part-IS from February 2026 with On-Site AI
Part-IS applies to aerodrome operators from 22 February 2026 and makes the airport, not its vendor, accountable for information-security risk. Running AI on operator-owned hardware behind a zero-egress perimeter keeps passenger and operational data inside that boundary, so a supplier's SOC 2 cannot discharge it.
18 Aug 2026
Can Automotive Suppliers Use AI on OEM Design Data While Keeping TISAX Prototype Protection?
Automotive suppliers can run AI on OEM design and prototype data and keep TISAX prototype protection, but only when the model runs on their own hardware inside the protected zone. Public cloud AI transmits the data outward, which prototype protection forbids.