What ISO/IEC 42001 Certification Requires, and Why On-Premise AI Makes It Easier to Pass
ISO/IEC 42001 requires an audited AI management system, and on-premise AI turns several Annex A controls into evidence generated automatically.

ISO/IEC 42001 certification requires an organisation to build, operate and continually improve an AI management system, and to evidence a defined set of Annex A controls covering data provenance, logging, AI system impact assessment, transparency and accountability. On-premise AI makes certification easier because several of those controls are proven by records the system produces automatically when the model runs on hardware you own and log. An auditor can inspect real provenance trails and event logs instead of accepting a cloud vendor's attestation. The management system work still has to be done, but the technical evidence is generated at source rather than requested from a third party.
The question matters in 2026 because regulated buyers are being asked to certify AI governance at the same moment the rules beneath them tighten. ISO/IEC 42001, published in December 2023, has become the reference framework that auditors and procurement teams cite when they ask how an organisation controls its AI. Where the model runs, and who holds the logs, now decides how much of the certification evidence sits under your own control.
What does ISO/IEC 42001 actually require?
ISO/IEC 42001 is a management system standard, structured like ISO 27001. The core clauses require leadership commitment, a defined scope, risk and impact assessment, documented objectives, operational controls, monitoring, internal audit and management review. Certification is granted by an accredited body after a two-stage audit and is maintained through surveillance audits.
The substance for AI teams sits in Annex A. Its controls include data quality and provenance for training and operation, logging and event recording, AI system impact assessments, transparency to affected parties, allocation of responsibilities, and management of third-party and supplier risk. To pass, you show both that a policy exists and that the control operates in practice with records to prove it.
How does running AI on your own hardware change the evidence?
Three Annex A control areas move from paperwork to primary evidence when the AI runs on infrastructure you own. Data provenance is recorded because the data never leaves your estate, so lineage is a fact of the system rather than a claim about someone else's. Logging is complete because every inference, input and model version is written to a ledger you hold. Impact assessment is grounded because the real inputs, outputs and decisions are available for inspection.
When the same workload runs through a public cloud AI service, that evidence is mediated. You inherit the provider's shared-responsibility model and its retention policy, and you certify against records you cannot independently reconstruct. On-premise operation collapses that gap.
What can an auditor check on operator-owned hardware?
An auditor can run a simple test: pick a past decision and ask the operator to reproduce it. On owned hardware the answer is a reconstruction from the local ledger, showing the input, the model version, the time, the identity that invoked it and the output, all sealed. The named check is point-in-time reconstruction with an unbroken log chain.
They can also verify log continuity, confirm that data did not egress the boundary, and confirm that identities acting on the system are attested rather than asserted. These are the questions Annex A logging and accountability controls are written to answer, and they are answerable directly.
Which controls does public cloud AI make harder to evidence?
Regulated buyers frequently cannot use ChatGPT, Claude or Gemini for sensitive workloads, and certification is one reason. Under the US CLOUD Act, data held by a US-based provider can be subject to lawful access requests regardless of where the servers sit, which complicates the data governance and cross-border controls an ISO/IEC 42001 auditor examines. Provenance and logging evidence produced by a provider is also evidence you do not fully control, which weakens the accountability chain.
This is an architectural point, not an accusation. Cloud AI services are engineered for scale and convenience. Certification rewards a different property: the ability to prove, from records you hold, exactly what the system did.
Which 2026 rules make this necessary?
ISO/IEC 42001 does not stand alone. DORA, in force since January 2025, imposes operational resilience and third-party oversight on financial entities. NIS2 extends cybersecurity duties to essential and important entities across the economy. GDPR governs personal data throughout. The EU AI Act adds AI-specific obligations, and the timeline shifted: the high-risk Annex III obligations, once due on 2 August 2026, were deferred by the Digital Omnibus to 2 December 2027, with embedded Annex I high-risk systems moving to 2 August 2028 and Article 50 transparency duties largely unchanged. We read that as a build window, not a reprieve. An AI management system certified to ISO/IEC 42001 is the scaffold that carries all of these.
“When the intelligence runs on hardware you own and log, ISO/IEC 42001 evidence stops being a vendor's promise and becomes a record you can produce on demand.”
How does a Sovereign Intelligence Operating System evidence these controls?
Mickai is a Sovereign Intelligence Operating System, a SIOS. It runs offline on operator-owned hardware behind a zero-egress inbound perimeter, so data provenance and residency are structural. Every action is written to a tamper-evident audit ledger sealed with post-quantum signatures under FIPS 204 (ML-DSA), which makes the log independently verifiable years after the fact. Identity is hardware-attested and bound to the audit chain, so the actor behind each decision is proven rather than asserted. Sensitive outputs can be checked by cross-model consensus before they are relied upon. The underlying sovereign models are ours and run wholly within the boundary. This architecture is protected by 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD and patent pending. The result maps the Annex A controls an auditor tests directly onto records the system already keeps.
Frequently asked questions
Does ISO/IEC 42001 require on-premise AI?
No. ISO/IEC 42001 is technology neutral and can be certified whether AI runs in the cloud or on your own hardware. On-premise operation makes certain controls easier to evidence, because data provenance, logging and impact assessment records are produced automatically inside a boundary you control rather than requested from a provider.
Is ISO/IEC 42001 certification mandatory?
No. It is a voluntary certification rather than a law. In practice it is increasingly demanded by procurement teams and auditors as proof of AI governance, and it supports compliance with binding regimes such as GDPR, DORA, NIS2 and the EU AI Act without replacing any of them.
Does ISO/IEC 42001 satisfy the EU AI Act?
Not on its own. ISO/IEC 42001 gives you the management system, risk process and controls that the EU AI Act's obligations build on, so it makes conformity work far easier. It is not a substitute for the Act's specific high-risk requirements, whose main obligations now fall due on 2 December 2027 following the Digital Omnibus deferral.
Can you certify to ISO/IEC 42001 while using ChatGPT or Claude?
Yes, certification is possible, but some Annex A controls become harder to evidence. Provenance and logging depend on the provider's records and shared-responsibility model, and cross-border data questions under the US CLOUD Act add scope. Running the model on operator-owned hardware removes that dependency and keeps the evidence in your hands.
How long does ISO/IEC 42001 certification take?
Timelines vary with organisation size and AI maturity, and typically run over several months across gap analysis, implementation, the two-stage audit and closing findings. The technical evidence stage is usually faster when logging and provenance are generated automatically at source, because there is less to assemble by hand before the auditor arrives.