International

ISO/IEC 42006:2025

77 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

77 controls 0 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
10.1Management system options0
10.2Option A: general management system requirements0
10.3Option B: management system in accordance with ISO 90010
2-3Normative references and terms0
4Principles0
5.1Legal and contractual matters0
5.2Management of impartiality0
5.2.2Conflicts of interest0
5.2.2.1No consultancy in AI, information security, data protection or risk management for ISO/IEC 42001 clients0
5.2.2.2Activities that are not conflicts of interest0
5.2.2.3Activities that are conflicts of interest, and no internal audits0
5.3Liability and financing0
5.3.2Liability cover proportionate to clients' turnover0
6Structural requirements0
7.1Competence of personnel0
7.1.1Competence requirements of ISO/IEC 17021-1 plus the AIMS technical competence of 7.1.2 and 7.1.30
7.1.2Generic technical competence requirements and Table 10
7.1.3Specific technical competence requirements0
7.1.3.1General requirements for AIMS0
7.1.3.1.1Auditing: general AIMS skills of every audit team member and of the team collectively0
7.1.3.1.2Reviewing reports and deciding: general AIMS knowledge0
7.1.3.2AIMS standards, normative documents and certification schemes0
7.1.3.2.1Auditing: knowledge of ISO/IEC 42001, documentation structures, normative documents and schemes; Annex A controls collectively0
7.1.3.2.2Reviewing reports and deciding: knowledge of the standards and schemes0
7.1.3.2.3Application review, team selection and audit time: knowledge of the standards and schemes0
7.1.3.3AI and AIMS related legal obligations0
7.1.3.3.1Auditing: knowledge of the legal obligations applying to AI0
7.1.3.3.2Reviewing reports and deciding: knowledge of AI legal obligations0
7.1.3.3.3Application review, team selection and audit time: knowledge of AI legal obligations0
7.1.3.4AI and AIMS specific terminology, principles, practices, tools, methods and techniques0
7.1.3.4.1Auditing: AI terminology, principles, practices, tools, methods and techniques0
7.1.3.4.2Reviewing reports and deciding: AI terminology, principles, practices, tools, methods and techniques0
7.1.3.4.3Application review, team selection and audit time: AI terminology, principles, practices, tools, methods and techniques0
7.1.3.5Client business sector0
7.1.3.5.1Auditing: knowledge of the client's business sector0
7.1.3.5.2Reviewing reports and deciding: knowledge of the client's business sector0
7.1.3.5.3Application review, team selection and audit time: knowledge of the client's business sector0
7.1.3.6Client products, processes and organization0
7.1.3.6.1Auditing: knowledge of the client's products, processes and organization0
7.1.3.6.2Reviewing reports and deciding: knowledge of the client's products, processes and organization0
7.2Personnel involved in the certification activities0
7.2.2Demonstration of knowledge and experience0
7.3Use of individual external auditors and external technical experts0
7.4Personnel records0
7.5Outsourcing0
8.1Public information0
8.2Certification documents0
8.2.2AIMS certification documents0
8.3Reference to certification and use of marks0
8.4Confidentiality0
8.4.2Access to the documentation of the organization0
8.5Information exchange between a certification body and its clients0
9.1Pre-certification activities0
9.1.2Audit programme0
9.1.3Scope of certification0
9.1.4Determining audit time0
9.1.5Multi-site sampling0
9.1.6Multiple management systems0
9.2Planning audits0
9.2.1Determining audit objectives, scope and criteria0
9.2.2Audit team selection and assignments0
9.2.3Audit plan0
9.2.4Deployment of remote audit0
9.3Initial certification0
9.3.2Initial certification audit0
9.4Conducting audits0
9.5Certification decision0
9.6Maintaining certification0
9.6.2Surveillance activities0
9.6.3Re-certification0
9.6.4Special audits0
9.6.5Suspending, withdrawing or reducing the scope of certification0
9.7Appeals0
9.8Complaints0
9.9Client records0
AAnnex A (normative): Audit time0
B-CAnnexes B and C (informative): examples for audit time calculations; template for a certification document0

Tell me when ISO/IEC 42006:2025 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Investigation procedure
  • Case files
  • Closure reports
  • Corrective action records
  • Management system documentation and records
  • Internal audit and management review records covering AIMS certification

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 42006:2025, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition