Open research, August 2026
The Only Public Crosswalk to ISO 42001 Names Zero of Its Controls
Organisations are being asked to prove their AI governance with an ISO/IEC 42001 certificate. We measured what a buyer can actually establish about one from public evidence. The single public domain crosswalk into the standard never references a control from the annex that certification audits examine, and it maps to the draft rather than the published edition. The standard was certifiable for roughly nineteen months before the rules for certifying the certifiers existed. And the national register that granted the world's first accreditation for it does not record that accreditation anywhere.
The short version
- 281 crosswalk pairs, zero Annex A controls. NIST's AI RMF to ISO/IEC 42001 crosswalk covers 72 AI RMF subcategories through 66 distinct ISO addresses. 202 of those references are Annex B implementation guidance and 79 are mandatory clauses. Not one is a control from Annex A.
- It maps the draft. The document's own printed title is "NIST AI RMF to ISO/IEC FDIS 42001". FDIS is the Final Draft International Standard, not the published 42001:2023.
- Nineteen months of certificates with no scheme behind them. ISO/IEC 42001 published December 2023. ISO/IEC 42006, which defines what a competent certification body must demonstrate, published 7 July 2025.
- The UKAS register records ISO/IEC 42001 nowhere. Zero occurrences across 9,278 harvested records, nine months after BSI announced the world's first UKAS accreditation for that exact standard.
- You cannot look a supplier up. IAF CertSearch does not permit listing certificates by certification body. Absence is unobservable by design.
- The artefact reproduces no ISO text. All 281 ISO titles carried by the source PDF are discarded at ingest, and a test asserts none survives.
0 of 38
Annex A controls referenced by the public crosswalk
19 months
certifiable before ISO/IEC 42006 was published
0
occurrences of 42001 in the UKAS public register
FDIS
edition the NIST crosswalk actually targets
Why this question is worth asking now
ISO/IEC 42001 is becoming the default answer to a question buyers have started asking, which is how do I know your AI is governed. It is a genuinely useful standard and this is not an argument against it. It is an argument for reading the certificate properly, because the infrastructure that would let you do so is younger and thinner than the marketing around it suggests.
We built this the same way as our ISO/IEC 27001 work, and for the same reason. If you want to reason about a standard you are not allowed to redistribute, you model it by address rather than by text. Control addresses like A.6 and B.2.2 are references in the way a page number is a reference. That discipline is what makes an open, reproducible measurement possible at all.
The crosswalk that cannot build a Statement of Applicability
NIST publishes a crosswalk from its AI Risk Management Framework to ISO/IEC 42001. It is a United States Government work in the public domain, which makes it the only crosswalk into this standard that anyone can freely redistribute, extend or build a product on. That matters, because the commercial alternatives sit under licences that forbid derivative work.
We parsed all sixteen pages and reduced them to address pairs, discarding every ISO title on the way in.
66 distinct ISO addresses across 72 AI RMF subcategories. Annex A is the normative control catalogue.
A Statement of Applicability is a declaration about Annex A controls. Which ones apply, which ones do not, and the justification for each exclusion. It is the document a certification audit works through. It is the artefact that determines what your certificate actually covers.
The crosswalk never mentions one. Follow it from an AI RMF subcategory and you arrive at an Annex B guidance address or a clause number, and you then have to make a further hop to reach the control you must declare. Annex B is numbered to correspond to Annex A, so that hop is usually mechanical. But the crosswalk never says so and never performs it, which means every tool that ingests this document to generate a Statement of Applicability is inferring the most important step and not showing its work. If you are buying such a tool, ask the vendor which document supplied their Annex A mapping. It was not this one.
There is a second problem visible on the front page. The document is titled "NIST AI RMF to ISO/IEC FDIS 42001 AI Management system Crosswalk". FDIS means Final Draft International Standard, the version that circulates before publication. This is the second time we have found a NIST crosswalk into an ISO management system standard addressing something other than the current published edition. The first was the SP 800-53 to ISO/IEC 27001 mapping, which addressed the superseded 2013 edition of that standard and has since been withdrawn from the NIST site entirely.
The nineteen month gap
Two standards are in play, and conflating them is the most common error in this area. ISO/IEC 42001 tells your organisation what an AI management system must do. ISO/IEC 42006 tells the certification body what it must demonstrate in order to audit and certify you competently. Accreditation bodies assess certification bodies against the second, never against the first.
| Date | Event |
|---|---|
| December 2023 | ISO/IEC 42001 published. Certification becomes commercially available at once. |
| 24 September 2024 | ANAB grants its first ISO/IEC 42001 accreditation, to Schellman. |
| December 2024 | RvA accredits BSI for ISO/IEC 42001. |
| 7 July 2025 | ISO/IEC 42006:2025 published, setting out what a certification body must demonstrate. |
| 17 November 2025 | BSI announces it is the first certification body in the world accredited by UKAS for ISO/IEC 42001. |
| 10 March 2026 | BSI announces ANAB accreditation, becoming the first accredited by UKAS, ANAB and RvA together. |
Read the first row against the bold one. For roughly nineteen months, organisations bought and certification bodies sold certificates against ISO/IEC 42001 while the standard defining a competent certifier had not been published. Accreditations granted in that window were assessed against earlier and more general requirements, and the Standards Council of Canada has since confirmed that new applications and scope extensions are assessed against ISO/IEC 42006:2025.
None of that makes an early certificate worthless and none of it implies anyone behaved improperly. It means the assurance behind an early certificate is different from the assurance behind one issued today, and a buyer who does not know the timeline has no way to tell them apart.
A register that does not record what it granted
UKAS publishes a genuinely open register, with no key and no account required, and that is more than most national accreditation bodies manage. We harvested every collection to its declared total: 2,921 accredited organisations, 2,986 schedules, 3,336 scope categories.
The string 42001 appears in none of them. A live query against the register's own standard vocabulary returns an empty array, and the only artificial intelligence entry in that vocabulary is a single term named simply AI, classifying one record.
So the United Kingdom's national accreditation body granted what BSI describes as the world's first UKAS accreditation for ISO/IEC 42001, announced it in November 2025, and nine months later its own public register carries no machine readable trace of it. That is not an allegation of wrongdoing. It is a practical warning: you cannot confirm an accreditation claim for this standard by searching the register, so you will have to ask the certification body directly and read the schedule they send you.
The number we refused to publish
We wanted to give a per objective breakdown of Annex A, showing how many controls sit under each of the nine objectives from A.2 to A.10. The total of 38 is consistent everywhere. The split is not. Secondary sources give A.6 as both eight and nine controls, A.8 as both four and five, A.10 as both two and three, and their totals do not reconcile to 38.
Settling it requires the standard, which is sold and which we will not reproduce. So the breakdown is absent from the report and from this page. We mention it because it is a smaller version of the same problem: even the shape of the control catalogue is not something a practitioner can establish from public sources, and the confident tables you will find elsewhere disagree with each other.
Three questions that make a claim checkable
If you are writing ISO/IEC 42001 into a contract or assessing a supplier who claims it, ask for these together. Any one of them on its own is unfalsifiable.
- The certificate number. Without it no register query can be formed at all, and IAF CertSearch will not help you form one because it cannot be browsed.
- The certification body, its accreditation body, and the date it obtained accreditation for ISO/IEC 42001 specifically. Compare that date against the certificate issue date. Accreditation for ISO/IEC 27001 or ISO 9001 does not carry across to this standard.
- The Statement of Applicability, or at minimum the list of excluded Annex A controls. A certificate tells you nothing about which of the 38 controls the holder declared out of scope, and no public crosswalk will tell you either.
Method and limits
The crosswalk was parsed with pdfplumber and reduced to address pairs, with all 281 ISO titles discarded at ingest and a test asserting that none survives anywhere in the dataset. The UKAS register was harvested through its public REST API with every collection reconciled against the record total the API itself declares, and the 42001 result confirmed by an independent live query.
Two registers could not be read. The ANAB accreditation directory returns HTTP 403 to any programmatic request, with and without a browser user agent. The RvA register was not obtained. Because of that, this work makes no claim whatsoever about the total number of accredited ISO/IEC 42001 certification bodies worldwide, and no such number appears anywhere in it. The timeline entries come from published announcements and are dated accordingly.
One correction was needed during the build and is recorded rather than quietly fixed. A secondary source placed BSI's first UKAS accreditation in January 2026. The BSI announcement itself is dated 17 November 2025, and the earlier figure was discarded before it was used anywhere.
The artefact
The repository is at github.com/fabio-rovai/ai-management-system-assurance. It holds the extractor, the extracted crosswalk as JSON, the granular report with the full per subcategory table, offline known answer tests including the assertion that no ISO title survives ingest, and continuous integration that re-extracts from the source PDF on every push. Code MIT, report CC BY 4.0. The companion repository certification-register-ontology applies the same method to ISO/IEC 27001, and proves the no standard text property with a SHACL layer.
Where to start
A bounded first engagement is a two week AI assurance claim audit on one supplier population. We take your supplier list, extract every AI governance and certification claim, classify each by whether it can be checked at all, run the checks that can be run, and hand back the evidence with the method. The deliverable is a defensible statement of what you can and cannot establish, which is more useful than a dashboard implying you can establish everything.
There is also a free course covering this material in depth, including the accreditation timeline and the checks above, on tesseract.academy.
Fabio Rovai, fabio@thetesseractacademy.com. Corrections are published on this page rather than applied silently.
