Where certification programmes go wrong.
The programme, gated in order.
Three routes to an audit.
A provider preparing a first 42001 certification.
- Establish, then map, then operate — phases gate in that order.
- The SoA fills as steps complete, with exclusions justified in place.
- Art. 17 checklist items tick where the system genuinely carries them.
- The pack exports sealed, with an integrity manifest.
A company already certified to ISO 27001.
- Fourteen records count toward both standards — a large head start, not a fresh project.
- Approving one re-plans the other programme.
- Clause 4 to 10 structures line up, so scope and context are written once.
- A step your ISO 27001 work already covers is Done, credited — never done twice.
A team asked for an SoA by a customer's security review.
- The SoA is a view, so it is current the moment the programme is.
- Applied and excluded controls, each with its reason.
- Exported without assembling anything by hand.
- It states what is assigned, not what is implemented — the distinction an auditor will test.
What sits beside the programme.
Straight answers about certification.
Does ISO/IEC 42001 make us EU AI Act compliant?
No, and anyone who tells you otherwise is selling something. A certified management system is strong evidence of governance, but requirement equivalence needs a harmonised standard cited in the Official Journal, and prEN 18286 is not there yet. Article 17(3) does let providers already subject to quality-management obligations under sectoral Union law fold the Article 17(1) aspects into that system — but a voluntary standard is not sectoral Union law, so 42001 does not open that route.
What is the Statement of Applicability, exactly?
The record of which Annex A controls you apply, which you exclude and why. In Veritome it is a view over the programme rather than a separate spreadsheet: the steps you have completed produce it, so it cannot drift from the work. An exclusion needs a justification sentence — a blank one will not pass an auditor and does not pass here either.
We already hold ISO 27001. Does that help?
Substantially. Fourteen of the record templates carry a second placement, so completing one satisfies the equivalent step in both programmes — one record, two programmes, and approving it re-plans the sibling. The clause structures share the same 4 to 10 spine.
How does the audit pack come together?
From the same register the programme runs on. Controls carry the evidence that proves them, policies carry owners and review dates, and the pack exports as a sealed PDF with an integrity manifest — the SHA-256 of every source document, so the bundle is tamper-evident.
Can Veritome issue the certificate?
No. Certification is issued by an accredited body after an audit, and no software can grant it. What Veritome does is get the management system into a state where the audit is about your organisation rather than about your paperwork.


