ISO/IEC 42001 certification in Italy: the map of Accredia-accredited bodies
Who can certify in Italy today, how to verify a supplier's certificate in minutes, what actually drives audit time and cost, and why scope is the decision that matters most.
In short. An ISO/IEC 42001 certificate carries weight in a due diligence, a public tender or before a regulator when it comes from an accredited body, which in Italy means accredited by Accredia. Accreditation specific to this standard was made possible by Accredia technical circular DC No. 08/2026, integrating ISO/IEC 17021-1 with ISO/IEC 42006. Below: who can certify today, how to verify somebody else's certificate, what drives time and cost, and why the scope is the decision that matters most.
Anyone, in principle, can issue a document attesting conformity with an ISO standard, and what changes that document's value is the accreditation of the body issuing it. For ISO/IEC 42001 in Italy, specific accreditation only arrived in 2026. Before then, certificates existed from serious bodies lacking that formal recognition.
ZeroFive is not a certification body and issues no certificates: we support companies in preparing for the path, and knowing who can certify is the first filter in the choice.
Why accreditation matters
Accreditation guarantees that the certification body has itself been verified against shared international rules, with competence, impartiality and procedures under control. In Italy the single accreditation body is Accredia, and an accredited certificate is recognised in tenders, in customer checks and in dealings with authorities, while a non-accredited certificate remains a private attestation.
Recognition doesn't stop at national borders. International mutual recognition arrangements mean a certificate issued by a body accredited by a foreign signatory carries the same value as one accredited by Accredia, which matters when assessing an overseas supplier. What needs verifying in that case is that the accreditation body is genuinely a signatory and that the accreditation covers ISO/IEC 42001 rather than management systems generally.
Technical circular DC No. 08/2026
Accredia technical circular DC No. 08/2026, which opened the way to accrediting bodies for ISO/IEC 42001, integrates the general requirements of UNI CEI EN ISO/IEC 17021-1, applying to all bodies certifying management systems, with those of ISO/IEC 42006, the standard setting requirements for those auditing and certifying AI management systems, including reference to the Annex A controls and Annex B guidance of ISO/IEC 42001. From that point bodies could apply for specific accreditation.
There's a practical consequence for certificates issued earlier too. A company certified by a body that couldn't be accredited for this standard at the time doesn't hold a worthless document, it holds one worth bringing under accreditation at the first renewal, because that's what customers will start asking for.
The accredited bodies
| Body | Note |
|---|---|
| CSQA | First body accredited in Italy for ISO/IEC 42001 |
| Bureau Veritas | Accredited |
| DNV | Accredited |
| TÜV Italia | Accredited |
| ACM CERT | Accredited |
The list reflects the position at the date of publication and is set to grow, so the source to consult remains the Accredia database.
How to verify a certificate
Anyone receiving a supplier's certificate and wanting to know what it's worth has a check available that takes a few minutes, and that's worth making a standard part of supplier qualification.
The first check is against the Accredia database, looking up the body that issued the document and verifying the accreditation covers ISO/IEC 42001 specifically. The second is on the scope stated on the certificate, compared against the activity you're assessing that supplier for: a certificate valid for the Milan site doesn't cover a plant in another country, and one covering software development doesn't necessarily cover the AI system the supplier uses to run your service.
The third is on validity dates and status, because a certificate may have been suspended or withdrawn in the meantime, and that information doesn't appear on the paper document. The fourth, where needed, is a direct enquiry to the body, which confirms the certificate's existence and status.
Scope, the decision that matters most
Scope is the part of the certificate almost nobody discusses enough during preparation, and it's what determines the certificate's usefulness.
Setting it too wide lengthens the audit, increases audit days and therefore cost, and above all exposes areas that weren't ready to findings. Setting it too narrow produces a certificate that is technically valid and commercially of little use, because the customer reading it looks for coverage of the system that concerns them and doesn't find it.
The practical criterion is to start from the inventoried systems and from whoever will ask for the certificate. If the request comes from customers buying a specific service, the scope has to cover the AI systems feeding that service, with the relevant organisational structure. Widening later is possible, done at a surveillance visit or a renewal, and costs less than narrowing.
The audit stages
| Stage | What it verifies | Typical evidence |
|---|---|---|
| Stage 1 | Existence and adequacy of the AIMS documentary structure | AI policy, scope, risk assessment, statement of applicability |
| Stage 2 | Actual implementation of the system | Staff interviews, record samples, control evidence on inventoried systems |
| Surveillance | Maintenance over time, normally annual | Internal audits, management review, corrective actions |
| Recertification | Overall conformity at the end of the three-year cycle | The system's history across the cycle |
The structure mirrors other management systems such as ISO/IEC 27001 and ISO 9001, and anyone who has been through those finds a familiar logic with different technical content.
Some weeks normally pass between stage 1 and stage 2, used to close the observations raised in the first phase. It's a window worth using, because stage 1 findings almost always anticipate where stage 2 will look.
Which framework does your company actually need?
AI Rating measures maturity across the four areas of the model and shows where to start, with priorities and estimated effort.
Start your AI RatingWhat drives time and cost
A body's quotation is built on audit days, and audit days depend on four variables: the number of people inside the scope, the number of sites to visit, the quantity and criticality of AI systems in the inventory, and the existence of other certified management systems the audit can be integrated with.
That last point saves the most. A company already certified to ISO/IEC 27001 can request an integrated audit, where the parts common to both standards, from documentation to nonconformity management to management review, get verified once. The saving is real and extends to internal people's time, which is the least visible cost and often the highest.
On the calendar, the dominant variable isn't the audit but the preparation. The typical distance between deciding to certify and stage 2 is measured in months, and depends almost entirely on how much of the management system already exists and genuinely works.
The distance from 27001 and 9001
Anyone arriving from other certifications finds the structure familiar and three substantive differences.
The first is the object. An AI system changes behaviour over time, with the model updated by the vendor or retrained internally, while an information asset or a production process stays more stable. That makes the system inventory a document that moves, rather than an annex refreshed once a year.
The second is the impact assessment on people and groups, which has no direct equivalent in 27001, where the analysis looks at assets and information security.
The third is a body of legislation running in parallel. An ISO 9001 auditor doesn't have to account for an evolving European regulation, while for ISO/IEC 42001 the relationship with the AI Act is part of the context, which is also why auditors with specific experience are worth more than generalists.
A hypothetical example
A software company receives a copy of a supplier's ISO/IEC 42001 certificate and attaches it to tender documentation. During verification the contracting authority asks whether the body is accredited for that standard, and a check against the Accredia database comes back negative: the certificate is genuine, but doesn't carry the value the tender required. The example is illustrative and does not describe a real case.
What the certificate does not cover
Legislative Decree 160/2026 has been in force in Italy since 30 September 2026, and its Article 19 establishes that conformity with AI Act obligations, even when certified through the conformity assessment procedures the regulation provides for, does not in itself exclude liability in a damages claim. The provision addresses AI Act certification, and the same logic reaches any voluntary attestation, including one against ISO/IEC 42001.
The distinction is sharp. A certificate attests that on a given date, across a given scope, a body verified that a management system existed. Litigation instead turns on how one specific system behaved in one specific case, and that reconstruction comes from logs, human oversight evidence and documented decisions rather than from the certificate on the wall.
Anyone entering certification knowing this sets it up differently, holding the certificate and the operational evidence the same system produces daily side by side, because the two serve different forums. The full picture is in the article on evidence and causation under Legislative Decree 160/2026.
When to wait
Certification certifies a system that works, it doesn't create one. An organisation without a current system inventory, or with policies written and never applied, facing the audit now risks the most expensive path of all: stage 2 findings, corrective actions under pressure, an additional visit, and a system built in haste to pass the check rather than to govern the risks.
The signal that the moment has arrived is easy to recognise. There's an inventory updated in recent months, there are risk assessments signed by named people, there's a training plan with evidence tied to roles, and there's at least one documented management review. With those four in place, the audit verifies something that already exists.
Without them, the months spent building them first are worth more than the months spent chasing findings afterwards.
Questions to ask a certification body
- Is the body accredited by Accredia, or by a signatory to the mutual recognition arrangements, specifically for ISO/IEC 42001?
- Does the proposed scope match the systems the company intends to certify?
- Do the assigned auditors have experience with comparable AI systems?
- How are time and cost structured across stage 1, stage 2 and surveillance?
- Can the audit be integrated with certifications already held, and with what saving in days?
- What happens if major nonconformities arise in stage 2, and within what closure timeframes?
- How much notice is needed to schedule stage 1, given your calendar?
Next step
Reaching the audit with a system that works requires coherent documentation, inventory and training. The starting point is the minimum documentation of an AIMS, followed by the AI system inventory, while the most frequent training findings are in the mistakes that make an AI training plan fail an audit.
Our approach to preparation is described on the AI Compliance page. To understand how far you are from the audit, you can book an assessment meeting.