AI, Regulation, and Certification: 11 Articles on ISO/IEC 42001
Tomorrow, two more pieces on cost and adoption, then eleven articles on ISO/IEC 42001 starting in September, documentation, competence, certification. The full calendar, date by date, with a way to subscribe so you don't miss a release.
Over the next few days we're publishing three articles on cost, on adoption, and on where to restart with AI in September. The thread connecting them leads straight to a very practical question, one we hear in almost every assessment: once you've decided to close the gap between initiative and governance, what do you actually do with it, on a Monday morning.
The answer we give most often is ISO/IEC 42001, the international standard for AI management systems. It isn't a document to read once and file away, it's an operating method, with precise clauses on documentation, competence, risk assessment, audit. Starting Tuesday, September 1st, we're publishing eleven articles that walk through it one piece at a time, from the first document you need to write to the certification itself.
The sequence isn't arbitrary
The first block covers the foundations: what documents an AI management system actually requires, how to build an inventory of the systems in use, how to run an impact assessment that ties DPIA and the AI Act together instead of duplicating the work twice, what to prepare before writing a single line of code if the goal is an ISO-ready system from the design stage onward.
The second block moves to people. Clause 7 on competence, explained without the standard's jargon, a matrix that says who needs training and on what, where the AI literacy required by the AI Act ends and the competence required by ISO 42001 begins, the mistakes that make a training plan fail an audit, why the mandatory course alone isn't enough.
The third block closes on certification: the map of Accredia-accredited bodies in Italy, and the real difference between becoming a Lead Implementer, a Lead Auditor, or getting the whole organization certified.
Why now
The regulatory calendar just settled, we wrote about that last week, and boards are closing out the budget for the last quarter. This is the moment when the question shifts from whether to invest in AI governance to which method to use, and ISO 42001 remains the most concrete reference available today, because unlike the AI Act it doesn't just describe what to avoid, it describes what to build.
The full calendar
One article every two or three days, through September 30th. Each piece is meant to stand on its own, useful even if you only read the one you need right now.
| Date | Article |
|---|---|
| Aug 27 | Why AI Budgets Blow Up (And It's Not the Tokens) |
| Aug 28 | 71% Started, 9% Arrived: What Happens in Between |
| Aug 31 | Where to Restart With AI in September 2026 |
| Sep 1 | The Minimum Documentation of an AIMS |
| Sep 3 | Impact Assessment: DPIA, the AI Act, and ISO/IEC 42001 Compared |
| Sep 8 | The AI System Inventory |
| Sep 10 | Designing an ISO-Ready AI System |
| Sep 15 | ISO/IEC 42001 Clause 7, Explained Without Jargon |
| Sep 17 | Who Needs Training and on What: A Roles-Competence Matrix |
| Sep 18 | AI Literacy and ISO 42001 Competence |
| Sep 22 | The Mistakes That Make an AI Training Plan Fail an Audit |
| Sep 23 | The Mandatory AI Course Isn't Enough |
| Sep 24 | ISO/IEC 42001 Certification in Italy: the Accredia Map |
| Sep 29 | Lead Implementer vs Lead Auditor vs Organizational Certification |
If you'd rather not check the blog every couple of days, you can subscribe to the newsletter.
Don't miss the next release. Subscribe to the ZeroFive newsletter: one email per article published, nothing else in between.