Back to blogApprofondimenti

    AI, Regulation, and Certification: 11 Articles on ISO/IEC 42001

    Tomorrow, two more pieces on cost and adoption, then eleven articles on ISO/IEC 42001 starting in September, documentation, competence, certification. The full calendar, date by date, with a way to subscribe so you don't miss a release.

    ZeroFive.AI August 25, 2026Updated on September 18, 2026 4 min

    Over the next few days we're publishing three articles on cost, on adoption, and on where to restart with AI in September. The thread connecting them leads straight to a very practical question, one we hear in almost every assessment: once you've decided to close the gap between initiative and governance, what do you actually do with it, on a Monday morning.

    The answer we give most often is ISO/IEC 42001, the international standard for AI management systems. It isn't a document to read once and file away, it's an operating method, with precise clauses on documentation, competence, risk assessment, audit. Starting Tuesday, September 1st, we're publishing eleven articles that walk through it one piece at a time, from the first document you need to write to the certification itself.

    The sequence isn't arbitrary

    The first block covers the foundations: what documents an AI management system actually requires, how to build an inventory of the systems in use, how to run an impact assessment that ties DPIA and the AI Act together instead of duplicating the work twice, what to prepare before writing a single line of code if the goal is an ISO-ready system from the design stage onward.

    The second block moves to people. Clause 7 on competence, explained without the standard's jargon, a matrix that says who needs training and on what, where the AI literacy required by the AI Act ends and the competence required by ISO 42001 begins, the mistakes that make a training plan fail an audit, why the mandatory course alone isn't enough.

    The third block closes on certification: the map of Accredia-accredited bodies in Italy, and the real difference between becoming a Lead Implementer, a Lead Auditor, or getting the whole organization certified.

    Why now

    The regulatory calendar just settled, we wrote about that last week, and boards are closing out the budget for the last quarter. This is the moment when the question shifts from whether to invest in AI governance to which method to use, and ISO 42001 remains the most concrete reference available today, because unlike the AI Act it doesn't just describe what to avoid, it describes what to build.

    The full calendar

    One article every two or three days, through September 30th. Each piece is meant to stand on its own, useful even if you only read the one you need right now.

    DateArticle
    Aug 27Why AI Budgets Blow Up (And It's Not the Tokens)
    Aug 2871% Started, 9% Arrived: What Happens in Between
    Aug 31Where to Restart With AI in September 2026
    Sep 1The Minimum Documentation of an AIMS
    Sep 3Impact Assessment: DPIA, the AI Act, and ISO/IEC 42001 Compared
    Sep 8The AI System Inventory
    Sep 10Designing an ISO-Ready AI System
    Sep 15ISO/IEC 42001 Clause 7, Explained Without Jargon
    Sep 17Who Needs Training and on What: A Roles-Competence Matrix
    Sep 18AI Literacy and ISO 42001 Competence
    Sep 22The Mistakes That Make an AI Training Plan Fail an Audit
    Sep 23The Mandatory AI Course Isn't Enough
    Sep 24ISO/IEC 42001 Certification in Italy: the Accredia Map
    Sep 29Lead Implementer vs Lead Auditor vs Organizational Certification

    If you'd rather not check the blog every couple of days, you can subscribe to the newsletter.


    Don't miss the next release. Subscribe to the ZeroFive newsletter: one email per article published, nothing else in between.

    Want to discuss this for your company?

    30 minutes with us to figure out where to start, or an AI Rating to measure your starting point.

    #ISO IEC 42001#editorial calendar#AI Governance#newsletter
    Share

    Keep reading