Auditing is not the most glamorous corner of the AI world. But it is where the EU AI Act starts to feel very real. The law does not just tell developers to build responsibly; it obliges providers and deployers to document, log and prove what their systems do. That requires people with a very specific skill set — part management auditor, part AI specialist, part EU regulation interpreter.
CertiProf, a certification body with a network of Authorized Training Partners across Europe and beyond, has responded with four proctored credentials: the ISO/IEC 42001 Lead Auditor (I42001LA™), the ISO/IEC 42001 Internal Auditor (I42001IA™), the AI Risk Manager Professional Certification (AIRMPC™) and the AI Governance Professional Certification (AIGPC™). Each is designed to bridge an international management standard and a binding European law that are, at their core, about the same thing: knowing what your AI does and being able to show it.
Why the timing matters in Europe
This is not a theoretical exercise. Obligations for general-purpose AI (GPAI) models became applicable on 2 August 2025. Providers of GPAI models placed on the EU market before that date have until 2 August 2027 to bring them into compliance where applicable. The European Commission’s general application date for the wider AI Act is 2 August 2026. The European AI Office supervises GPAI model obligations, a role it has held since those obligations became applicable in 2025, and it supports enforcement of the wider AI Act.
For European businesses, the practical consequence is a staffing problem. A mid-sized company that fine-tunes or deploys an AI model suddenly needs someone who can produce technical documentation, run risk assessments and prepare for audits. That role sits somewhere between IT, legal and quality management — and it barely existed in job listings two years ago.
The standard itself recently became more accessible to European organisations: the European adoption, EN ISO/IEC 42001:2026, was published on 18 March 2026, following the ISO/IEC 42001 adoption path. Having a single European adoption makes it easier for companies in different member states to use one consistent framework instead of inventing their own.
ISO/IEC 42001 and the AI Act: two systems, one goal
ISO/IEC 42001 defines an AI management system (AIMS) — essentially a structured way for an organisation to oversee AI throughout its lifecycle: planning, risk treatment, operation, performance evaluation and continual improvement. The EU AI Act, by contrast, is a legal text with binding obligations and penalties. The two frameworks nevertheless cover many of the same high-level operational requirements from different angles.
That common ground is the key insight for non-specialists. A company that builds a mature AI management system has already done a large share of the groundwork the EU AI Act demands — risk management, data governance, technical documentation, transparency, human oversight and audit trails. The two are not identical, and compliance with a voluntary standard does not automatically equal compliance with the law. But the shared architecture means organisations can avoid building separate, parallel compliance worlds.
Who are the new credentials for?
The four tracks point to four different jobs inside that shared architecture:
- ISO/IEC 42001 Internal Auditor — for people who assess and improve the AI management system inside their own organisation.
- ISO/IEC 42001 Lead Auditor — for those conducting formal, often external, audits against the standard.
- AI Risk Manager Professional — for the hands-on work of identifying and mitigating AI-related risks across projects.
- AI Governance Professional — for senior roles shaping policy, oversight structures and accountability — often the people who talk to regulators.
These are individual professional credentials, not an organisational certification. Completing one does not certify a company against ISO/IEC 42001, guarantee EU AI Act compliance, or establish recognition by regulators.
CertiProf’s rollout targets not just individual learners but entire institutions. The expanded programme is delivered through its network of Authorized Training Partners, commercial academies and universities, with faculty train-the-trainer vouchers, online exam portals and blockchain-verifiable digital badges issued to successful candidates. That ecosystem approach matters: Europe needs thousands of competent auditors, not a handful of experts.
What the fines actually mean in practice
The stakes are easy to state and hard to overstate. The maximum penalty for the most serious infringements, such as prohibited practices, is €35 million or 7% of worldwide annual turnover, whichever is higher. For a company turning over €10 million, that is €700,000 — enough to erase a year of profits at many small and mid-sized firms. For a large technology provider, the percentage-based figure dwarfs any fixed penalty.
Fines alone, however, are not the only pressure. Under the AI Act’s transparency rules, users need to know when they are interacting with an AI system. Companies bidding for public contracts or partnering with large enterprise clients are already being asked about their AI governance practices. Certification of the people doing that work is becoming a quiet but decisive part of procurement conversations.
Questions worth asking before you sign up
For a European professional considering one of these tracks, a few checks make sense. First, confirm that the course treats ISO/IEC 42001 and the EU AI Act as one integrated framework rather than two separate lectures. Second, ask who delivers the training and whether the trainers have experience with actual AI systems — an auditor who has never seen a machine-learning pipeline in production is of limited help. Third, check whether the credential is recognised beyond the provider: a credential is only as valuable as the trust that employers and regulators place in it.
The broader lesson is more reassuring. Compliance does not have to mean a paperwork arms race between companies and regulators. When an international standard covers many of the operational requirements a law demands, it creates a common language — and a realistic path forward. Europe now needs the people who speak that language fluently.
Is ISO/IEC 42001 certification mandatory under the EU AI Act?
No. ISO/IEC 42001 is a voluntary international standard, and certification against it does not automatically mean an organisation is EU AI Act compliant. Completing CertiProf’s professional credentials also does not certify a company or guarantee compliance; it signals individual knowledge and skills. In practice, however, the standard’s requirements overlap substantially with the AI Act’s operational obligations, so a mature AI management system can form the backbone of the documentation and risk processes the law requires.
Do these certifications apply only to organisations based in the EU?
No. The EU AI Act applies to any provider placing AI systems or general-purpose models on the EU market, and to deployers using them within the EU, regardless of where the company is headquartered. That is why the credentials are being offered through a global network of Authorized Training Partners, commercial academies and higher education institutions.
Which track should a professional choose?
It depends on the role. An internal auditor tracks the organisation’s AI management system over time; a lead auditor typically conducts formal, sometimes external, assessments; the risk manager focuses on identifying and mitigating AI-specific risks; and the governance professional works on policy, accountability and regulatory engagement. Many organisations will eventually need people in more than one of these roles.