ISO/IEC 42001 at allclouds.pl. We Certified What We Were Already Doing
Most posts about certification begin with self-congratulation. This one begins with a confession: the ISO/IEC 42001 standard did not change the way we work with AI. And that is the most important piece of information in this text

The first such certificate from Bureau Veritas in Poland
Bureau Veritas Polska has awarded allclouds.pl ISO/IEC 42001:2023 certification (no. PL019296) for its Artificial Intelligence Management System. We are the first organisation to receive this certificate from Bureau Veritas in Poland — which says something both about us and about the market: AI management is only now becoming a field that is audited, not merely declared.
The certification audit carried out on 22 May 2026 ended without any nonconformities — neither major nor minor. That is rather rare in certification audits, but our experience with standards (this is already our seventh certified ISO standard), supported by skilful work with AI tools, produced a concrete result. The certificate remains valid until 17 June 2029.
The scope of certification covers what we live on: software design and production — including our TWIN:DESK and PROXY:AI products — and the methodology for implementing artificial intelligence systems (CDF, Cognitive Deployment Framework). All of them operate within a documented, auditable AI management system — from strategy and risk assessment, through model testing, to monitoring and continual improvement.
What the auditor found
This brings us back to the confession in the first paragraph. Before the standard came along, the team’s everyday work was already governed by an internal AI-Operating & Working Agreement — a document that everyone in the company knows and anyone can propose changes to. It rests on three pillars that the auditor was able to verify in practice, not in a binder:
- The final decision belongs to a person. AI supports analysis, but verification and accountability rest with the employee — this is a checkpoint built into the processes, not a slogan.
- Full transparency of operation. The use of AI is documented and communicated to stakeholders. The client knows where AI is in our work and who is responsible for it.
- Data sovereignty. Sensitive information remains in the organisation’s infrastructure — a principle we apply in-house exactly as we design it for our clients.
Preparing for certification was therefore less about building something new and more about mapping existing practice onto the requirements of the standard. This distinction defines two types of certification: one in which the management system is created for the audit, and one in which the audit confirms an existing system. We know from our clients’ experience what the first looks like. We wanted the second.
It is worth mentioning that the actual preparation for certification took us 1.5 months. So do not believe the narrative that AI certification is necessarily a months-long project costing huge sums — if your organisation operates within orderly and measurable processes, preparing for certification is simply fine-tuning a smoothly running machine, not painting a rusty wreck pink. It is simpler, which does not mean it requires no work.
As Paweł Borowicz, Head of Enterprise Risk at Bureau Veritas Polska, emphasises:
> “Clients and regulators today expect documented AI management and a clear framework of accountability. ISO 42001 certification is a response to these real market needs. (…) allclouds.pl sp. z o.o., as a company that itself makes intensive use of AI in its daily work, is an excellent example of an organisation that consciously manages the risks associated with this technology”.
What implementation taught us
Mapping existing practice onto the requirements of the standard was, however, not a formality. We faced several challenges:
- Defining the scope of the system. The most conceptual work went into answering a seemingly simple question: what in our organisation is an AI system, and what exactly does the certification cover. The boundary between commercial products, research and development work and internal uses of AI had to be drawn precisely — together with the rule that any extension of the scope requires a formal change to the documentation and notification to the certification body.
- A seventh standard in one system. The biggest risk when adding another standard is duplicated documentation and two versions of the truth. Instead of a separate set of policies for AI, we integrated the requirements of ISO/IEC 42001 into the existing system — one overarching policy, shared risk registers and one Statement of Applicability covering the controls from ISO/IEC 27001, 27017, 27018 and 42001.
- Human oversight in practice, not on paper. The standard requires real human control over how AI operates. In our automated processes this meant designing specific control points: an automated tool may prepare and pre-classify a document, but verification belongs to a person. Translating this principle into each process separately took more time than writing the policy itself.
- Assessing AI suppliers in a world that changes every month. AI models and services evolve faster than any other category of supplier. A one-off supplier qualification proved insufficient — we replaced it with a recurring quarterly assessment with register updates.
- Measurable objectives instead of slogans. It is easy to declare responsible AI; it is harder to point to indicators that can actually be measured and that you are actually held accountable for. We had to make some of the metrics we originally adopted more realistic — a process that continues after certification too.
What this changes for our clients
For an organisation in a regulated sector, a supplier’s certificate is not a diploma on the wall — it shortens its own audit work. When assessing the supplier of an AI system, the compliance team of a bank or an infrastructure company has to answer the questions posed by the EU AI Act, DORA and NIS2: who controls the system’s life cycle, how risks are managed, where the human is in the decision loop. A certified AI management system at the supplier means that a significant part of these answers has already been confirmed by an independent body.
ISO/IEC 42001 also joins the Integrated Management System we have maintained for a long time: ISO 9001, 27001, 27017, 27018, 22301 and 14001. We list them together not for decoration, but because in practice they work together — AI management without information security management and business continuity management would be a facade.
Why this matters at all
Implementing artificial intelligence is not only a technological challenge — it is above all a matter of control, methodology and compliance. Without the right approach, deployments stall: the project gets stuck in a pilot that nobody dares to put into production.
It is equally important that the AI being deployed gives users sovereignty — independence from the vendor and the right to decide. Without it, it is hard to talk about AI Business Solutions; what remains is renting someone else’s service on someone else’s terms.
A certificate does not solve these problems on its own. But it enforces what does solve them: measurable processes, assigned responsibilities and a person at the point where the decision is made.
This is not another certificate for the gallery. It is confirmation that artificial intelligence management can — and must — be done methodically.
We thank Bureau Veritas Polska for conducting the certification process professionally.