Independent AI Assurance and ISO 42001 for Energy Operators

Who Audits the Builder

Certification bodies are barred from certifying AI management systems they consulted on. AI buying decisions deserve the same discipline the standard applies to itself.
2 years
cooling-off before a body can certify a system it consulted on
99 to 0
US Senate vote to separate audit from consulting after Enron
Under 50%
AI adoption in the energy sector, per the IEA's Energy and AI report

The question every AI implementation eventually faces

Picture a familiar sequence on a capital project. An operator commissions an integrator to build a predictive maintenance system in the business-systems layer: work orders, asset registers, planning data, an AI model deciding which interventions move up the schedule. The build lands, the demonstrations impress, and the board asks the question boards now ask: is this thing governed? The integrator produces a document confirming that it is. The same firm that designed the system, wrote its logic, and stands to win the next phase of work has just marked its own homework.

The problem sits in the structure, and honesty has surprisingly little to do with it. An assurance opinion carries value in proportion to the independence of the party giving it. When the builder assures the build, the opinion is shaped by the same incentives that shaped the system: the commercial relationship, the follow-on work, the natural attachment to design decisions already made. A conscientious integrator and a careless one produce opinions of identical worth in that position, because the reader has no way to tell them apart. The signal collapses regardless of the intent behind it.

Energy has understood this for decades. Offshore installations run on independent verification. Financial statements run on external audit. Safety-critical control systems run on assessor independence that scales with the stakes. The sector's own history explains why each of those regimes exists. What is striking is how rarely the same discipline follows the money into AI procurement, where the builder's word is routinely accepted as the governance opinion.

What ISO 42001 and its certification rules require

The precedents energy already runs on

The clearest lesson comes from financial audit. Arthur Andersen served as Enron's external auditor while also selling it consulting services; in 2000, Enron paid Andersen $52 million, of which $27 million was for consulting. The firm was, in effect, auditing an environment it helped build. The Sarbanes-Oxley Act that followed passed the US Senate 99 to 0 and separated audit from consulting for audit clients. The same crisis, incidentally, reshaped oversight of energy trading.

Engineering reached the same conclusion by its own route. IEC 61508, the functional safety standard, scales assessor independence with the safety integrity level of the system: at the lower levels an independent person suffices, while the highest levels require an independent organisation. And in the UK offshore regime, the Safety Case Regulations 2015 require verification of safety-critical elements by a party sufficiently independent of the management system that produced them. That requirement descends directly from the Piper Alpha inquiry. The pattern across all three regimes is identical: as consequence rises, the assurer's distance from the builder becomes the point.

What the AI governance standard actually assumes

ISO/IEC 42001, the AI management system standard, is often read as permissive on this question, because Clause 9.2 allows an organisation to audit its own management system internally, provided the auditors are objective and impartial. That reading stops one layer too early. The certification architecture above the standard is built on separation. Under ISO/IEC 17021-1, the conformity assessment standard that governs certification bodies, a body cannot offer management system consultancy, and it cannot certify a management system it consulted on or internally audited for a minimum of two years after that work ends. ISO/IEC 42006, published in 2025 specifically for bodies certifying AI management systems, extends the same bar to consulting on AI, information security, data protection and risk management for certification clients.

Read together, the message is precise. Internal audit is a management tool, useful for finding problems early. Credible assurance, the kind a certificate represents, is deliberately walled off from anyone who built or advised on the system. The framework treats the builder's opinion of its own work as structurally inadmissible at the certification layer, however competent the builder. That rule binds certification bodies; for an operator's procurement it stands as logic rather than law. The logic travels anyway: an operator accepting an integrator's self-attestation as the governance opinion is accepting exactly what the certification regime is engineered to exclude.

Regulation is moving the same way, unevenly. The EU AI Act classifies AI used as a safety component in critical infrastructure, including electricity and gas, as high-risk, yet permits self-assessment for most high-risk categories, a choice its critics argue leans too far on the provider's own word. In the UK, Ofgem has published good-practice guidance on AI in the energy sector and is consulting on the role of AI assurance, while the NCSC's Cyber Assessment Framework, used across operators of essential services, added expanded AI risk coverage in its 2025 release. The direction of travel favours operators who can show an opinion formed at arm's length.

A proportionate route for scaling energy operators

There is an honest counter-argument, and it deserves a fair hearing. Separating build from assurance means paying twice, and a scaling operator watches that line. UK estimates put first-year ISO/IEC 42001 certification for a small organisation in the region of £6,000 to £8,000, before advisory support, and independent review of a single AI system costs less but still costs. The market has largely accepted vendor self-attestation, model cards and completed questionnaires as sufficient, so the operator who asks for more is spending money its peers are keeping.

Energy already knows how to answer that. A pressure vessel reaches an operator with conformity assessed by an approved body under the UK's pressure equipment regulations, and the cost of that verification is priced into owning the asset, a baseline every operator carries. The AI layer now sits above those same assets, scheduling the interventions that keep them running. The budgeting discipline follows the criticality, and treating an AI system's assurance as part of its purchase price is the same commercial logic the sector applies to the steel.

Proportionality answers the objection better than principle does. Separation is a role before it is an invoice. A scaling operator can apply the logic of Clause 9.2 internally from day one: the people who commissioned and configured the system stand aside, and someone with no stake in the build reviews it against the operator's own risk appetite. That costs organisational discipline. When the stakes rise, the response scales with them, exactly as IEC 61508 scales assessor independence. An AI system scheduling maintenance interventions on revenue-critical assets, or one whose failure touches an essential service, has crossed the threshold where an independent opinion becomes part of the asset's value. For operators already holding ISO/IEC 27001, the shared structure of the two standards materially reduces the incremental cost of formalising this.

The buying decision is where the discipline starts. An operator evaluating an AI build should establish, before signature, who will form the governance opinion and what relationship that party has to the build. Structured vendor scrutiny does much of this work early; our analysis of the AI due diligence gap examines why questionnaires written for conventional software miss the risks AI introduces, and the accompanying AI vendor due diligence questionnaire gives that scrutiny a working structure. The full cost picture of an AI system includes the assurance that makes its outputs defensible, and pricing that in at the start is cheaper than discovering its absence when a regulator, an insurer or an incident asks the question.

An implementer occupies a specific structural position, and that position comes with a ceiling. The firm that builds a system knows it intimately, and that intimacy is precisely what disqualifies its opinion from standing as assurance. The practical consequence for the operator is a two-part discipline: ask at procurement who will form the governance opinion, and commission builds that anticipate independent scrutiny, with the documentation, decision logs and controls in place for an outside party to examine. That is where commercial and technical leadership meet, and a system built to be inspected holds its value when the inspection comes. That is the standard worth writing into the next contract, and it is the standard an implementer should welcome being held to.

More Insights

Connect with our Automation Practice