Search for Author, Title, Keyword
RESEARCH PAPER
Auditing AI Governance under ISO/IEC 42001 Certification: EU AI Act, Product Liability Directive, and Multi-Dimensional Security and Liability Considerations
 
More details
Hide details
1
Dr. Franjo Tudjman Defense and Security University, Croatia
 
2
Faculty of Law, University of Zagreb, Croatia
 
3
Faculty of Law, University of Split, Croatia
 
 
Submission date: 2026-06-13
 
 
Final revision date: 2026-08-01
 
 
Acceptance date: 2026-08-03
 
 
Online publication date: 2026-08-07
 
 
Corresponding author
Natalija Parlov   

Dr. Franjo Tudjman Defense and Security University, Zagreb, Croatia
 
 
 
KEYWORDS
TOPICS
ABSTRACT
Artificial intelligence (AI) governance increasingly relies on management systems, independent assurance, and risk and security processes, yet the evidentiary and legal significance of artificial intelligence management system (AIMS) certification remains insufficiently defined. This paper examines what International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 42001 third-party audits assess, how ISO/IEC 42006 competence requirements affect the credibility and limits of audit evidence, and when AIMS documentation and certification outputs may be relevant in civil, criminal, professional-liability, and product-liability assessments. The study applies a conceptual, standards-interpretive, and doctrinal legal design, analysing standards, the European Union (EU) Artificial Intelligence Act, the revised product liability directive and governance, cybersecurity, and auditing and liability literature. It develops a governance-evidence-liability framework distinguishing technical AI systems, AI-enabled products and services, organisational governance, certification, and legal accountability. The analysis finds that AIMS audits assess organisational governance, including security-risk oversight, through scope-bound, sampled, and time-bound evidence. Multidisciplinary auditor competence may strengthen the credibility of judgements but does not transform management-system certification into technical cybersecurity validation, product certification, or a binding compliance determination. AIMS documentation may constitute important contextual evidence in civil and criminal liability because cybersecurity risk assessments, vulnerability records, monitoring logs, and incident-response records may show whether foreseeable threats were identified and managed. However, its probative value depends on scope, timing, reliability, factual connection to the system or incident, and corroborating technical and operational evidence. It cannot independently establish cybersecurity resilience, technical correctness, legal compliance, defectiveness, fault, causation, or liability. The framework supports interpretation of security-related AIMS evidence without overstating the assurance provided by certification.
eISSN:2956-4395
ISSN:2956-3119
Journals System - logo
Scroll to top