For nearly fourteen years, ISO/IEC 17024:2012 has been the benchmark against which personnel certification bodies are accredited. That era ended on 31 March 2026, when ISO published ISO/IEC 17024:2026, the third edition of the standard and its most substantial revision since 2012. If your credential carries accreditation, or you intend it to, the transition clock is now running, and for the first time the standard has something to say about AI.
This article covers what changed, what the new AI requirements mean in practice, the transition dates that matter, and what to do this quarter. It is written for the leaders of certification and credentialing programmes who will own the transition, and for the scheme owners, exam developers, and testing providers whose work will be assessed under it.
Why 17024 anchors the credential
ISO/IEC 17024 sets the requirements for bodies operating certification of persons. It is the standard your accreditation body assesses you against, whether that is ANAB, UKAS, or another national body operating under international mutual recognition arrangements. It covers impartiality, structure, resources, scheme development, examinations, the certification decision, surveillance, appeals and complaints, and the management system that holds all of it together.
Accreditation against 17024 gives a certificate independent evidence a third party can rely on. In many sectors, regulators reference it. Procurement frameworks require it. Employers rely on it without knowing its name. When the standard moves, the definition of a defensible certification programme moves with it.
It is also worth remembering what the world looked like when the 2012 edition was written. Remote examination was an edge case. Digital delivery was maturing. Automated scoring existed, but AI was nowhere near the operational governance question it is today. The 2026 edition is the standard catching up with how certification is actually delivered.
What actually changed
Most of the revision is evolution rather than revolution. Expect:
- updated terminology and alignment with the common structure used across the ISO CASCO conformity assessment standards, with the standard now superseding the separate vocabulary document ISO/IEC TS 17027:2014
- strengthened impartiality and conflict of interest safeguards
- more detailed requirements for organisational structure and personnel competence
- expanded provisions across certification schemes, examinations, appeals, and complaints
- clearer recognition of remote and technology-enabled examination
- a new Annex B mapping how certification activities, processes, assessments, applications, examinations, and schemes fit together
Then the step change. The 2026 edition introduces a tailored definition of artificial intelligence and dedicated clauses governing its use in certification processes. It is the first standard in the ISO/IEC 17000 conformity assessment family to address AI directly. For a document that governs how competence is certified across every sector, that is not a footnote. It is the headline.
AI is now an accreditation matter
The standard does not prohibit AI, and it does not endorse it. It does something more consequential. It makes your use of AI examinable by your accreditation assessor.
“It makes your use of AI examinable by your accreditation assessor.”
ISO’s own summary of the revision is specific. Certification bodies are expected to monitor and validate AI-generated outcomes, maintain appropriate human oversight, and ensure competence in the use of AI tools. ANAB’s transition material highlights four touchpoints where those expectations bite. These are scheme development, assessment and scoring, remote proctoring, and the handling of complaints and appeals. Anywhere AI influences how a candidate is examined, scored, monitored, or heard, the 2026 edition expects you to be able to show your working.
Taken together, the standard’s stated expectations and ANAB’s transition guidance mean you should expect assessors to seek evidence of:
- disclosure, so candidates know where AI is used in the process
- documented human oversight, showing who reviews what and with what authority
- documented expert review of AI-generated content, including examination items
- monitoring of AI behaviour over time, not a one-off validation at purchase
- oversight of vendor and commercial models you did not build and do not train
That last point deserves emphasis. If an AI feature sits inside your certification pipeline, the accountability for it sits with you, whether you built it, bought it, or received it in a vendor’s product update. Outsourcing the tool does not outsource the accountability. “The supplier does it” has never been an acceptable answer to an accreditation assessor, and the 2026 edition makes that explicit for AI.
“Outsourcing the tool does not outsource the accountability.”
The pattern will be familiar to readers of the earlier articles in this series. The question your assessor will ask is not whether the tool performs. It is whether you can evidence how it behaves, who is accountable for it, and what happens when it gets something wrong. Capability without examinable evidence does not pass, and that holds however impressive the technology looks in a demonstration.
The transition clock
ANAB, the ANSI National Accreditation Board, whose personnel certification programme covers more than 200 accredited certifications, has published its transition timeline for currently accredited bodies:
The ANAB transition timeline
- 1 October 2027: transition self-attestation due to ANAB
- October 2027 to September 2028: ANAB assessments conducted under the 2026 edition
- 31 March 2029: final transition deadline
These are ANAB dates. Confirm the equivalent milestones with your own accreditation body rather than assuming they match.
New applicants are being asked to contact ANAB directly to discuss timing. Other accreditation bodies are setting their own arrangements on similar horizons. If your accreditation sits elsewhere, confirm the dates with your accreditation body now rather than assuming them.
Three years sounds generous. It is not. The window has to absorb a clause-by-clause gap analysis, scheme documentation changes that move at the speed of committee cycles, vendor contract renegotiation, personnel training, and at least one surveillance cycle under the new expectations. Above all, evidence has a minimum age. Monitoring logs, oversight records, and review trails are only convincing when they have accumulated through months of live operation.
“You cannot backfill twelve months of monitoring evidence the week before an assessment.”
You cannot backfill twelve months of monitoring evidence the week before an assessment. The bodies that plan backwards from their attestation date will discover that the comfortable margin is smaller than it looks.
One evidence base, four doors
Readers following this series will recognise the shape. The EU AI Act brings high-risk obligations for specified AI uses in assessment from December 2027. The AERA, APA, and NCME Testing Standards raise the professional evidence bar the moment AI enters scoring or proctoring. ISO/IEC 42001 describes the management system that produces the evidence, with ISO/IEC 23894 guiding the risk management inside it. Now ISO/IEC 17024:2026 makes the same evidence an accreditation requirement.
These are four doors into the same room. Each asks, in its own vocabulary, for an examinable evidence base covering every AI touchpoint in your assessment pipeline. Structure the work once, around an AI register and an audit pack, and it serves all four. Structure it as four separate compliance projects and you will do the work four times, badly.
“Structure the work once, around an AI register and an audit pack, and it serves all four.”
What to do this quarter
ANAB’s guidance to accredited bodies is blunt: start now. Its own transition material prioritises AI, competence, and vendor oversight as the high-impact areas, which should tell you where assessors expect to find the gaps. The sequence that works:
The transition sequence
- Run a gap analysis against the 2026 edition, clause by clause, and record where you stand
- Prioritise the areas the accreditation bodies themselves are flagging, namely AI use, competence requirements, and vendor oversight
- Assign a transition owner with decision rights, not a committee with a mailing list
- Plan backwards from your accreditation body’s dates, leaving time for evidence to accumulate
- Train the people who will actually face the assessor, including scheme managers, examiners, and operations staff
If you already maintain an AI register, extend each entry to record where AI use is disclosed to candidates, how human oversight is evidenced, and where expert review is documented. If you do not, this is now the second instrument in a year, after the EU AI Act, telling you that the register is where defensible governance starts. The companion piece on building an audit-ready evidence pack sets out what the assessor will actually want to read.
Accreditation is the currency of trust
A credential trades on third-party confidence, and accreditation is how that confidence is manufactured. The 2026 edition raises the bar exactly where the market was already asking its hardest questions, on impartiality, on technology-enabled assessment, and on AI. That is not the standard getting ahead of the field. It is the standard catching up with what candidates, employers, and regulators have started to expect.
The bodies that use the window will walk into their first assessment under the 2026 edition with evidence that has had time to mature. The bodies that treat March 2029 as a distant administrative deadline will be explaining gaps to their assessor, and shortly afterwards to their market. In my experience, a first-pass gap analysis is a fortnight’s work. Start there.
Ready to run your ISO/IEC 17024:2026 gap analysis?
Talk to our team about how Globebyte can help you build a defensible AI operating model for certification.