Skip to main content
Should AI Certification Be Voluntary or Mandatory?Trustworthy AI Principles
4 min readFor Procurement & Third-Party Risk Teams

Should AI Certification Be Voluntary or Mandatory?

The Question at Hand

Your procurement team is evaluating AI vendors. One claims ISO/IEC 42001 certification, while another follows a voluntary industry framework. Which is more important? As AI assurance schemes mature, you're facing a choice: should certification be driven by regulation or market incentives?

This isn't just theoretical. The UK government's adaptable approach to AI regulation allows certification to develop organically. However, with ISO/IEC 42001 still in the approval stage and ISO/IEC 42005 in committee, the standards are moving targets. You're asking if voluntary schemes can establish trust before mandatory ones arrive, or if they'll be too weak to matter.

The Case for Mandatory Certification

Mandatory certification is effective when stakes are high. In aerospace, nuclear safety, and medical devices, regulation creates hard requirements. Accidents are rare because certification isn't optional.

For high-risk AI systems affecting hiring, creditworthiness, or medical diagnoses, voluntary compliance isn't enough. You need enforceable standards with real consequences for non-compliance. A mandatory framework ensures baseline safety and robustness across all deployers, not just those who choose to participate.

From a procurement perspective, mandatory certification simplifies vendor evaluation. You're checking a binary requirement: certified or not. This reduces due diligence burden and creates clear accountability when something goes wrong.

When certification requirements are codified in law, they mature alongside enforcement mechanisms. Your legal team can point to specific obligations. Your vendor contracts can reference concrete standards. Your audit trail becomes defensible because you're following prescribed rules.

The Case for Voluntary Certification

Voluntary certification thrives when market forces create incentives. In cybersecurity and sustainability, organizations pursue certification to differentiate themselves. Brand recognition and consumer trust make certification worthwhile.

For AI, voluntary schemes offer flexibility while standards are still emerging. ISO/IEC 42001 and related frameworks are developing in real time. A mandatory regime built on immature standards risks locking in requirements that don't match how AI systems work or how risks manifest. Voluntary schemes can iterate faster, testing what works before it becomes law.

Consider your vendor evaluation again. The vendor with voluntary certification is signaling investment in governance beyond legal minimums. They're building an AI Management System proactively. That tells you something about their risk culture that a mandatory checkbox doesn't capture.

Voluntary certification also addresses principles that don't fit neatly into regulation. How do you mandate explainability or fairness through a single standard when these concepts depend heavily on context? Voluntary frameworks can tackle these nuanced requirements without forcing one-size-fits-all rules onto diverse use cases.

The timeline matters too. Across sectors examined by the Centre for Data Ethics and Innovation, certification was one of the final governance elements to mature. If you wait for perfect mandatory standards before building certification infrastructure, you'll delay trust-building for years. Voluntary schemes let you start now, learning what works while regulations catch up.

Where Practitioners Actually Land

Most procurement and third-party risk teams aren't choosing between voluntary and mandatory certification. They're managing both, and that's likely where AI governance will land too.

You're already seeing this hybrid model emerge. The EU AI Act creates hard requirements for high-risk systems while leaving room for voluntary codes of practice for General-Purpose AI Models. Top-down rules establish safety baselines; voluntary schemes push beyond them on fairness, transparency, and other trust factors.

In practice, you'll evaluate vendors on a spectrum. For high-risk AI that falls under regulatory scope, mandatory certification becomes essential. For lower-risk systems or principles not covered by regulation, voluntary certification becomes a differentiator. Your vendor scorecards will likely weight both: mandatory compliance as a go/no-go criterion, voluntary certification as a quality signal.

The challenge is managing this complexity during the transition period. Right now, you're often evaluating vendors against standards that don't yet exist or certification schemes that haven't matured. Your due diligence questionnaires are asking about governance practices without clear benchmarks for what "good" looks like.

Our Take

Start building voluntary certification infrastructure now, but design it to evolve into mandatory schemes later.

The UK's adaptable approach to AI regulation creates space for iterative certification development. Use that space. Voluntary schemes let you test governance models, identify what works, and build community consensus before requirements harden into law. But don't treat voluntary certification as a permanent alternative to regulation for high-risk systems.

For procurement teams, this means maintaining dual evaluation tracks. Require evidence of governance maturity even when certification doesn't exist yet. Ask vendors about their AI Management System structure, their validation evidence, their post-market monitoring processes. When voluntary certifications emerge, evaluate them critically: Who developed the standard? What's the conformity assessment process? How does it align with emerging regulatory requirements?

The sectors with mature certification didn't get there by waiting for perfect standards. They started with voluntary schemes, learned from failures, adjusted, and eventually codified what worked. AI assurance should follow the same path. The dialogue about certification needs to happen in parallel with standards development, not afterward.

Your job isn't to pick sides between voluntary and mandatory approaches. It's to build governance infrastructure flexible enough to accommodate both as the landscape matures.

You Might Also Like