exact.works
StudioAgent Index ↗Log inSign up
Trust Center

ISO 42006 and what we are not

exact.works is not a certification body, does not issue certificates, and does not hold audit evidence. What it publishes is a standard form and clause-level mappings an auditor can read.

Positioning

A form, not an assessor.

ISO/IEC 42006:2025 sets requirements for bodies that audit and certify AI management systems under ISO/IEC 42001. exact.works is not one of those bodies and does not supply the evidence they assess.

ISO 42006ISO 42001ISO 17021-1

An earlier version of this page mapped seven ISO 42006 requirement areas to exact.works mechanisms and marked six of them ALIGNED. Those mechanisms were a behavioural scoring engine, a continuous runtime surveillance loop, an AI dispute process, and a hosted evidence ledger. All four are withdrawn: exact.works does not score agents, does not watch them run, does not decide disputes, and does not hold anyone’s records. The mapping went with them, because a conformity claim resting on engines we no longer operate is worse than no claim at all.


What a certification body gets from us

Documents, not determinations.

Everything below is a published artefact or something the customer runs themselves. None of it involves exact.works holding, observing or attesting to anything.

A published standard form

The agreement, its schedules and their versions are public. An auditor can read what a customer's engagements are governed by without asking us for anything.

Clause-level mappings

Where a framework's control corresponds to a clause, the mapping is written down. It shows an auditor where an obligation lives in the contract — not that it was met.

A seal anyone can check

The agreed terms carry a canonical hash signed with a published key. An auditor holding the document can confirm it is the version that was agreed.

An open record verifier

The record standard is published and the verifier runs against the customer's own export, on the customer's side. We never receive the export.


Limitations

What exact.works does NOT do.

Issue ISO 42001 certificates

Certification decisions rest entirely with the customer's ISO 42006-accredited certification body. We are not in that chain.

Produce conformity observations

The engine that made them is withdrawn. We record nothing about how an agent behaved, because we never see it behave.

Hold or supply audit evidence

Execution records go from the customer's agent to the customer's own storage. If an auditor wants them, they ask the customer — we do not have a copy.

Perform management system audits

ISO 42001 is about an organisation's management system. We supply contract text, not an audit of how anyone runs their organisation.

Assess auditor competence

Competence of human auditors is the certification body's obligation under ISO 42006 Section 7. It was never ours.

Surveil ongoing conformity

Periodic or continuous surveillance of a deployment is enforcement and sits in the data path. Out on both counts.


Analogy

ISDA, and only the ISDA half.

ISDA is not a counterparty, a regulator, or a record keeper. It publishes a master agreement, a documentation architecture and a set of definitions, and the market transacts on them. That is the whole of the comparison exact.works is entitled to: a standard form for AI-agent engagements, published and versioned, that two parties negotiate from. What each party then keeps, proves and certifies is theirs — which is true of ISDA too.

Back to Trust CenterRead the standard form
exact.works

Product

  • SAISA
  • Agent Contract Studio

Offerings

  • Government
  • Financial
  • Legal
  • Healthcare
  • Enterprise
  • Infrastructure

Tools

  • Pricing
  • Repositories
  • API
  • Documentation

Company

  • About
  • Newsroom
  • Trust
  • Governance
  • Careers
  • Contact

Every AI agent needs a service agreement.

© 2026 exact.works, Inc. Delaware C-Corp.
PrivacyTerms