Key takeaways
- ISO 42001 certification is an accredited third-party audit confirming that your AI management system (AIMS) meets ISO/IEC 42001:2023, the first certifiable standard for governing AI.
- You are assessed against management-system clauses 4 to 10 and the 38 controls in Annex A, grouped under nine objectives.
- The path runs through five phases and a two-stage external audit, taking most organisations four to twelve months.
- Budgets commonly land between $4,000 and $20,000 for smaller firms, and 15,000 to 80,000 euros once consultancy is included; holding ISO 27001 lowers both.
- Certification signals diligence and prepares you for the EU AI Act, but it is not a legal shield: ISO 42001 is not yet a harmonised standard.

What ISO 42001 certification actually is
ISO 42001 certification is a formal, independent confirmation that your organisation runs an AI management system built to ISO/IEC 42001:2023. Published in December 2023, ISO/IEC 42001 is the first management-system standard written specifically for artificial intelligence, and the first that an accredited body can certify against. A certificate is issued after an external auditor reviews your documentation and then tests whether the system works in practice.
The object of certification is the management system, not any single model. An AI management system is the set of policies, roles, risk processes, and controls through which you govern AI across its life cycle. That framing matters: you are not certifying that one product is safe, you are certifying that your organisation has a repeatable way to keep AI accountable. Certificates are valid for three years, with annual surveillance audits in between.
Because ISO 42001 shares the high-level structure used by ISO 27001 and ISO 9001, certification slots into management systems you may already run rather than sitting beside them as a separate silo.
Who needs ISO 42001 certification, and who does not
No law currently forces any company to hold ISO 42001 certification. Demand is driven by the market and by risk exposure rather than by statute. Three groups tend to pursue it first.
The first is providers and developers of AI systems who sell into regulated sectors, where buyers now ask for evidence of AI governance during procurement. A certificate answers that question once, in a form auditors and customers recognise.
The second is enterprises deploying AI at scale internally, where boards want assurance that AI risk is managed with the same rigour as security or financial control. Certification gives leadership an external check on that claim.
The third is organisations preparing for the EU AI Act and similar regimes, who use certification to put governance foundations in place before obligations bite.
Certification is less urgent for teams running a single low-risk pilot with no external stakeholders. For them, adopting the practices without paying for a certificate is often the sensible first step. A short readiness assessment, which you can support with an AI risk management platform, usually clarifies which camp you are in.
What you are audited against: clauses 4 to 10 and Annex A
An ISO 42001 audit examines two layers. The first is the management-system requirements in clauses 4 to 10. The second is the applicable controls in Annex A.
The management-system clauses
Clauses 4 to 10 follow the common structure shared across modern ISO standards, and they run on a Plan-Do-Check-Act rhythm:
- Clause 4, Context: define the scope of your AIMS and the interested parties it must satisfy.
- Clause 5, Leadership: assign accountability, publish an AI policy, and secure executive ownership.
- Clause 6, Planning: identify AI risks and opportunities, set objectives, and run an AI impact assessment.
- Clause 7, Support: provide resources, competence, awareness, and documented information.
- Clause 8, Operation: run the AI risk assessment and treatment, and control the AI life cycle.
- Clause 9, Performance evaluation: monitor, audit internally, and hold management reviews.
- Clause 10, Improvement: handle nonconformities and drive continual improvement.
Annex A: 38 controls across nine objectives
Annex A lists 38 reference controls organised under nine objectives numbered A.2 to A.10, according to authoritative readings of the standard (ISMS.online). The objectives span AI policy, internal organisation, resources for AI systems, AI impact assessment, the AI system life cycle, data for AI systems, information for interested parties, responsible use of AI, and third-party relationships. You justify which controls apply in a Statement of Applicability, the same mechanism ISO 27001 practitioners will recognise.
For a fuller walkthrough of each objective, our explainer on the ISO 42001 standard sets out how the clauses and Annex A fit together.
The certification process, phase by phase
Most programmes move through five phases before the certificate is issued.
- Preparation and gap analysis. Define the certification scope, then compare current practice against the clauses and Annex A to find the gaps. This phase runs from two weeks to three months.
- AIMS design and documentation. Build the policies, risk processes, roles, and the Statement of Applicability. Expect one to three months.
- Implementation and training. Operate the system, train staff, and start generating the records the audit will need. This is the longest phase for most, at one to four months.
- Internal audit and management review. Test the system yourself, close obvious findings, and have leadership formally review it. Roughly one month.
- External certification audit. An accredited body runs the audit in two stages.
Stage 1 and Stage 2 audits
Stage 1 is a documentation review: the auditor checks that the AIMS is designed correctly and that you are ready. Stage 2 is the main event, where the auditor gathers evidence that the controls operate in practice, interviews owners, and samples records. Findings are graded, and any major nonconformity must be resolved before the certificate is granted. Together the two stages usually span one to two months (SureCloud).
How long ISO 42001 certification takes
For most organisations, ISO 42001 certification takes four to twelve months from kickoff to certificate. A small company with a narrow scope and mature governance can reach it in three to four months, while a large enterprise with many AI systems and little existing structure sits at the upper end.
The single biggest accelerant is an existing ISO 27001 programme. Because the two standards share their backbone and several controls, teams that already run an information security management system reuse much of the scaffolding and cut the timeline materially.
How much ISO 42001 certification costs
Costs fall into three buckets: the certification body’s audit fees, any consultancy or tooling you use to get ready, and the recurring surveillance audits.
For small and mid-sized firms, total spend commonly runs between $4,000 and $20,000, while broader estimates that include consultancy reach 15,000 to 80,000 euros depending on scope and complexity (Advisera). Audit fees make up a predictable share; consultancy is the variable that scope drives hardest. Annual surveillance audits then add a smaller recurring line, and recertification comes around every three years.
As with the timeline, prior ISO 27001 certification lowers cost, because the gap to close is smaller. Treating readiness as a controls-and-evidence exercise rather than a one-off document sprint keeps the number down, since most overrun comes from rework.
ISO 42001 certification and the EU AI Act
This is where careful language matters. ISO 42001 certification does not make you compliant with the EU AI Act, and any claim that it does is wrong. ISO 42001 is a voluntary international standard. It is not, at the time of writing, a harmonised European standard, so it does not by itself grant the presumption of conformity that Article 40 of the EU AI Act attaches to harmonised standards (ISMS.online analysis).
The harmonised AI-management-system standard the EU is developing, referenced as prEN 18286, is the document that will carry that legal weight once cited in the Official Journal. Its draft is designed to map back to ISO 42001 Annex A, so certified organisations should be able to reuse existing controls rather than start over.
What certification does buy you is readiness. The obligations the AI Act places on high-risk providers, from risk management and data governance to logging, human oversight, transparency, and post-market monitoring, overlap heavily with an ISO 42001 AIMS. Certification puts those foundations in place and gives you an audit trail, which is why we describe it as preparation and a trust signal rather than a finish line. For the wider picture, see our view on why ISO 42001 alone will not deliver AI Act compliance.
Keeping certification alive: surveillance and continuous compliance
A certificate is a snapshot; the standard expects a living system. After Stage 2, the certification body returns for surveillance audits, typically once a year, to confirm the AIMS still operates and improves. Let controls lapse between audits and you risk findings that suspend the certificate.
Continuous compliance is mostly an evidence problem. Each applicable control needs an owner, a record that it ran, and a review cadence. Management reviews and internal audits have to happen on schedule, and corrective actions from earlier findings must be closed and documented. Doing this in spreadsheets works until the AI inventory grows, at which point the mapping from controls to owners to evidence becomes the bottleneck.
This is the work a governance platform is built for: a live inventory of AI systems, each control tied to its evidence, and review cycles that surface what is due before an auditor asks. That operational layer is what turns a one-time ISO 42001 certification into durable governance.
FAQ
Is ISO 42001 free? No. The standard itself is a copyrighted document you purchase from ISO or a national standards body. Certification then adds the cost of an accredited audit, and usually some readiness work, so the real figure is the total programme cost, not just the document price.
Who needs ISO 42001 certification? Anyone who has to prove structured AI governance to an outside party: AI providers selling into regulated markets, enterprises deploying AI at scale, and organisations preparing for the EU AI Act. Teams running a single low-risk pilot with no external stakeholders can usually adopt the practices without certifying yet.
What is the difference between ISO 27001 and ISO 42001? ISO 27001 certifies an information security management system; ISO 42001 certifies an AI management system. They share the same structural backbone and several overlapping controls, so they are designed to integrate. Holding ISO 27001 makes ISO 42001 certification faster and cheaper.
How long does ISO 42001 certification take? Four to twelve months for most organisations, and as little as three to four months for a small, well-prepared scope. The strongest accelerant is an existing ISO 27001 programme.
Does ISO 42001 certification make me EU AI Act compliant? No. It prepares you and demonstrates diligence, but ISO 42001 is not a harmonised standard and does not grant presumption of conformity. The forthcoming prEN 18286 is the standard to watch for that legal effect.
How often is recertification required? The certificate is valid for three years, with annual surveillance audits in between. At the end of the cycle a recertification audit renews it.
Conclusion
ISO 42001 certification is less a badge than an operating discipline. It asks you to define how AI is governed, prove that the system runs, and keep improving it under independent review. Treated that way, certification does double duty: it satisfies customers and boards today, and it lays the groundwork for the EU AI Act tomorrow. The organisations that get the most from it are the ones that build the evidence layer once and maintain it, rather than sprinting to a certificate and letting the controls drift. If you are scoping the work, start by mapping your AI systems and the controls that govern them, then decide where ISO 42001 certification fits your roadmap.