ISO 42001 Certification: How the AI Audit Actually Runs
ISO 42001 certification means two completely different things depending on who is searching for it, and almost nothing published on the topic separates them. This post is about the organizational version: the audit that certifies a company's AI management system, what the certification body actually checks, and what drives the cost and timeline.
If you want the standard itself rather than the audit process, start with the ISO 42001 guide.
First: Which Kind of Certification Do You Mean?
Search results for this topic mix two unrelated products. Sort out which one you need before you spend anything.
Organizational certification audits your company. An accredited certification body examines your AI management system (AIMS) against ISO/IEC 42001:2023, and if it conforms, issues a certificate in the company's name. This is what a customer means when they ask whether you are ISO 42001 certified. It is what a procurement questionnaire is asking for.
Individual certification is a training credential. Providers such as PECB, BSI, and others run ISO 42001 Lead Implementer and Lead Auditor courses ending in an exam. The credential belongs to the person, not the business. It is useful if you are the one who will run the implementation or audit programs, and it is what queries like "ISO 42001 certification for individuals" or "certification exam cost" are looking for.
The two are complementary, not substitutes. Sending your compliance lead on a Lead Implementer course does not certify your company. Certifying your company does not credential your staff.
Everything below concerns the organizational path. We do not run training courses, so if you came for the individual credential, go directly to a training provider.
What the Certificate Actually Attests
This is worth being precise about, because it is oversold constantly.
ISO 42001 certification does not say your AI is accurate, safe, fair, or free of bias. No audit could say that, and no certification body claims it.
What it says is that you operate a management system for AI: you know what AI systems you run, you have assessed what could go wrong with each of them and who it could affect, you have assigned accountability for them, you monitor them, and you improve the system when something goes wrong. It is a statement about governance maturity, not model quality.
That distinction matters commercially. When an enterprise buyer asks how you govern AI, they are usually not asking you to prove your model is unbiased. They are asking whether anyone is minding the store. The certificate answers that question with third-party evidence.
The Certification Path, Start to Finish
1. Define scope
Scope is the single biggest cost lever in the entire project, so decide it deliberately.
You are defining which AI systems, which business units, and which locations sit inside the management system. A scope covering one product line with three AI systems is a different engagement from a scope covering an entire multi-entity group.
Two common mistakes:
- Scoping too wide too early. Every additional AI system adds inventory, risk assessment, and monitoring work. You can extend scope at a later surveillance audit.
- Scoping so narrowly the certificate does not answer the buyer's question. If the certificate excludes the product your customer is buying, it does not help you close the deal. Check the scope statement against what your prospects are asking about.
2. Gap assessment
Compare what the standard requires against what you actually have. Most organizations discover the same pattern: the security and quality scaffolding largely exists, and the AI-specific governance does not.
Typically already in place if you hold ISO 27001:
- Management system structure, policy, leadership commitment
- Risk methodology, internal audit function, management review
- Document control, competence and training, corrective action
Typically missing:
- An inventory of AI systems with owners and lifecycle stage
- AI-specific impact assessment covering effects on individuals and groups
- Data governance for training and evaluation data
- Documented human oversight arrangements
- Supplier controls covering third-party models and AI services
That last one catches people. Most companies deploying AI are not training foundation models. They are consuming someone else's, which makes third-party governance a large share of the work.
3. Build and operate
Close the gaps, then run the system. This second half is the part teams underestimate.
A certification body cannot audit a management system that has never operated. It needs records: risk assessments that were actually performed, an AI inventory that has been maintained, oversight decisions that were logged, incidents that were handled through the process. A policy approved the week before the audit and never exercised is a finding, not evidence.
Plan for a period of genuine operation before Stage 2. How long depends on your audit cycle and your certification body's expectations, so ask them directly during scoping rather than guessing.
4. Internal audit and management review
Both are requirements of the standard, and the certification body will ask to see them. Run a full internal audit against the standard, log what it found, and hold a documented management review where leadership examines the results and makes decisions.
Skipping these to save time is the most reliable way to fail Stage 1.
5. Stage 1 audit
The certification body reviews your documentation and assesses readiness. They are checking that the management system exists on paper, that the scope makes sense, and that you are ready to be tested.
Stage 1 commonly surfaces gaps. That is what it is for. Finding them here is much cheaper than finding them at Stage 2.
6. Stage 2 audit
The real one. Auditors test whether the system works in practice: interviewing staff, sampling AI systems from your inventory, tracing risk assessments through to the controls that came out of them, checking that oversight actually happened.
Findings are graded. Minor nonconformities need a corrective action plan. Major nonconformities have to be fixed and verified before a certificate can be issued.
7. Certificate and surveillance
The certificate runs on a three-year cycle with surveillance audits in between, typically annual, and a recertification audit at the end. Certification is an ongoing commitment, not a one-time purchase, and the surveillance audits are where an unused management system gets exposed.
What Drives ISO 42001 Certification Cost
We do not publish pricing, because any number quoted without seeing your scope would be fiction. What we can tell you is what moves it, so you can estimate sensibly and compare quotes on a like-for-like basis.
Scope size. The number of AI systems, sites, and legal entities in scope. This dominates everything else.
AI system diversity. Five similar recommendation models are less work than five systems doing genuinely different things, because each distinct use case needs its own impact assessment.
Existing certifications. If you hold ISO 27001, a large share of the management system scaffolding already exists and can be reused. Combined audits with a single certification body also reduce audit days versus running two separate programs.
Documentation maturity. Organizations with an existing risk register, vendor inventory, and functioning internal audit program start much further along.
Gap remediation effort. Usually the largest line item, and it is internal effort or consulting rather than a certification body fee. The audit fee is often the smaller half of the total.
Audit cycle costs. Budget the full three-year cycle, not just the initial audit. Surveillance audits recur.
When you request quotes, give each certification body an identical scope statement and AI system count. Otherwise you are comparing numbers that describe different projects.
How Long Does It Take?
The honest answer is that it depends on where you start, and the biggest variable is the operating period before Stage 2 rather than the audit itself.
A company that already holds ISO 27001, has a small AI scope, and maintains decent documentation moves considerably faster than one building its first management system from nothing while inventorying AI systems it did not know it had.
The long pole is almost always discovery: finding every AI system in use across the business, including the ones individual teams adopted without telling anyone. Start that inventory on day one, well before you engage a certification body.
Choosing a Certification Body
A few practical checks:
- Accreditation. Confirm the body is accredited for ISO 42001 specifically by a recognized accreditation body. Accreditation for other ISO standards does not automatically extend to this one.
- Independence. A body that audits you cannot also consult for you on the same management system. Any firm offering both is either misdescribing one of them or cannot issue your certificate.
- Sector familiarity. An auditor who understands your AI use case asks better questions and wastes less of your time.
- Combined audit capability. If you also hold or want ISO 27001, a body that can audit both together saves real money.
ShieldKey does implementation and readiness work, not certification. We cannot issue your certificate, and any consultancy that says it can is describing something else.
For the standard itself and what an AI management system contains, see the ISO 42001 guide and the ISO 42001 service page. If you are weighing the standard against a framework rather than a certificate, ISO 42001 vs NIST AI RMF covers that decision. The audit process mirrors the security one closely, so what to expect in an ISO 27001 audit is a useful companion read, and the ISO 27001 service page covers the combined-certification path.
Frequently Asked Questions
What is the purpose of ISO 42001 certification? It proves an organization runs a managed, audited system for governing AI. An accredited body checks your AI management system against ISO/IEC 42001:2023 and certifies conformity. It answers procurement and security-questionnaire questions with third-party evidence. It does not certify that any individual model is safe, accurate, or unbiased.
How do you get ISO 42001 certification? Define scope, run a gap assessment, build the missing governance, then operate it long enough to generate records. Run an internal audit and management review. Engage an accredited certification body for the Stage 1 documentation audit and the Stage 2 operational audit, clear any nonconformities, and maintain the certificate through annual surveillance audits.
How much does ISO 42001 certification cost? There is no list price. Cost is driven by scope: number and diversity of AI systems, sites and entities, whether you already hold ISO 27001, the state of your documentation, and how much gap remediation is needed. Budget both the certification body's audit fees across the three-year cycle and the readiness effort, which is usually the larger share.
Is ISO 42001 mandatory? No. It is a voluntary standard. What is growing is commercial pressure from enterprise and public sector buyers asking how AI is governed. Regulation like the EU AI Act creates separate legal obligations, and ISO 42001 helps produce governance evidence for them, but the certificate is not a substitute for meeting a legal requirement.
Is ISO 42001 certification for individuals or for companies? Both exist and they are unrelated. Organizational certification audits a company's management system. Individual certification is a training credential like Lead Implementer or Lead Auditor, awarded to a person. For a procurement answer you need the organizational kind. For personal credentials, go to a training provider.
Planning an ISO 42001 Certification?
ShieldKey Solutions runs AI management system readiness work: scoping, gap assessment, building the AI inventory and impact assessment process, and getting you audit-ready before a certification body arrives. We do not issue certificates, which is exactly why we can tell you honestly what your scope should be.