TL;DR: ISO 42001 certification covers an organization’s AI management system (AIMS). Build and operate an AIMS that meets ISO/IEC 42001:2023, then an accredited certification body reviews readiness at Stage 1 and implementation at Stage 2. The body makes a separate certification decision after the audit. A successful decision begins the three-year certification cycle, maintained through surveillance audits.
The shape of the path will look familiar if you have taken an organization through ISO 27001: stand up the management system, then bring in an external body for a two-stage audit and annual surveillance. What changes with ISO 42001 is the subject. The standard governs how your organization develops, provides, or uses AI systems, and Stage 2 does not check whether you wrote the policies. It checks whether the AI management system is working.
Something else changes too, and it shapes every decision you make from here: the certificate is not the finish line. It is the start of a cycle in which an accredited body returns every year to see whether the system is still running. A program built to assemble documents for one audit date has to reassemble them for the next surveillance visit, and the one after that. A program whose AIMS produces current evidence on its own has far less to rebuild.
This guide walks the path to certification and shows where the choices along the way cost time or money — most of them long after the certificate is issued.
Is ISO 42001 certification for organizations or individuals?
ISO 42001 certification applies to an organization’s AI management system, not to a person. The certificate names the organization whose system was audited.
Individuals do take ISO 42001 training, qualifying as ISO/IEC 42001 lead auditors or lead implementers. Those are professional credentials for auditing or implementing an organization’s system, and a different purchase from the organizational certificate.
How much does ISO 42001 certification cost?
Cost depends on the scope of the AI management system and the work required to audit it. Ask the certification body for a scoped quote that separates audit days, day rate, surveillance and other charges. A headline price without those assumptions is not a budget.
ISO/IEC 42006:2025 sets requirements for bodies auditing an AIMS, including how audit time is calculated. Give the body what it needs: the AI activities and roles in scope, the people involved, the sites and legal entities, and how the management system is organized. Ask it to explain its assumptions and any additions or reductions. Total headcount alone does not describe the work.
One assumption to correct before it reaches your budget. Teams holding ISO 27001 routinely expect an integrated audit to absorb most of the ISO 42001 work. IAF MD 11:2023 governs audit time for integrated audits: time is calculated per standard, summed, then adjusted, and where the adjustment reduces the total it “shall not exceed 20% from the starting point.” That is a cap on the combined audit-time baseline, not a measure of what your existing certificate is worth; the actual reduction depends on integration and the ability to audit both systems together.
Around that audit-day core, a few drivers move the total:
- Organization size and sites in scope. More legal entities and locations mean more to audit.
- Your role and the number of AI systems in scope. Providers and larger AI footprints raise audit time.
- How mature the AIMS already is. A documented, operating system has evidence to assess; incomplete implementation needs follow-up.
- Readiness work done beforehand. Unresolved concerns can add follow-up or delay progression.
The body’s invoice is not the whole cost. Around it sit readiness work, internal time from control owners and your program lead, building or fixing controls over your AI systems, and running the program through the surveillance cycle. Leaving those out is how budgets get surprised.
Ask the body to show its audit-day calculation separately from its day rate, so you can see what is driving the number.
{{ banner-image }}
The ISO 42001 certification process, step by step
The path has a fixed order, and the split of who does what is worth getting right early: your organization builds and runs the system, an external accredited body audits it, and the certification decision is made by people who did not run the audit.
1. Build or align your AIMS to ISO/IEC 42001:2023. The bulk of the preparation. Define your organization’s role, set the AIMS scope, establish AI policies and responsibilities, and perform risk and impact assessments. If you are evaluating tooling to maintain those records, the ISO 42001 compliance software page explains what to look for.
2. Engage an accredited certification body — and verify the accreditation yourself. This step carries more weight here than in a mature scheme, for the reasons above. Check the accreditation body’s register, confirm the scope names ISO/IEC 42001, and note the date it was granted. A familiar logo or a long history in other schemes does not establish accreditation for this one. Then agree scope, audit plan, fees and the process for handling findings before fixing dates.
3. Stage 1 audit: documentation and readiness. The body reviews whether the AIMS is designed and ready, and produces areas of concern to close before Stage 2.
4. Stage 2 audit: the system in operation. The body audits whether your policies and controls are implemented and effective, not just written.
5. Certification decision. Made by people separate from the audit team — a separation accreditation exists to verify.
Build the calendar from readiness evidence and the body’s availability. A policy draft is not the same milestone as a policy approved and used; a risk register is not finished while treatment decisions lack owners. Agree what must be complete for Stage 1 and reserve time to address its concerns.
The certification decision is the start, not the finish
Those five steps read like a project plan with a terminus. That shape is the most expensive assumption in ISO 42001, because the decision at step 5 is where the work begins rather than where it stops.
Here is what the decision actually starts. Under ISO/IEC 17021-1, which every accredited body works to, the first surveillance audit falls within 12 months of the certification decision. Surveillance continues in year two. Recertification comes before the certificate expires at the end of year three. Across a first cycle you are audited four times, not once, and every one of those visits asks the same question Stage 2 asked: is this management system working?
Meanwhile the subject moves. Clause 8.4 ties the AI system impact assessment to planned intervals or to significant changes being proposed or occurring — not to your audit calendar. Clause 6.3 requires you to plan changes to the management system itself. The standard assumes the thing under management does not hold still, which is a reasonable assumption about AI systems.
So there are two programs you could build, and on the day the certificate is issued they look identical.
The first assembles evidence for an audit date. It works. It passes. Then the evidence ages, and eleven months later the same people run the same interviews and send the same requests, because nothing about the first pass made the second one easier. Each cycle starts from zero.
The second produces evidence as a by-product of operating. It can answer “is the AIMS working right now” on any day, which includes audit day, because audit day is not special. Surveillance becomes a read of records that already exist.
The difference between them is invisible at Stage 2. It shows up at the first surveillance and it is substantial by recertification.
Most teams build the first kind, and not because they chose badly. When evidence is collected by hand, an annual scramble is the only cadence the calendar allows — the method is the constraint, not the team. What changes the answer is changing the method.
Which makes the question worth asking in month one a different one than most programs ask. Not “what do we need for the audit.” What will this look like on a random Tuesday in year two, when nobody is preparing for anything.
What ISO 42001 implementation involves
The following is a working plan for organizing preparation, not an additional set of ISO requirements.
Preparation resultSuggested accountable roleEvidence to have readyAIMS boundary and AI-system scopeAIMS/program owner with business and technical ownersDefined activities, organizational roles, systems, sites and exclusions.AI risk and impact decisionsRisk owners and affected business/system ownersRisk and impact assessments, decisions, selected controls and reasons.Controls operating in practiceControl ownersApproved procedures plus implementation and operating records for the period reviewed.Internal review and corrective actionInternal audit lead and managementAudit and management-review records; findings, owners and evidence of corrective action.External audit readinessAIMS owner with certification bodyAgreed scope, audit plan, accessible evidence and resolved Stage 1 concerns.
Implementation is where most of the calendar goes, and none of it belongs to the auditor. The pieces:
Your role and scope. Determine whether your organization provides, produces, or uses AI systems, and set the AIMS boundary. Both drive what you control and how long the audit runs.
AI governance roles. Name who owns AI governance, who owns each policy and control, and who decides on AI risks.
Risk assessment. Cover AI-specific risks such as lack of transparency, fairness considerations, and system bias.
AI system impact assessment. Its own piece of work, distinct from risk assessment, required by clauses 6.1.4 and 8.4: how an AI system and its foreseeable uses could affect individuals and society. Clause 8.4 ties it to planned intervals or to significant change, so it is not an annual task by default. ISO/IEC 42005:2025 is the guidance for running one.
Policies and controls. Set the policies, objectives and procedures for responsible AI, and put the controls in place.
Internal audit and management review. Both happen before the external audit. Stage 1 and Stage 2 expect them done.
Evidence. The scope, policies, methodologies and Statement of Applicability Stage 1 reads, and the operating records Stage 2 tests.
How you generate that evidence is where implementation either sets you up for the years ahead or leaves you rebuilding. Stage 2, and every surveillance audit after it, looks at the system in operation, so the evidence has to be current when the auditor arrives. A program that collects by hand for the audit date starts each cycle from scratch.
That is the case for running the AIMS on evidence that maintains itself. With Anecdotes’ ISO 42001 software workflow, evidence is collected from connected systems on a schedule and the analysis rules that check it re-run on each new version, so a gap surfaces when it appears rather than at the next review. A playbook can open a finding and assign an owner. The platform closes nothing on its own: it surfaces the gap and routes it, and a person owns the decision.
Much of what ISO 42001 asks for is documented judgment rather than system state, and automated collection keeps only the technical share current. Where a control expects evidence you already collect for ISO 27001, that evidence is reused — but cross-mapping is not proof, so confirm it against each ISO 42001 requirement.
AI risks are managed the same way as your security risks. Each risk has an owner in the risk-management process who decides whether to mitigate, accept, transfer, or avoid it and can explain the reason, and risks are tied to the controls meant to reduce them.
If you want to see what running an AIMS on continuous evidence looks like, the shortest path is a working session with your own systems connected. Book a demo when you are ready.
The ISO 42001 audit: Stage 1 and Stage 2
Stage 1 reviews whether the AIMS is designed and ready. Stage 2 audits whether it actually operates, and it is the one a documents-only program underestimates.
Stage 1Stage 2FocusDesign and readiness of the AIMSThe AIMS in operationWhat the auditor reviewsScope, policies, risk and impact methodologies, Statement of Applicability, and whether internal audit and management review are doneWhether policies and controls are implemented and effective: risk and impact management, monitoring against objectives, internal audit, management review, corrective actionsWhat it producesAreas of concern to close before Stage 2, and a Stage 1 reportA certification recommendation, decided by people separate from the audit team
One accredited body, Schellman, publishes typical durations of 1–2 days for Stage 1 and 3–9 or more days for Stage 2, with a typical 4–12 week interval between them, and notes Stage 1 may need to be performed again if the gap exceeds six months. Those are that body’s stated ranges, not a universal timetable. Confirm your own calculation and the applicable policy with the body conducting your assessment.
If the audit finds a nonconformity, record its classification, the required response and the due date. A useful corrective-action record separates the immediate correction from the root cause and the evidence the fix worked. Agree whether the body needs a document review, further evidence or a follow-up visit.
Anecdotes holds ISO 27001, ISO 27701 and ISO 42001, described in its first-hand certification account. That is one team’s experience, not a promise about another organization’s scope, findings or timeline.
Maintaining certification: surveillance and re-certification
A certificate starts an ongoing audit cycle. Under ISO/IEC 17021-1, which every accredited certification body works to, the first surveillance audit takes place within 12 months of the certification decision date.
First surveillance within 12 months of the decision, then continuing surveillance. Agree dates with the body as part of the audit program, not from an assumed certificate-printing date.
Shorter than the initial audit, but not a formality. Expect the body to select records and activities for review and to ask how changes and findings were handled.
Re-certification before the certificate expires at the end of the three-year cycle. If it lapses, the route back depends on the body’s restoration procedures; do not assume the certificate stays valid while work continues.
This is the discipline the whole cycle rewards, and it is why the evidence question is settled in month one rather than in month thirty. Keep the scope, risk and impact decisions, operating evidence and corrective actions current as the AI systems change. Plan for the cycle, not just the first certificate.
Frequently asked questions
How does an organization get ISO 42001 certified?
Build an AI management system that meets ISO/IEC 42001:2023, then engage an accredited certification body to audit it in two stages. Stage 1 reviews documentation and readiness; Stage 2 audits the system in operation. A certification decision follows from people separate from the audit team.
How do I check whether a certification body is accredited for ISO 42001?
Use the accreditation body’s public register, not the certification body’s website, and check three things: that the body appears, that its scope names ISO/IEC 42001 specifically rather than a general management-systems scope, and the date that scope was granted. Accreditation for this scheme arrived at different accreditation bodies at very different times, and bodies are still being accredited, so a body can be reputable and accredited for other schemes without yet holding this one. Ask for its current accreditation certificate, and whether it works to ISO/IEC 42006:2025.
Does it matter if an ISO 42001 certificate is not accredited?
It matters, and it is not the same as invalid. Accreditation has never been a legal prerequisite for issuing a certificate. What an unaccredited one lacks is the independent chain — no external check on auditor competence, duration or impartiality, and no register to trace it through. If you hold one, be able to explain it rather than hope nobody asks.
How much does ISO 42001 certification cost?
The body quotes the audit work against your AIMS scope. Budget separately for preparation, internal time, implementation, the initial audit, surveillance and recertification — software fees and readiness consulting are separate from the certification decision. An existing ISO 27001 certificate does not itself guarantee a reduction; IAF MD 11:2023 caps any integrated-audit reduction at 20% of the combined audit-time baseline.
What are the stages of the ISO 42001 certification audit?
Two. Stage 1 reviews AIMS documentation and readiness, including whether internal audit and management review are complete. Stage 2 audits the system in operation. One accredited body puts Stage 1 at 1 to 2 days and Stage 2 at 3 to 9 or more, but your length depends on scope and is calculated with your own body.
How long does the ISO 42001 certification process take?
It depends on the work needed to establish and operate the AIMS, resolve readiness concerns and schedule audits. Track completed deliverables rather than another organization’s timeline. Stage 1 and Stage 2 are separate events whose interval must leave time to address Stage 1 concerns.
What does ISO 42001 implementation involve?
Standing up an AI management system over your AI systems: defining role and scope, naming AI governance roles, running an AI risk assessment and an AI system impact assessment, setting policies and controls, and completing internal audit and management review before the external audit.
Key takeaways
- ISO 42001 certifies your organization’s AI management system, not any individual.
- The certification decision starts the cycle rather than ending it. First surveillance falls within 12 months, surveillance continues in year two, recertification comes at year three — four audits in a first cycle, each asking whether the system is working now.
- A program that assembles documents for the audit date passes Stage 2 and pays for it at every surveillance visit afterwards. One that produces evidence as a by-product of operating answers on any day. The two look identical the day the certificate is issued.
- Verify a body’s ISO 42001 scope and its grant date on the accreditation body’s register, not the body’s website. Accreditation for this scheme arrived at different bodies at very different times.
- An integrated audit may reduce the combined audit-time baseline by up to 20% under IAF MD 11:2023; an existing ISO 27001 certificate does not itself guarantee that reduction.
- The impact assessment lives with the AI system’s lifecycle and with significant change, per clause 8.4 — refreshed as the system changes, not rebuilt for audit day.






