The question arrives from sales, not compliance. A prospect’s vendor questionnaire has a line item — “Is your organization certified to ISO/IEC 42001?” — and the deal is large enough that someone forwards it upward with a note asking how quickly we can get that.
That framing is the right one, and almost nobody uses it. ISO 42001 certification answers a commercial question, not a regulatory one. It does not make you compliant with any law. What it does is let you answer a procurement question with a certificate instead of a forty-page security response.
Whether that is worth six to twelve months of work depends on facts specific to you. This covers what the standard actually requires, what certification involves, the thing people most often get wrong about its relationship to the EU AI Act, and how to decide whether to start now.
What the standard actually is
ISO/IEC 42001:2023 is an AI management system standard. Note the phrase — it governs how you manage AI, not how your models behave. Nothing in it evaluates a model’s accuracy, robustness, or fairness directly. It evaluates whether you have a system for deciding those things and evidence that the system runs.
Structurally it uses the same Harmonized Structure as ISO 27001 and ISO 9001. Clauses 4 through 10 cover context, leadership, planning, support, operation, performance evaluation, and improvement, in that order. If you have been through an ISO 27001 implementation, this shape is already familiar, and that familiarity is worth a great deal — more on that below.
The distinctive part sits in Annex A: a set of controls organized under control objectives covering AI policy, internal organization, resources for AI systems, impact assessment, the AI system lifecycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships.
The control that has no equivalent in 27001 is the AI system impact assessment — an assessment of consequences for individuals and groups, not just for the organization. That is the clause that catches security teams by surprise. Every instinct built through information security points at risk to the business. This one points outward.
What certification actually involves
Certification is against an accredited certification body, and it runs the standard ISO path.
- Stage 1 — documentation review. The auditor checks that the management system exists on paper: scope, policy, risk methodology, Statement of Applicability. Failures here are almost always scope definition problems.
- Stage 2 — implementation audit. The auditor checks that the system runs. Records, not intentions. This is where organizations that wrote good documentation and changed nothing operationally get found out.
- Surveillance audits in years one and two, then recertification in year three. Certification is a subscription, not a purchase.
The artifacts you need to produce are recognisable to anyone who has done this before: defined scope, an AI policy, named roles and responsibilities, a risk assessment methodology and its results, a Statement of Applicability justifying every control you included or excluded, impact assessments for your AI systems, internal audit results, and a management review.
Scope is the decision that determines everything else. You are not certifying the company. You are certifying a defined boundary — specific AI systems, specific processes, specific sites. A narrow, honest scope certifies faster and holds up better than a broad one you cannot evidence. Organizations that scope wide to make the certificate sound impressive spend the next three years defending it at every surveillance audit.
The thing people get wrong
This is the misconception worth correcting before you spend anything: ISO 42001 certification does not give you a presumption of conformity with the EU AI Act.
Under the Act, presumption of conformity attaches to harmonised standards — European standards developed under a Commission mandate and cited in the Official Journal. ISO/IEC 42001 is an international standard developed through ISO and IEC. Those are different instruments with different legal effect, and the gap between them is precisely why the high-risk obligations were pushed back: the harmonised standards were not ready.
What certification gives you is a management system that produces much of the evidence the Act will want, and an auditable record that you were governing these systems deliberately. That is genuinely valuable. It is not a compliance shortcut, and any vendor telling you otherwise is selling something.
Treat them as separate workstreams that share inputs. The inventory, the classification, the impact assessments, and the change control feed both.
What it costs
Time, mostly, and the range is wide because the starting point varies enormously.
- With a certified ISMS already running: the shorter end. You have the management system machinery — internal audit, management review, risk methodology, document control — and you are adding an AI scope to it rather than building from nothing. Many organizations run integrated 27001 and 42001 audits with the same body.
- With no management system experience: considerably longer, and most of the time goes into things that are not AI-specific at all. Document control, internal audit competence, and management review are new muscles.
The cost that surprises people is not the certification body’s fee. It is the internal audit and management review cadence, which continues indefinitely. Budget for the operating cost, not just the project.
Should you do it yet?
Four questions. If you answer yes to two or more, it is probably worth starting.
- Has a customer or prospect asked? Not “might ask” — has one asked, in writing, in the last six months. This is the strongest signal by a distance, and it is the one that justifies the spend to a board.
- Do you already hold ISO 27001? The marginal cost is far lower and the integration is real, not theoretical.
- Do you sell AI functionality, rather than just use it? Providers get asked. Deployers mostly do not.
- Do you sell into regulated sectors or the public sector? Those buyers use certification as a procurement filter, which makes it a revenue question rather than a compliance one.
If you answered no to all four, build the governance without the certificate. The inventory, the impact assessments, and the approval records carry most of the value. You can certify later against a system that is already running, which is a much easier project than certifying and implementing at once.
What good looks like
Before you engage a certification body, you should be able to answer these from documents:
- What exactly is in scope — which AI systems, which processes, which locations — and why is everything else out?
- For each in-scope system, where is the impact assessment, and when was it last reviewed?
- Which Annex A controls did you exclude, and what is the written justification?
- When did you last run an internal audit and a management review, and what came out of them?
- Scoping wide to make the certificate sound better. Every system in scope is a system you evidence at every surveillance audit, forever.
- Buying certification as a compliance shortcut. It is not a route to EU AI Act conformity, and building the programme on that belief means discovering the gap at the worst moment.
- Writing documentation without changing operations. Stage 1 reviews documents. Stage 2 reviews records. The second one is where this approach collapses.
- Treating the impact assessment as a risk assessment. Risk assessment asks what could harm the organization. Impact assessment asks what could harm the people affected by the system’s output. Reusing one for the other produces a finding.
- Running it as a project with an end date. Surveillance audits arrive annually whether or not the team that built the system is still assigned to it.
That last one is the most common Stage 2 failure. You need to have actually run the cycle at least once, with findings and actions, before an auditor will accept that the system operates.
Five failure patterns worth avoiding
Where to start
Define the scope first, on one page, before anything else. Which AI systems, which processes, which parts of the organization — and the written reason everything else sits outside. Almost every implementation problem downstream traces back to this page being vague.
Then build the inventory for that scope, run one impact assessment properly rather than six badly, and draft the Statement of Applicability. Those three artifacts will tell you within weeks whether the timeline you promised sales is realistic.
And be honest with the question underneath all of this: are you certifying because a buyer asked, or because certification feels like progress? The first is a business case. The second is an expensive way to avoid deciding what you actually need.
Get the template
Our ISO 42001 Readiness Pack ships with the scope definition worksheet, an AI system impact assessment template, a Statement of Applicability starter, and the internal audit checklist — tailored to your sector and size.
Deciding whether to certify? Book a free 30-minute call. No slides — you leave with a view on whether it is worth it for you, whether or not you hire us.
References
– ISO/IEC 42001:2023 — Information technology, Artificial intelligence, Management system
– ISO/IEC 27001:2022 — for the Harmonized Structure comparison
– Regulation (EU) 2024/1689 (EU AI Act) — Article 40 on harmonised standards and presumption of conformity
Advisory content, not legal advice.
