ISO 42001

The ISO 42001 certification process

ISO/IEC 42001 is the first certifiable standard for an AI management system. Here is the path from first scoping call to certificate, and what auditors look for at each step.
Certifyi compliance team · Updated September 2026
Short answer. ISO/IEC 42001:2023 certification follows the same route as other ISO management systems: define the scope of AI systems covered, establish the AI management system (AIMS) per clauses 4 to 10, perform AI risk and impact assessments, select controls from the 38 in Annex A with a Statement of Applicability, operate the system and run an internal audit and management review, then pass a Stage 1 documentation review and a Stage 2 implementation audit by an accredited certification body. Certificates run for three years with annual surveillance audits.

Step 1: decide which AI systems are in scope

Scope is the first audit question and the biggest cost driver. List every AI system you develop, provide or use in a material way, then decide which are in scope for certification. A SaaS company might scope its customer-facing recommendation model and its internal LLM assistant while excluding a vendor’s spam filter. Document the boundary, the roles (provider, developer, user) and the lifecycle stages covered.

Step 2: context, leadership and policy

Clauses 4 and 5 require you to understand internal and external issues, interested parties and their requirements (regulators, customers, affected individuals), and to publish an AI policy signed off by top management. The policy should state principles such as fairness, transparency, safety, accountability and privacy, and name who owns them.

Step 3: AI risk assessment and impact assessment

Clause 6 requires two linked assessments. The AI risk assessment looks at risks to the organisation from each system. The AI system impact assessment (control A.5) looks at consequences for individuals, groups and society: bias, safety, misuse, environmental impact. Both feed the risk treatment plan and the Statement of Applicability. Auditors expect the impact assessment to be a repeatable process, run per system and per material change, not a one-off memo.

Step 4: select controls and write the Statement of Applicability

The nine Annex A control objectives (38 controls)

Step 5: operate, measure, audit internally, review

Clauses 8 to 10 require the system to run: operational planning, the assessments performed as planned, performance monitoring, an internal audit programme and a management review with documented outputs. Certification bodies expect at least one internal audit and one management review to have taken place before Stage 2. Record decisions, not just meetings.

Step 6: Stage 1 and Stage 2

StageWhat the auditor doesTypical duration
Stage 1Reviews documentation: scope, policy, risk and impact assessment method, SoA, internal audit and management review records; confirms readiness1 to 2 days
Stage 2Tests implementation: interviews, sampling of AI systems, evidence of controls operating, data governance, logging, incident handling2 to 5 days depending on scope
SurveillanceAnnual check that the system still operates and improvesRoughly a third of Stage 2
RecertificationFull audit at the end of the three-year cycleSimilar to Stage 2

Step 7: combine with ISO 27001

ISO 42001 uses the harmonised structure, so clauses 4 to 10 mirror ISO 27001. Organisations with an ISMS reuse the context, leadership, document control, internal audit and management review machinery, and many certification bodies offer integrated audits. Certifyi runs both on one control library, with the AI system inventory, impact assessments and Annex A controls in the AI governance module and the auditor working in the Auditor Workspace.

ISO 42001 certification, answered

With an existing ISO 27001 system, three to five months to Stage 2 is realistic. Without one, six to nine months, most of it establishing the management-system machinery.

No. The standard covers organisations that develop, provide or use AI systems. A company that only uses third-party AI can certify a narrower scope.

Not by itself. It demonstrates a conforming AI management system, which covers much of the Act’s governance expectations, but the Act’s specific obligations for high-risk systems still need to be mapped and evidenced.

Bodies accredited to ISO/IEC 17021 with ISO 42001 in scope. Ask for the accreditation certificate and the number of 42001 audits the body has completed.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top