top of page

ISO/IEC 42001 certification: a step-by-step guide

  • 5 days ago
  • 5 min read
ISO/IEC 42001 certification: a step-by-step guide

ISO/IEC 42001 certification: a step-by-step guide


ISO/IEC 42001 is the international standard for managing artificial intelligence. This guide sets out what the standard requires, the nine steps from first assessment to certificate, what each stage involves, and the practical constraints that affect cost and timing.


What ISO 42001 requires

The standard requires an AI management system: the policies, processes and controls governing how your organisation develops, provides or uses AI across its lifecycle.


It follows the same management system structure as ISO 27001, which is why the two integrate well. It adds thirty-eight controls across nine control objectives, covering areas specific to AI: system inventory, risk and impact assessment, data governance, human oversight, lifecycle management and third-party AI.


It is a management standard rather than a technical one. It does not specify which models to use or what accuracy to achieve. It governs how you manage whatever you have chosen to use.


Your roadmap to certification

1. Decide whether you need it

Ask who is asking. If a client, a counterparty or a supplier programme has requested it, the decision is largely made and the remaining question is timing.


If nobody has asked, consider what your alternative answer would be. A questionnaire asking how your AI is governed still needs a credible response: an inventory, named owners, documented controls, evidence. That answer requires most of the same work.


2. Define your scope

Scope determines which parts of the organisation and which AI systems are covered, and it is stated on the certificate.


Drawn too widely, you pay to control systems nobody asked about. Drawn too narrowly, the certificate arrives and the client immediately asks about a system outside it.


This is the single most consequential decision in the project and it is made at the start.


3. Gap analysis

Assess your current position against each clause and each Annex A control. Classify what is missing by severity, and separate what must exist before certification from what can follow.


Expect the inventory to surface AI systems nobody had catalogued, and expect the evidence gaps to be larger than the control gaps. Most firms are doing more than they can prove.


4. Design the management system

Build the documentation that addresses the gaps: policies, procedures, roles, the risk methodology, the statement of applicability, and the mapping from each requirement to an internal control.


Write policies that describe how your organisation actually operates. A template adopted unedited creates a standard you will be measured against and do not meet.


5. Implement and embed

Put the controls into practice, and make sure people use them.


This step needs training, communication and follow-up. A control that exists in a document and not in anyone's routine will not survive Stage 2, because the auditor interviews the people who are supposed to be operating it.


6. Internal audit

ISO 42001 requires an internal audit of the management system every year, including before your first Stage 1 audit.


The auditor must be competent in the standard and independent of the work being examined. Your certification body cannot perform it. In most firms, the person who built the system is the only person who understands it, and they are precisely the person not permitted to audit it.


This is why internal audit is usually outsourced. It is also a recurring commitment, not a one-off.


7. Stage 1 audit

The certification body reviews your scope, governance framework, policies and risk approach to confirm the management system is documented and ready.


It usually takes several days and focuses on documents and discussions. You receive feedback on areas of concern and have the opportunity to address them before Stage 2.


Going into Stage 1 unprepared wastes an audit and delays the certificate.


8. Stage 2 audit

Stage 2 tests whether the system operates in practice. The auditor examines evidence, interviews the people who run the controls, and checks that what is documented matches what happens.


It is longer and more detailed than Stage 1. Findings are presented as nonconformities or opportunities for improvement, with next steps toward certification.


9. Certification and surveillance

The certificate is issued and runs for three years.


A surveillance audit is carried out each year to confirm the system still operates. These are shorter than the certification audit and focus on changes, risk management and evidence of improvement. Full recertification follows at the end of the cycle.


If you already hold ISO 27001

You are a considerable way along, and the two should be run as one programme rather than in sequence.


ISO 27001

ISO/IEC 42001

Subject

Information security

Management of AI

Structure

Management system with Annex A controls

Same structure, different controls

Certification

Accredited body, two stages

Accredited body, two stages

Cycle

Three years, annual surveillance

Three years, annual surveillance

Internal audit

Required annually

Required annually

Carries over

Governance, risk method, document control, competence, internal audit, management review

Does not need rebuilding

Genuinely new


AI inventory, classification, impact assessment, data governance for AI, human oversight, third-party AI


A firm holding ISO 27001 is adding a layer. A firm holding neither is better off building the management system once and certifying against both.


Cost and timing

Both depend on scope. Any figure quoted without knowing your scope is guesswork, but the shape of the cost is consistent.


Certification body fees, paid directly to them, covering Stage 1, Stage 2 and each annual surveillance audit.


Implementation, whether done internally or with support. This is usually the larger figure.


Internal time, which is the component firms consistently underestimate. Someone senior gives this months of attention, and that attention comes from somewhere else.


The variables that move the total are the number of AI systems in scope, whether they are built or bought, whether you already hold a management system certification, and how firm the deadline is.


Practical considerations

1. Certification body availability. Only a limited number of bodies are accredited for this standard. For some firms, availability rather than readiness has set the timeline.


2. The practitioner shortage. The standard is young and the pool of people who genuinely know it is small. Much of the early expertise has been absorbed by large advisory practices and by the certification bodies themselves. This is the main reason implementations in 2026 are running longer than equivalent ISO 27001 projects did at the same stage.


3. Your certification body cannot advise you. It has to remain independent of the system it certifies. Firms expecting guidance from their auditor discover this late.


4. ISO 42005. Published in 2025, it sets out methodology for AI impact assessments. ISO 42001 requires you to conduct them; 42005 explains how. Most organisations use them as a pair.


5. Supply chain pressure is the real driver. Large supplier programmes have begun adding AI governance requirements, and those cascade down. Financial services buyers are incorporating ISO 42001 into vendor questionnaires.


How we help

Buckingham Capital Consulting advises firms on AI governance and compliance. We have supported firms on compliance, governance and regulator engagement since 2013. We advise boards and senior management on AI governance: how AI is used across the business, who is accountable for it, and whether the firm could demonstrate that to a client, an auditor or a regulator.


Our work covers gap analysis, implementation, internal audit, certification support, buyer and counterparty security reviews, and continuous assurance, across ISO/IEC 42001, SOC 2, ISO 27001, the EU AI Act, the NIST AI Risk Management Framework and data protection as it applies to AI.


Hael advises firms on AI governance and compliance, built on fifteen years of regulatory practice. Hael supports firms through ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001, from first assessment to certificate, and ensures ongoing compliance. Services span readiness, implementation, internal audit, certification support, client security reviews and continuous assurance.

 
 
bottom of page