Cybersecurity Blog

How to Get ISO 42001 Certified: Step-by-Step Roadmap

Written by BEMO | Aug 26, 2026

Quick Answer: ISO 42001 certification runs through eight working stages and a two-stage external audit. Plan for several months end to end, not weeks. That estimate comes from the audit structure ISO/IEC 42006:2025 sets for certification bodies. It also draws on comparable ISO 27001 timelines. It is not a published ISO figure.

A customer sends the renewal security review. This year it has an AI section.

They want to know which models touch their data. Who signs off on changes. Whether anyone independent has checked. Your options are a written explanation or a certificate. One of those gets scored higher.

ISO 42001 certification is the certificate. Getting it is not a documentation exercise. It is building an AI management system and running it long enough to produce evidence. Then an accredited body tests it.

Key Takeaways

  • Scope is the biggest lever. Get it wrong and every later stage costs more.
  • The external audit has two stages: a documentation review, then an implementation review.
  • You do not implement all 38 Annex A controls. You select from them and justify what you exclude.
  • Existing ISO 27001 certification shortens the path, which is helpful when choosing between ISO certifications, because the management system clauses carry across.
  • Certification is not the finish line. Surveillance audits continue annually.
  • BEMO runs the certification end to end, from AI scoping through Stage 2 and surveillance.

Before You Start: Define Your AI System Scope

Scope creep is what makes ISO 42001 implementation expensive. Decide the boundary before you write a policy.

Start with a real inventory. Not the models your engineering team built. Every AI system the organization provides or uses.

That list is longer than expected. AI features arrive inside SaaS tools nobody bought as AI. Meeting transcription. Support ticket triage. Resume screening. Forecasting in the CRM. Code completion in the IDE. Each one makes or shapes a decision.

Then decide what sits inside the management system boundary. Reasonable boundaries exist. You can scope to a product line, a business unit, or customer-facing systems.

What you cannot do is exclude something quietly. Every exclusion needs a documented justification that survives an auditor's question. "We forgot" is not a justification. "This system produces no output used in a decision affecting a person" might be.

A narrow, defensible scope beats a broad one you cannot evidence. Certifying one product properly is worth more than certifying everything badly.

Three questions settle most scoping arguments. Does this system affect a person outside the company? Does a customer rely on its output? Would its failure be visible to anyone but us?

Write the scope statement early and put a version number on it. It will change, and you want the change history.

The Certification Stages

Eight stages. The first six are yours. The last two belong to the certification body.

Gap Assessment

Assess your current state against clauses 4 through 10 and the Annex A controls. Output is a gap register with an owner and a date per gap.

Effort is usually two to four weeks. Longer if the AI inventory does not exist yet. You build it during the assessment.

Management System Design and Documentation

Write the AI policy, define roles and set objectives. Build document control and corrective action processes. If you hold ISO 27001, most of this is adaptation rather than authoring.

Effort is three to six weeks from a mature starting point. Double it cold.

Risk and Impact Assessment

Two distinct exercises, and teams routinely collapse them into one.

Risk assessment covers risk to the organization. Impact assessment covers effect on individuals and society. ISO/IEC 42005:2025 gives dedicated guidance on the second.

Impact assessment needs input from product and legal, not just security. Booking that time is the actual constraint. Allow four to eight weeks.

Control Implementation

Select applicable Annex A controls from the 38 available, then build them. Record every inclusion and exclusion in the Statement of Applicability.

This is the longest stage. Lifecycle controls, data governance, transparency artifacts and supplier assessments all land here. Allow two to four months.

Internal Audit

Audit your own AIMS against the standard before anyone external does. Use someone independent of the work being audited.

This is where you find the gap between the policy and the practice. Allow two to three weeks including remediation.

Management Review

Leadership formally reviews performance, resourcing and risk. Document the decisions, not just the meeting.

Auditors check that this happened and that it changed something. A review with no output reads as theatre.

Stage 1 Audit

The certification body reviews your documentation and readiness. Scope statement, Statement of Applicability, risk and impact records, internal audit results.

Output is a findings report. Expect gaps. Stage 1 exists to surface them before Stage 2.

Stage 2 Audit

The body tests whether the system is implemented and working. Interviews, evidence sampling, control walkthroughs.

Output is the certificate, or nonconformities with a remediation window. The gap between Stage 1 and Stage 2 has a maximum permitted length. Confirm the current window with your certification body and plan inside it.

Stage

Output

Owner

Gap assessment

Gap register with owners and dates

Compliance lead

Management system design

AI policy, roles, objectives, document control

Compliance lead

Risk and impact assessment

Risk register, AI system impact assessment records

Security, product, legal

Control implementation

Operating controls, Statement of Applicability

Engineering, security

Internal audit

Internal audit report, corrective actions

Independent auditor

Management review

Documented review with decisions

Executive leadership

Stage 1 audit

Readiness findings

Certification body

Stage 2 audit

Certificate or nonconformities

Certification body

 

Timeline Expectations

There are two paths, and the difference between them is months.

The fast path applies if you already hold ISO 27001. Your risk methodology and internal audit program carry across. So do management review, document control and corrective action. The new work is the AI inventory, the impact assessment process and the AI controls. Teams in this position can move in a few months.

The slow path applies if you are starting cold. No management system. AI tools spread across teams with no inventory. No owner for model risk. Here the calendar stretches, often past six months, and the delay is rarely technical.

Three variables decide which path you are on. Whether the AI inventory exists. Whether a single person owns the program. Whether product and legal have booked time for impact assessments.

Certification body availability is a fourth variable outside your control. ISO 42001 is a young standard and the pool of accredited auditors is still growing. Book early.

Treat published four-week case studies carefully. In those cases the management system already existed and operated. The four weeks covered formalization and audit, not the build.

The security side runs the same two-stage model. Our guide to obtaining ISO 27001 certification walks it.

What Certification Costs

Costs split into four buckets, and only one of them is the audit.

Certification body fees cover Stage 1, Stage 2 and the annual surveillance audits that follow. Fees scale with audit duration, which ISO/IEC 42006:2025 governs through its audit time calculation rules. Scope size, number of AI systems, sites and complexity all move the number.

Implementation cost covers the build: gap assessment, documentation, risk and impact assessment, control work. This is usually the larger figure.

Internal effort is the cost most estimates omit. It is staff time, and it does not stop at certification.

Ongoing cost covers surveillance audits, evidence collection and reassessment after model changes.

Published ranges often come from vendors selling into the same market, so treat any single headline figure as indicative and unreliable. While we do not publish BEMO pricing here, you can see our ISO 42001 certification cost breakdown to understand the four cost buckets, or review our SOC 2 certification cost breakdown for a more predictable example of audit and internal costs.

Why Most Teams Stall Partway

The gap assessment gets done. Then nothing happens for four months.

This is the single most common failure pattern, and the causes repeat:

  • No single owner. AI governance sits across engineering, legal, product and security. Everyone contributes. Nobody is accountable. Twenty gaps get identified and none get closed, because closing them is nobody's actual job.
  • The inventory goes stale. You catalogue AI systems in March. By May two teams have adopted new tools. A vendor has shipped AI into a product you already use. The inventory is now wrong, and the auditor will find the gap.
  • Impact assessments need people who do not report to you. Product knows what the model affects. Legal knows the obligations. Neither reports to whoever owns compliance. Getting three hours of their attention takes weeks.
  • Evidence collection is continuous work nobody was staffed for. Monitoring output, model change logs, retraining records, supplier reassessments. The standard expects an operating system, not a project.
  • And the deadline is soft. Nothing legally compels ISO 42001 compliance in the United States today. When a contract deadline slips, the compliance work slips with it. Then a bigger deal arrives with a harder requirement, and now it is urgent.

The realistic staffing picture is a fraction of a role, permanently. Hiring for it competes in a tight market. BLS data puts the median wage for information security analysts at $124,910 in May 2024. Projected growth through 2034 is 29 percent. AI governance experience sits above that median, and the hiring cycle runs months.

Microsoft and Azure AI Configuration

If your AI runs on Microsoft, most of your evidence layer is available. It usually needs turning on and retaining:

  • Content filtering: Turn on and schedule evaluations in Microsoft Foundry, formerly Azure AI Foundry. Evaluation runs are the monitoring artifact auditors ask for against lifecycle controls.
  • Microsoft Purview: Apply classification, sensitivity labels, and DLP to prompt and output flows. This is how you evidence what data can reach a model.
  • Entra ID: Set conditional access on AI tooling. Use Privileged Identity Management for anyone changing model configuration or prompts.
  • Unified audit log: Retain the log for longer than your audit window. Default retention is frequently shorter than the period an auditor will sample. Set it deliberately and document the setting.
  • Defender for Cloud Apps: Use the tool to find AI services already in use across the organization. That discovery output is a better inventory starting point than a survey.
  • Microsoft 365 Copilot: Document the tenant data boundary and grounding behavior. Put it in your impact assessment. Microsoft publishes an ISO/IEC 42001 template in Purview Compliance Manager you can map against.

How BEMO Runs an ISO 42001 Certification

Consultants advise and leave. Platforms tell you what is missing. Neither closes a gap.

BEMO builds the AI management system and operates it. That starts with discovery of the AI systems actually in use. Not a questionnaire asking you to list them.

We run risk and impact assessments as a repeatable process rather than a one-time document. We perform control selection and draft a Statement of Applicability designed to survive an auditor.

We complete the configuration work by implementing Purview policies, conditional access, and log retention, with Foundry evaluations scheduled to produce evidence continuously.

We perform an internal audit and management review before the certification body arrives, which helps Stage 1 surface fewer surprises.

BEMO stays through Stage 2 and into the surveillance cycle. The AI security foundation service covers the technical layer. The compliance practice covers the management system.

Where to Start

If a customer has already asked, the clock started before you read this.

The first move is not a policy document. It is finding out what AI systems you actually run, then which of them a buyer cares about. Our requirements checklist makes a good working document for that pass.

A gap assessment produces that. A real inventory, a scoped boundary, a gap register with owners. It also tells you whether you are on the fast path or the slow one.

Book a gap assessment and get a defensible answer for the next questionnaire.

Frequently Asked Questions

Do we need ISO 27001 before ISO 42001?

No. ISO 27001 is not a prerequisite. Holding it materially shortens the path. Management system clauses, risk methodology and audit habits carry across. Starting with ISO 42001 alone is possible.

Who can certify us against ISO 42001?

An accredited certification body. ISO/IEC 42006:2025 sets the competence, impartiality and audit-time requirements those bodies must meet. Check current accreditation directly with the body and its accreditation authority before signing.

Does certification cover AI models we did not build?

Yes. The standard applies to organizations that provide or use AI systems. For bought or API-accessed models, controls center on supplier assessment and use governance. Monitoring and transparency replace model development work.

What happens at surveillance audits?

The certification body samples your operating evidence annually to confirm the AIMS still works. They look for monitoring output, updated impact assessments, closed corrective actions and inventory currency. Recertification follows on a three-year cycle.

Can we certify one product rather than the whole company?

Yes, provided the scope is defensible and documented. A single product line or business unit is a valid boundary. Exclusions need justification. The certificate states the scope, so customers see what it covers.