Quick Answer: ISO 42001 certification runs through eight working stages and a two-stage external audit. Plan for several months end to end, not weeks. That estimate comes from the audit structure ISO/IEC 42006:2025 sets for certification bodies. It also draws on comparable ISO 27001 timelines. It is not a published ISO figure.
A customer sends the renewal security review. This year it has an AI section.
They want to know which models touch their data. Who signs off on changes. Whether anyone independent has checked. Your options are a written explanation or a certificate. One of those gets scored higher.
ISO 42001 certification is the certificate. Getting it is not a documentation exercise. It is building an AI management system and running it long enough to produce evidence. Then an accredited body tests it.
Scope creep is what makes ISO 42001 implementation expensive. Decide the boundary before you write a policy.
Start with a real inventory. Not the models your engineering team built. Every AI system the organization provides or uses.
That list is longer than expected. AI features arrive inside SaaS tools nobody bought as AI. Meeting transcription. Support ticket triage. Resume screening. Forecasting in the CRM. Code completion in the IDE. Each one makes or shapes a decision.
Then decide what sits inside the management system boundary. Reasonable boundaries exist. You can scope to a product line, a business unit, or customer-facing systems.
What you cannot do is exclude something quietly. Every exclusion needs a documented justification that survives an auditor's question. "We forgot" is not a justification. "This system produces no output used in a decision affecting a person" might be.
A narrow, defensible scope beats a broad one you cannot evidence. Certifying one product properly is worth more than certifying everything badly.
Three questions settle most scoping arguments. Does this system affect a person outside the company? Does a customer rely on its output? Would its failure be visible to anyone but us?
Write the scope statement early and put a version number on it. It will change, and you want the change history.
Eight stages. The first six are yours. The last two belong to the certification body.
Assess your current state against clauses 4 through 10 and the Annex A controls. Output is a gap register with an owner and a date per gap.
Effort is usually two to four weeks. Longer if the AI inventory does not exist yet. You build it during the assessment.
Write the AI policy, define roles and set objectives. Build document control and corrective action processes. If you hold ISO 27001, most of this is adaptation rather than authoring.
Effort is three to six weeks from a mature starting point. Double it cold.
Two distinct exercises, and teams routinely collapse them into one.
Risk assessment covers risk to the organization. Impact assessment covers effect on individuals and society. ISO/IEC 42005:2025 gives dedicated guidance on the second.
Impact assessment needs input from product and legal, not just security. Booking that time is the actual constraint. Allow four to eight weeks.
Select applicable Annex A controls from the 38 available, then build them. Record every inclusion and exclusion in the Statement of Applicability.
This is the longest stage. Lifecycle controls, data governance, transparency artifacts and supplier assessments all land here. Allow two to four months.
Audit your own AIMS against the standard before anyone external does. Use someone independent of the work being audited.
This is where you find the gap between the policy and the practice. Allow two to three weeks including remediation.
Leadership formally reviews performance, resourcing and risk. Document the decisions, not just the meeting.
Auditors check that this happened and that it changed something. A review with no output reads as theatre.
The certification body reviews your documentation and readiness. Scope statement, Statement of Applicability, risk and impact records, internal audit results.
Output is a findings report. Expect gaps. Stage 1 exists to surface them before Stage 2.
The body tests whether the system is implemented and working. Interviews, evidence sampling, control walkthroughs.
Output is the certificate, or nonconformities with a remediation window. The gap between Stage 1 and Stage 2 has a maximum permitted length. Confirm the current window with your certification body and plan inside it.
|
Stage |
Output |
Owner |
|---|---|---|
|
Gap assessment |
Gap register with owners and dates |
Compliance lead |
|
Management system design |
AI policy, roles, objectives, document control |
Compliance lead |
|
Risk and impact assessment |
Risk register, AI system impact assessment records |
Security, product, legal |
|
Control implementation |
Operating controls, Statement of Applicability |
Engineering, security |
|
Internal audit |
Internal audit report, corrective actions |
Independent auditor |
|
Management review |
Documented review with decisions |
Executive leadership |
|
Stage 1 audit |
Readiness findings |
Certification body |
|
Stage 2 audit |
Certificate or nonconformities |
Certification body |
There are two paths, and the difference between them is months.
The fast path applies if you already hold ISO 27001. Your risk methodology and internal audit program carry across. So do management review, document control and corrective action. The new work is the AI inventory, the impact assessment process and the AI controls. Teams in this position can move in a few months.
The slow path applies if you are starting cold. No management system. AI tools spread across teams with no inventory. No owner for model risk. Here the calendar stretches, often past six months, and the delay is rarely technical.
Three variables decide which path you are on. Whether the AI inventory exists. Whether a single person owns the program. Whether product and legal have booked time for impact assessments.
Certification body availability is a fourth variable outside your control. ISO 42001 is a young standard and the pool of accredited auditors is still growing. Book early.
Treat published four-week case studies carefully. In those cases the management system already existed and operated. The four weeks covered formalization and audit, not the build.
The security side runs the same two-stage model. Our guide to obtaining ISO 27001 certification walks it.
Costs split into four buckets, and only one of them is the audit.
Certification body fees cover Stage 1, Stage 2 and the annual surveillance audits that follow. Fees scale with audit duration, which ISO/IEC 42006:2025 governs through its audit time calculation rules. Scope size, number of AI systems, sites and complexity all move the number.
Implementation cost covers the build: gap assessment, documentation, risk and impact assessment, control work. This is usually the larger figure.
Internal effort is the cost most estimates omit. It is staff time, and it does not stop at certification.
Ongoing cost covers surveillance audits, evidence collection and reassessment after model changes.
Published ranges often come from vendors selling into the same market, so treat any single headline figure as indicative and unreliable. While we do not publish BEMO pricing here, you can see our ISO 42001 certification cost breakdown to understand the four cost buckets, or review our SOC 2 certification cost breakdown for a more predictable example of audit and internal costs.
The gap assessment gets done. Then nothing happens for four months.
This is the single most common failure pattern, and the causes repeat:
The realistic staffing picture is a fraction of a role, permanently. Hiring for it competes in a tight market. BLS data puts the median wage for information security analysts at $124,910 in May 2024. Projected growth through 2034 is 29 percent. AI governance experience sits above that median, and the hiring cycle runs months.
If your AI runs on Microsoft, most of your evidence layer is available. It usually needs turning on and retaining:
Consultants advise and leave. Platforms tell you what is missing. Neither closes a gap.
BEMO builds the AI management system and operates it. That starts with discovery of the AI systems actually in use. Not a questionnaire asking you to list them.
We run risk and impact assessments as a repeatable process rather than a one-time document. We perform control selection and draft a Statement of Applicability designed to survive an auditor.
We complete the configuration work by implementing Purview policies, conditional access, and log retention, with Foundry evaluations scheduled to produce evidence continuously.
We perform an internal audit and management review before the certification body arrives, which helps Stage 1 surface fewer surprises.
BEMO stays through Stage 2 and into the surveillance cycle. The AI security foundation service covers the technical layer. The compliance practice covers the management system.
If a customer has already asked, the clock started before you read this.
The first move is not a policy document. It is finding out what AI systems you actually run, then which of them a buyer cares about. Our requirements checklist makes a good working document for that pass.
A gap assessment produces that. A real inventory, a scoped boundary, a gap register with owners. It also tells you whether you are on the fast path or the slow one.
Book a gap assessment and get a defensible answer for the next questionnaire.
No. ISO 27001 is not a prerequisite. Holding it materially shortens the path. Management system clauses, risk methodology and audit habits carry across. Starting with ISO 42001 alone is possible.
An accredited certification body. ISO/IEC 42006:2025 sets the competence, impartiality and audit-time requirements those bodies must meet. Check current accreditation directly with the body and its accreditation authority before signing.
Yes. The standard applies to organizations that provide or use AI systems. For bought or API-accessed models, controls center on supplier assessment and use governance. Monitoring and transparency replace model development work.
The certification body samples your operating evidence annually to confirm the AIMS still works. They look for monitoring output, updated impact assessments, closed corrective actions and inventory currency. Recertification follows on a three-year cycle.
Yes, provided the scope is defensible and documented. A single product line or business unit is a valid boundary. Exclusions need justification. The certificate states the scope, so customers see what it covers.