What ISO 42001 certification actually certifies
ISO/IEC 42001:2023 certifies an AI Management System (AIMS) — the governance, risk and lifecycle processes your organisation uses to develop, provide or use AI systems. It does not certify a model, an algorithm or an accuracy figure. Auditors assess whether you can demonstrate, with evidence, that AI risks and impacts are identified, treated, monitored and improved over time.
That distinction matters commercially. When an enterprise customer asks "is your AI governed?", ISO 42001 is the only accredited, internationally recognised answer available today.
Who needs it
| Organisation type | Typical driver |
|---|---|
| SaaS products embedding LLMs or ML features | Enterprise security reviews, procurement questionnaires |
| AI-first startups | Fundraising diligence, differentiation in tenders |
| Healthcare, BFSI, insurance | Sector regulators, model risk management expectations |
| Enterprises deploying third-party AI | Internal AI policy, board and audit-committee assurance |
| GCCs and IT services firms | Client contractual requirements, RFP scoring |
Clause requirements at a glance
ISO 42001 follows the Annex SL high-level structure, so if you hold ISO 27001 the shape will feel familiar.
- Clause 4 — Context: define the AI systems in scope, your role (developer, provider, deployer, user), interested parties and AIMS boundaries.
- Clause 5 — Leadership: AI policy, accountability for AI outcomes, defined roles for AI risk owners.
- Clause 6 — Planning: AI risk assessment, AI system impact assessment (the clause that has no ISO 27001 equivalent), objectives and treatment plans.
- Clause 7 — Support: competence for data science and review roles, documented information, awareness.
- Clause 8 — Operation: lifecycle controls — data management, design, verification and validation, deployment, monitoring, third-party and supplier AI.
- Clause 9 — Performance evaluation: monitoring, internal audit, management review.
- Clause 10 — Improvement: nonconformity handling, corrective action, continual improvement.
Annex A controls you will be asked to evidence
Annex A contains 38 controls across nine objectives. The ones that most often cause findings:
- AI policy and governance structure — a policy that names accountable owners, not a generic statement.
- AI system impact assessment — documented assessment of impact on individuals, groups and society, refreshed when the system changes materially.
- Data for AI — provenance, quality, labelling, bias evaluation and retention of training and evaluation datasets.
- Lifecycle documentation — objectives, design choices, known limitations and intended use recorded per system.
- Verification and validation — evidence of pre-release testing, including robustness, fairness and, for generative systems, safety and prompt-injection testing.
- Human oversight — where humans can review, override or escalate, and proof it happens.
- Transparency to users — disclosure that AI is used, its limitations and how to contest an outcome.
- Monitoring in production — drift, incident and complaint monitoring with defined thresholds.
- Third-party AI — due diligence on model and API providers, and allocation of responsibilities in contracts.
The certification process, step by step
- Scope definition (1-2 weeks) — list every AI system and your role for each. Over-broad scope is the single biggest cost driver.
- Gap assessment (2-3 weeks) — clause and Annex A gap analysis with a prioritised remediation plan.
- Risk and impact assessment (2-4 weeks) — AI risk register plus impact assessments for in-scope systems.
- Documentation and control build (6-10 weeks) — AI policy, lifecycle procedures, data governance, model cards, oversight and incident processes.
- Implementation and evidence generation (4-8 weeks) — controls must run long enough to produce records auditors can sample.
- Internal audit and management review (2 weeks) — mandatory before Stage 2; findings must be closed or in treatment.
- Stage 1 audit — documentation and readiness review by the certification body.
- Stage 2 audit — effectiveness audit against clauses and applicable Annex A controls.
- Certification decision and surveillance — three-year cycle with annual surveillance audits and recertification in year three.
Realistic timelines
| Organisation profile | First certification |
|---|---|
| Startup, one or two AI features, ISO 27001 already in place | 3-4 months |
| Mid-size SaaS, several AI systems, no prior ISMS | 5-7 months |
| Enterprise, multiple business units and third-party models | 8-12 months |
Evidence maturity, not document writing, sets the floor. Most Stage 2 delays come from controls that were documented but had not operated long enough to be sampled.
What drives cost
Certification spend splits into three buckets:
- Certification body fees — driven by audit days, which follow headcount, number of sites and number of AI systems in scope.
- Implementation effort — internal time plus consulting support for risk and impact assessments, documentation and validation evidence.
- Tooling — model registries, evaluation and monitoring tooling, GRC platform if you do not already have one.
Cost control levers that actually work: start with a narrow, defensible scope; reuse ISO 27001 processes for audit, management review, supplier management, incident response and training; and integrate AIMS records into the systems your engineers already use rather than building a parallel paper trail.
Integration with ISO 27001 and other frameworks
| You already have | Reuse for ISO 42001 | Still need |
|---|---|---|
| ISO 27001 | Clauses 4-10 machinery, risk methodology, internal audit, supplier controls | AI impact assessment, lifecycle and data-for-AI controls, human oversight |
| ISO 27701 | Privacy controls, DPIA process, data subject rights | AI-specific bias, robustness and transparency evidence |
| SOC 2 | Change management, access control, monitoring evidence | The entire AI governance layer — SOC 2 has no AI criteria |
For the EU AI Act, ISO 42001 is not a conformity presumption on its own, but the AIMS, risk management, data governance, logging, human oversight and post-market monitoring requirements map closely onto Articles 9-17 obligations for high-risk systems. Organisations that certify first typically find AI Act readiness a delta, not a restart.
Findings we see most often
- Impact assessments written once and never updated after model or use-case changes.
- No record of pre-release evaluation for generative features shipped "behind a flag".
- Human oversight claimed in policy with no reviewer logs to prove it.
- Third-party model providers accepted with no due diligence or contractual allocation of AI responsibilities.
- Training data provenance unknown for models inherited from an acquisition or open-source base.
Key takeaways
- ISO 42001 certifies your AI management system, not individual models.
- AI risk and impact assessment are the requirements with no ISO 27001 equivalent — start there.
- Narrow scope and reuse of existing ISMS processes are the two biggest cost and timeline levers.
- Plan for evidence to accumulate before Stage 2; documentation alone does not pass.
- Certification materially shortens the path to EU AI Act readiness and to clearing enterprise AI security reviews.
Planning ISO 42001 certification? ICyberWave provides gap assessment, AI risk and impact assessment, AIMS documentation and certification audit support, integrated with ISO 27001 and ISO 27701 where you already hold them.
