ISO 42001 Certification: How It Works and What It Does Not Prove
Most organisations approach ISO 42001 certification the same way: they ask what it costs and how long it takes. Those are the wrong first questions. The first question is what the certificate will be used for — because that determines which certification body you can use, and choosing the wrong one produces a document that your customers’ procurement teams will reject.
This article covers how certification works, the accreditation check that most buyers skip, and the three claims the certificate does not support.
What certification actually is
ISO does not certify anyone. It writes standards. Certification is issued by an independent certification body — a commercial organisation that audits you against the standard and issues a certificate if you pass.
Two standards govern the certification body itself. ISO/IEC 17021-1 is the general standard for bodies that audit and certify management systems of any kind. ISO/IEC 42006:2025 sits on top of it, setting the additional requirements that apply specifically to certifying AI management systems. It was published in July 2025 by the same technical committee that wrote ISO 42001.
The distinction matters because a body can be experienced at certifying information security and still lack the AI-specific competence that ISO/IEC 42006 now requires.
Above the certification body sits an accreditation body, which assesses whether the certifier is competent and impartial. The recognised ones for ISO 42001 include ANAB, UKAS and RvA.

Figure 1 — The three layers: accreditation body, certification body, and the organisation being certified.
The check most buyers skip
Here is the failure that costs money. An organisation engages a certification body, completes the audit, receives a certificate, and then discovers the certificate carries no accreditation mark for ISO 42001.
You must check that ISO 42001 sits within the body’s accreditation scope, not just that the body is accredited for something. A body accredited only for ISO 9001 or ISO 27001 cannot give you a recognised ISO 42001 certificate.
The check takes ten minutes. Go to the accreditation body’s public directory — not the certifier’s own website — search for the certification body, and confirm ISO 42001 appears in the listed scope. If it does not, the certificate you receive will be an unaccredited one. Unaccredited certificates are not worthless, but they are not what an enterprise procurement questionnaire is asking for.
As of 2026, ISO 42001 accreditation is still maturing, with new certification bodies being approved on a rolling basis — so a body that could not offer accredited certification last year may be able to now, and it is worth asking directly rather than assuming.
Which accreditation you need depends on who your buyers are. For US enterprise buyers, ANAB-accredited bodies are most commonly accepted; for UK and EU buyers, UKAS and RvA accreditation carry weight, and some EU procurement processes specify particular national accreditation.
The two-stage audit
Certification follows the same two-stage model used across ISO management system standards.
Stage 1 is a readiness review. The auditor examines your documented information, confirms the scope makes sense, checks that the required processes exist, and identifies whether you are ready for stage 2. It is usually shorter and can often be done remotely. The output is a report listing what must be resolved before stage 2 — and it is entirely normal for stage 1 to conclude that you are not ready yet.
Stage 2 is the substantive audit. The auditor tests whether the management system is actually implemented and effective, by sampling records: risk assessments, impact assessments, life cycle records, audit reports, management review minutes. This is where documentation that was written but never used becomes visible.
A successful stage 2 results in a certificate valid for three years, with annual surveillance audits in between. Surveillance audits sample part of the system rather than all of it; at the end of the three years a recertification audit covers the whole system again.

Figure 2 — The certification cycle from stage 1 through recertification.
What you need in place before stage 1
The requirement that surprises people is not documentary. It is temporal: the system has to have been running long enough to have produced records.
At minimum, before stage 2 you need:
- A completed internal audit covering the management system. Not a plan for one — a completed one, with findings.
- A management review held by top management, with decisions recorded.
- Risk assessments and impact assessments performed for the AI systems in scope, with outcomes that fed into something.
- A Statement of Applicability covering all 38 Annex A controls, with justification for every inclusion and exclusion.
- Evidence that the processes ran: records produced by the procedures, dated across a period rather than all in the week before the audit.
That last point sets the earliest realistic certification date. A management system that was documented last month cannot show three months of operation, and no amount of documentation quality substitutes for it.
What the certificate does not prove
It also does not say anything about your information security management system, which is a separate standard with a separate certificate — the actual mapping between the two sets out what transfers and what does not.
It also does not demonstrate compliance with the EU AI Act, which is law rather than a voluntary standard and applies whether or not you certify — see what AI Act compliance involves.
Three claims the certificate does not support, all of which get made anyway.
It does not demonstrate EU AI Act conformity. ISO 42001 is a management system standard; the AI Act is law. Certifying to one does not discharge obligations under the other, and the Act does not require ISO 42001. The overlap is real — the standard builds much of the organisational machinery the Act’s obligations rely on — but conformity with the Act is assessed against the Act.
It does not certify any specific AI system. It demonstrates governance maturity. It does not certify any specific model’s safety, accuracy, or fairness. An organisation with a certified management system can still deploy a model that performs badly. What the certificate says is that there is a process for noticing.
It does not cover systems outside the scope. The scope statement on the certificate is the boundary. A certificate scoped to one product line says nothing about the AI tools the rest of the business uses — which is why a scope written narrower than the reality of the business is a false economy.
How long it takes, honestly
For a small organisation with a handful of AI systems and someone able to give the work a day a week, ninety days is enough to build the management system. Add to that:
- The operating period needed to generate records — three months is a reasonable minimum.
- Scheduling with the certification body, which for accredited ISO 42001 audits can involve a wait, since capacity is still growing.
- Stage 1, remediation of whatever it finds, then stage 2.
Six to nine months from a standing start to certificate is a realistic planning assumption. Organisations that already hold ISO 27001 move faster, because document control, internal audit, management review and corrective action all transfer — what they have to build is the impact assessment, the second consequence dimension in risk, and the AI-specific controls.
Where to start
If you are still deciding what the whole thing consists of, the AI governance framework lists the documents, processes and records rather than the pillars.
If you make medical devices, the picture is different again: most of the management system already exists in your ISO 13485 QMS. What ISO 42001 adds to ISO 13485 works through what transfers and what does not.
If you want to know where you stand before contacting anyone, work through the ISO 42001 readiness checklist first.
Before contacting a certification body, do three things.
List every AI system the organisation actually uses. Most organisations underestimate this by half, and the scope depends on it.
Decide what the certificate is for. Enterprise procurement, a specific customer requirement, and general market positioning point at different accreditation choices.
Build the system and run it long enough to have records. The audit tests operation, not intention.
Our ISO 42001 kit contains the documents an AI management system needs — sixteen procedures, ten forms, nine registers including a Statement of Applicability pre-populated with all 38 controls, and an implementation guide with the ninety-day sequence. €590 excl. VAT.