AI Compliance —

ISO 42001 Certification: Requirements, Cost & Timeline

ISO 42001 certification requirements, the 38 Annex A controls, a realistic cost and timeline breakdown, and how it compares to ISO 27001.

Jon Ozdoruk

iso-42001

Share this article

ISO 42001 certification requirements, cost, and timeline overview graphic

Contents

No headings found on page

If you build, deploy, or sell AI systems to enterprise buyers, you've probably run into this sentence somewhere in a vendor security questionnaire: "Are you ISO/IEC 42001 certified?" Two years ago, almost nobody asked that. In 2026, it's becoming a standard line item, and for good reason: ISO 42001 is the first international certification built specifically for how organizations govern AI, not just how they secure data.

This guide covers what the certification actually requires, what it costs, how long it realistically takes, and how it compares to ISO 27001, using verified figures from certification bodies and implementation guides published in 2026, not the vague "get certified fast" claims that dominate a lot of the content on this topic.

What ISO 42001 Actually Certifies

ISO/IEC 42001:2023 is the world's first certifiable standard for an AI Management System (AIMS), the same structural idea as an Information Security Management System (ISMS) under ISO 27001, but built around AI-specific risks: fairness, transparency, human oversight, and the AI system lifecycle, instead of confidentiality, integrity, and availability of data.

It doesn't certify a specific model or product. It certifies your organization's management system, the policies, roles, risk assessments, and ongoing processes you use to govern AI responsibly. That distinction matters: a company can be ISO 42001 certified while still shipping flawed AI features, because the standard is about governance discipline, not a guarantee of model performance.

For a broader overview of what the standard covers and why it exists, see our ISO 42001 AI Management System guide. This article focuses specifically on what certification actually requires, costs, and takes.

Why It's Gaining Ground Fast in 2026

Three things are driving adoption right now:

  • Enterprise procurement is starting to require it. Fortune 500 buyers increasingly ask AI vendors to either hold ISO 42001 or show a documented roadmap toward it, the same pattern that made SOC 2 a baseline requirement for SaaS a decade ago.

  • Public certifications are accelerating. More than 350 organizations globally held ISO 42001 certificates as of mid-2026, with the number climbing sharply as accredited certification bodies scale up audit capacity.

  • It's becoming the practical answer to "prove your AI governance." Where the EU AI Act sets legal requirements and NIST AI RMF offers voluntary guidance, ISO 42001 is the one or three that produces an actual third-party certificate you can put in front of a customer or auditor.

ISO 42001 Requirements: Clauses 4-10 and the 38 Annex A Controls

ISO 42001 has two layers of requirements, and mixing them up is the most common misunderstanding about the standard.

Clauses 4 through 10 are mandatory. These define the management system itself: context of the organization, leadership commitment, planning, support (resources, competence, awareness), operation, performance evaluation, and continual improvement. Every certified organization must meet all of these.

Annex A's 38 controls are a reference set, not a checklist. They're organized into nine control objectives (A.2 through A.10):


Objective

Focus

A.2

Policies related to AI

A.3

Internal organization

A.4

Resources for AI systems

A.5

Assessing impacts of AI systems

A.6

AI system life cycle

A.7

Data for AI systems

A.8

Information for interested parties

A.9

Use of AI systems

A.10

Third-party and customer relationships

You don't implement all 38 by default. You run a risk assessment, select the controls that address your actual risks, and document your reasoning, including what you excluded and why, in a Statement of Applicability (SoA). Auditors will ask you to justify every exclusion, so "we skipped it" isn't a valid answer without a documented rationale tied to your risk assessment.

For comparison, ISO 27001's Annex A has 93 controls across four themes focused on information security. ISO 42001's smaller, more targeted set reflects its narrower purpose: governing how AI systems are built, deployed, and monitored, not general information security.

The Certification Process, Step by Step

Certification follows five phases, and the audit itself is only the last one:


Phase

Typical Duration

What Happens

Preparation & gap analysis

2 weeks - 3 months

Define AIMS scope, secure stakeholder buy-in, identify gaps against Annex A

AIMS design & documentation

1-3 months

Build AI policies, risk assessment framework, data governance procedures

Implementation & training

1-4 months

Operate the AIMS in practice, train staff, start logging evidence

Internal audit

About 1 month

Independent internal review of controls and evidence before the real audit

External audit (Stage 1 & Stage 2)

1-2 months

Stage 1 reviews documentation; Stage 2 assesses whether the AIMS actually operates as documented

The Stage 1 and Stage 2 audits are conducted by an accredited certification body (Schellman, BSI, DNV, and A-LIGN are among the most commonly used). Once certified, the certificate is valid for three years, with annual surveillance audits required to keep it active.

How Much Does ISO 42001 Certification Cost?

Cost estimates vary more than almost any other part of this process, largely because "cost" gets defined differently across sources (certification body fees alone vs. total cost including consulting and internal time). Here's the honest range, pulled from multiple 2026 sources rather than a single vendor's estimate:


Cost component

Typical range

Certification body audit fees (small org)

$5,000-$20,000

Combined Stage 1 + Stage 2 audit (larger org)

$20,000-$50,000

Consulting/implementation support

$10,000-$50,000

All-in first-year cost (50-200 person company)

$85,000-$150,000

Minimum realistic cost, small org with existing governance

~$10,000-$20,000

The single biggest cost lever is whether you already have ISO 27001. Organizations extending an existing ISMS into an AIMS commonly report cutting both cost and timeline by roughly 40-60%, since the risk assessment methodology, internal audit program, and documentation structure largely transfer over.

How Long Does ISO 42001 Certification Take?

Most sources converge on the same range: 4 to 12 months from kickoff to certificate.

  • 3-4 months is realistic for a small organization with a narrow AIMS scope and an existing ISO 27001 program to build on.

  • 4-9 months is typical for a mid-size company building AI governance largely from scratch.

  • 12 months or more is common for larger enterprises with a broad AI system inventory and less mature existing governance.

Two variables matter more than company size: how much of your AI management system already exists, and how quickly you can define your AI system inventory and scope. Auditor availability is also a real, underrated bottleneck in 2026, some accredited certification bodies now have lead times of several months, so it's worth confirming auditor availability before locking in a target certification date.

ISO 42001 vs. ISO 27001: What's Actually Different



ISO 27001

ISO 42001

What it governs

Information security (confidentiality, integrity, availability)

AI system governance (fairness, transparency, human oversight, lifecycle risk)

Annex A controls

93 controls, 4 themes

38 controls, 9 objectives

Core question it answers

Is your data secure?

Is your AI system responsibly governed?

Certificate validity

3 years

3 years

Can one help the other?

Existing ISMS structure, risk methodology, and audit cadence transfer directly into an AIMS

Reuses ISO 27001's management-system foundation rather than duplicating it

They're complementary, not competing. If you already hold ISO 27001, ISO 42001 is an extension of infrastructure you've already built, not a separate project from zero.

Who Actually Needs ISO 42001

This isn't only for companies building foundation models. It's increasingly relevant for:

  • AI product and SaaS companies whose enterprise customers require proof of responsible AI governance during vendor security review

  • Any company using AI in regulated decision-making (hiring, lending, healthcare triage), where the impact-assessment requirements in Annex A directly address regulatory expectations

  • Companies selling into the EU or into Fortune 500 procurement, where ISO 42001 is increasingly requested as evidence alongside, or instead of, a lengthy custom AI governance questionnaire

How DSALTA Helps You Get Audit-Ready

DSALTA doesn't issue ISO 42001 certificates, that's the accredited certification body's role. What DSALTA does is close the gap between "we have a policy document" and "we can produce evidence an auditor will accept." That means automating the parts of this process that eat the most time: mapping your existing ISO 27001 controls to Annex A's AI-specific requirements, building and maintaining your Statement of Applicability, and keeping your evidence current so you're not scrambling to reconstruct nine months of documentation the week before your Stage 1 audit.

Frequently Asked Questions

Is ISO 42001 legally required? No. It's a voluntary certification. It's becoming a de facto requirement in enterprise procurement and public-sector tenders, but no law currently mandates it the way the EU AI Act mandates certain compliance obligations.

Can a company be ISO 42001 certified in a few weeks? Only if the AI management system was already built and operating before the clock started. Case studies advertising a "four-week certification" are almost always formalizing and auditing a system that already existed, not building governance from scratch. Budget 4-12 months for a realistic, ground-up timeline.

Do I need ISO 27001 before I can get ISO 42001? No, they're independent certifications. But if you already hold ISO 27001, expect a meaningfully faster and cheaper path to ISO 42001, since the management-system foundation (risk methodology, internal audit program, documentation structure) carries over.

How often do I need to renew ISO 42001 certification? The certificate is valid for three years, with an annual surveillance audit required each year to keep it active, and a full recertification audit at the three-year mark.

What happens if I fail to maintain evidence between audits? A certification body can withdraw an active certificate if a surveillance audit finds a major nonconformity, meaning your AIMS stopped operating the way it did at certification. Continuous evidence collection, not a pre-audit scramble, is what keeps a certificate valid.

Explore more AI Compliance articles

Stop losing deals to compliance.

Get compliant. Keep building.

Join 100s of startups who got audit-ready in days, not months.