Get Your ISO/IEC 42001 Quote
Certified governance for the AI you build and deploy so procurement stops stalling
ISO/IEC 42001 certifies that an organisation manages its AI systems deliberately: an inventory of what is deployed, an assessment of who the outputs affect, controls over training data and model change, and named humans accountable for oversight. It is what enterprise buyers, regulators and boards now ask for when AI sits inside a product or a decision.
You need ISO/IEC 42001 ifβ¦
- !A customerβs procurement team has sent an AI governance questionnaire and your answers are currently verbal.
- !You are shipping a product with a model inside it into the European market.
- !The board has asked who signed off the model now making credit, pricing or eligibility decisions.
- !An internal team adopted a third-party model and nobody can say what data it sees.
- !A regulator or ombudsman questioned an automated decision and you have no impact assessment on file.
- !You already hold ISO/IEC 27001 and the same buyers are now asking about AI specifically.
A management system standard for organisations that develop, supply or use artificial intelligence. It asks you to know which AI systems you run, judge the harm they could cause, control the data and models behind them, and keep people answerable for the outputs.
ISO/IEC 42001 is certified by an accredited certification body such as SIS after a two-stage audit. It is not a self-declaration and not a product approval.
The certificate runs three years, with a surveillance audit each year and a full recertification audit before it expires.
Software vendors, banks, insurers, health and public bodies, and manufacturers embedding models in products or in release and pricing decisions.
Where this certification is demanded
ISO/IEC 42001 is applicable across 8 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO/IEC 42001 Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
Decide whether you develop, supply or use each AI system, list them all, and set the boundary of the management system accordingly.
Top management signs an AI policy, allocates budget and names who owns each model, including who has authority to stop it running.
Assess risk to the organisation and, separately, the impact on individuals and society, then record which Annex A controls apply and why.
Document the provenance, quality and labelling of training and input data, and show the people reviewing model outputs are competent to do it.
Set design objectives, validate before release, control model and prompt changes, keep human oversight, and hold suppliers of models to the same terms.
Track performance and drift in live use, log AI incidents and complaints, audit internally, and take the findings to management review.
How ISO/IEC 42001 Certification Works
No black box. A defined, time-bound route from first call to certificate in hand.
Application & Proposal
We scope by counting AI systems, not headcount alone: which models you build versus buy, whether decisions are automated or advisory, and how many sites and development teams are involved.
1β2 daysGap Review & Readiness
A model gets retrained on Friday to fix a complaint, and by Monday it is scoring applications differently. Nobody wrote that down. That absence is what stalls a Stage 2.
1β2 weeksStage 1 + Stage 2 Audit
Stage 1 checks scope, AI policy, Statement of Applicability and the impact assessment method. Stage 2 traces a live system end to end, from data source to human override.
Scheduled around operationsCertificate Issued
The certificate names your AI scope. Surveillance is where it bites: the auditor returns to a different inventory and asks what governance ran on the systems added since.
Valid 3 yearsIndustries That Need ISO/IEC 42001
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
How many of your models have a named owner?
Two numbers matter. How many models are in production, and how many have an impact assessment written before deployment? An ISO/IEC 42001 audit starts with the gap between them.
Get My Free Quote βWhat ISO/IEC 42001 Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
Answers the AI questionnaire
Procurement questionnaires stop being a scramble. The inventory, impact assessments and oversight records already exist, so responses take days rather than weeks.
Shadow AI comes into view
Building the inventory surfaces the models teams adopted without review, and the data those models have been reading. The list is usually longer than the one IT keeps.
Groundwork for AI regulation
Risk classification, technical documentation, logging and human oversight are what emerging AI law asks for, so the same evidence serves both purposes.
Model changes stop surprising you
Version control, retraining triggers and release approval mean a model does not quietly change behaviour between a demonstration and a production decision.
Something to show the board
Directors asking who is accountable for AI get a named owner, a risk register and an audit report from an independent body.
Accepted without a second audit
An accredited certificate carries through the IAF arrangement, so a buyer in another country accepts it without commissioning an audit of its own.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
ISO/IEC 42001 implementation guide for AI teams
Clause-by-clause walkthrough with the Annex A controls explained in plain terms, and worked examples for a developer and a deployer.
AI system inventory and impact assessment
A working register covering purpose, role, data sources, affected groups, oversight owner and review date, ready to populate.
Pre-audit readiness check for AIMS
Fifty questions an auditor is likely to ask, arranged by clause, with the record each one expects to see.
Where 42001 meets AI regulation
How management system evidence maps onto the risk classification, technical documentation and human oversight duties appearing in new AI legislation.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO/IEC 42001.
Does ISO/IEC 42001 certify our AI model, or the organisation?
We only use AI bought from vendors. Does the standard still apply?
Does certification make us compliant with the EU AI Act?
Can we add 42001 to an existing ISO/IEC 27001 certificate?
What does the AI impact assessment actually have to cover?
How long is the certificate valid and what happens each year?
Start ISO/IEC 42001 certification with an accredited body
Certification here is not a paperwork exercise: an accredited body will look at models running in production. The certificate names the AI scope your customers keep asking about.
Get My Free Quote β WhatsApp Us