Key facts
- Controls
- 38 Annex A controls under 9 objectives (vendor consensus across seven independent sources; the standard text is paywalled and we have not checked it against ISO's own document)
- Recertification cycle
- 3-year certificate
- Ongoing oversight
- Annual surveillance audits in years 1 and 2 (certification-body practice under ISO/IEC 17021-1, not stated in a free ISO source)
- Public registry
- IAF CertSearch β
- Related standards
What is ISO 42001?
An international standard (ISO/IEC 42001:2023) published by ISO and IEC in December 2023, scoped to an organization's Artificial Intelligence Management System (AIMS). It applies to any organization of any size or sector that develops, provides, or uses AI, and it governs how AI is managed across its lifecycle rather than setting rules for individual AI applications.
Is ISO 42001 a certification or an attestation?
ISO 42001 is a certification. An accredited certification body audits the AI management system and issues a certificate valid for three years. ISO itself certifies nobody. Three claims get confused here: a certified organization was audited by an accredited body, a compliant one usually assessed itself, and a lead auditor certificate belongs to a person.
Who can actually certify your organization to ISO 42001?
Only a certification body that a national accreditation body such as ANAB, UKAS, or RvA has accredited for AI management systems. ISO certifies nobody. AWS and Anthropic were each certified this way, by an ANAB-accredited body. Most search results for this question sell training courses to individuals instead.
| The claim | Who issues it | What it actually proves |
|---|---|---|
| "ISO 42001 certified", said of an organization | An accredited certification body, after a Stage 1 and Stage 2 audit | An independent, accredited third party examined this organization's AI management system and issued a three-year certificate. This is the only claim that should be called certification, and the certificate is verifiable in IAF CertSearch. |
| "ISO 42001 compliant" or "conformant" | The organization itself, with no external audit | That the organization believes it meets the standard. Nobody independent has checked. Unlike "certified", the word is policed by no one, so ask who audited it and under whose accreditation. |
| "ISO 42001 Lead Auditor" or "Lead Implementer" | A training provider, to one individual who passed a course and exam | That a person completed training. It says nothing about whether their employer, or any organization, holds a certificate. These courses dominate the search results for ISO 42001 certification, which is why the distinction matters. |
- Firms in our directory accredited to issue ISO 42001 certificates
- 12
- Firms that sell ISO 42001 readiness or implementation work
- 17
We set those two flags only from a firm's own site or its accreditor's record, so a firm missing from them is one we have not verified rather than one without the capability. There is no public count of certified organizations either: ISO now compiles its Survey from IAF CertSearch, which requires a login, so any global certificate total quoted without a source is guesswork.
Who needs ISO 42001?
Companies that build, embed, or resell AI and are now being asked how they govern it. That means AI vendors facing enterprise procurement questionnaires, teams preparing for the EU AI Act, and organizations already certified to ISO 27001 that want one management system covering information security and AI together.
What happens during an ISO 42001 certification audit?
The same two-stage shape as ISO 27001, because both are certified under the same accreditation rulebook, followed by annual surveillance and a three-year recertification cycle. The detail below comes from certification bodies and consultancies rather than from the standard, whose text is paywalled.
- Check the certification body's accreditation first
- Confirm the body holds ISO 42001 scope with a recognized accreditor such as ANAB, UKAS, or RvA, and that the scope covers AI management systems specifically. ISO published ISO/IEC 42006 in July 2025 to set the competence requirements those bodies must meet, which is why accredited capacity only became widely available through 2025 and 2026.
- Stage 1: documentation review
- The body reviews the AI policy, the scope of the management system, the AI risk and impact assessment, and the Statement of Applicability that justifies which Annex A controls apply and which are excluded. Usually remote, one to two days, and it ends in a list of gaps to close.
- Stage 2: certification audit
- Weeks to a couple of months later, auditors test whether the system actually operates as documented, sampling evidence and interviewing staff. A pass leads to the three-year certificate.
- Surveillance audits (years 1 and 2)
- Narrower annual audits, each roughly a third the length of the initial audit, confirm the system keeps operating. A major nonconformity can suspend or withdraw a certificate that has not yet expired.
- Recertification (year 3)
- A full audit renews the certificate for another three-year cycle. Let a certificate lapse and the next one starts again at Stage 1.
What does ISO 42001 cost and how long does it take?
There is no independent benchmark for what ISO 42001 costs. Every published figure we found comes from a party selling something, and the figures differ mainly in what they count rather than in what the market charges. A compliance platform puts the certification body's audit fee alone at $7,000 to $20,000, plus $3,500 to $9,000 a year for surveillance. A consultancy selling implementation puts a first-year enterprise program at $160,000 to $505,000. A third vendor puts an all-in small-business program at $4,000 to $20,000. Before comparing two quotes, ask which of those three things each one covers. Timelines cluster at three to six months for organizations that already run an ISO 27001 management system, with a gap of at least two weeks between the Stage 1 and Stage 2 audits.
The EU AI Act timeline moved on 27 July 2026. The AI Omnibus deferred the Annex III high-risk rules to 2 December 2027 and the Annex I embedded-product rules to 2 August 2028, so anything still citing 2 August 2026 as the high-risk deadline is out of date. It does not follow that ISO 42001 satisfies the Act. Only a harmonized European standard cited in the Official Journal creates a legal presumption of conformity, and none has been cited yet. ISO 42001 is useful evidence for that work, never a legal shield.
Sources
- ISO: ISO/IEC 42001:2023 official page β
- ISO: ISO 42001 explained (voluntary certification, ISO certifies nobody) β
- ISO: ISO/IEC 42006:2025, requirements for bodies certifying AI management systems β
- ISO: the ISO Survey, now compiled from IAF CertSearch β
- IAF CertSearch: the accredited-certification registry β
- ANAB: applicants for management systems accreditation β
- NIST AI Resource Center: AI RMF crosswalks (the ISO 42001 one is authored by Microsoft, hosted by NIST) β
- European Commission: AI Omnibus enters into force, 27 July 2026 β
- AWS: ISO/IEC 42001 accredited certification announcement β
- Anthropic: ISO 42001 certification announcement β
- Vanta: ISO 42001 certification cost (vendor estimate, audit fee only) β
- Elevate Consult: ISO 42001 enterprise cost breakdown (vendor estimate, full program) β
- Cycoresecure: ISO 42001 cost and timeline FAQ (vendor estimate, small-business all-in) β
Go deeper on this
Ready to act on ISO 42001?
Most AI companies reach ISO 42001 second, after the SOC 2 report their enterprise buyers ask for first. Keep the two hires separate when you get there: the accredited body that issues your certificate should not be the firm that built the management system it is auditing.