ISO 42001 Certification
ISO 42001 certification. Pass at first attempt.
From gap analysis through Stage 1 + Stage 2 to ongoing surveillance — the complete 3-year cycle, realistic cost, the certification body shortlist, and the eight most common audit findings.
3-year cycle · Stage 1 + Stage 2 · Surveillance · Recertification
The 3-Year Cycle
From Stage 1 to recertification.
Cost Breakdown
What ISO 42001 actually costs.
For a mid-sized organization (50-500 employees) running an integrated management system with existing ISO 27001.
Stage 1 + Stage 2 audit (cert body)
€8,000 – €30,000
One-time, depends on org size and AI scope
Internal implementation effort
€5,000 – €25,000
If done in-house (200-400 hours)
External consultants (optional)
€20,000 – €80,000
Skips most internal effort
Annual surveillance audit
€3,000 – €8,000
Years 2 and 3
Recertification (year 3)
€6,000 – €22,000
Roughly 70 percent of original audit cost
Total 3-year program
€15,000 – €60,000
Mid-sized org, integrated with existing ISO 27001
Certification Bodies
Accredited bodies offering ISO 42001 in 2026.
Verify accreditation scope on the IAF database before signing. Sector experience and audit team competence matter more than brand name.
BSI
UKAS · Global
Largest ISO 42001 portfolio as of 2026
DNV
Norwegian ACCR · Global, EU-strong
Energy & maritime sector depth
Schellman
ANAB (US) · US + EU
SOC 2 + ISO 27001 dual experience
A-LIGN
ANAB (US) · US + EU
Fast-moving on SaaS scopes
TÜV Süd
DAkkS · DACH, global
German market default for industrial AI
DEKRA
DAkkS · DACH, EU
Strong automotive sector depth
TÜV NORD
DAkkS · DACH, EU
Public sector experience
PECB
IAS · Global
Strong in MENA + EU
Common Findings
The eight most common ISO 42001 audit findings — and how to avoid each one.
AI inventory incomplete or stale
Shadow AI projects, deprecated model versions still listed, third-party APIs (OpenAI, Anthropic, Azure OpenAI) not classified.
Risk and impact assessment not differentiated
Treating Clause 6 risk and A.5 impact as one process. Auditors expect two distinct artifacts with different methodologies.
Statement of Applicability lacks rationale
Excluded Annex A controls need a documented reason. "Not applicable" alone is not sufficient — explain why.
Supplier due diligence missing for foundation models
Most orgs onboard OpenAI/Anthropic without an A.10.2 supplier risk assessment. Auditors are starting to flag this.
Human oversight in policy, not in practice
Policy says "human reviews all decisions" but logs show 0 percent override rate. Operationalize oversight: define triggers, review SLAs, escalation paths.
AI literacy training records incomplete
Art. 4 EU AI Act requires demonstrable training. Auditors check completion records by person and date, not just attendance lists.
Incident classification framework missing
AIMS needs a defined process for serious AI incidents, aligned with EU AI Act Art. 73 (serious incident reporting) — most orgs lack this.
Management review minutes lack AI decisions
Generic minutes that don't show AI-specific risk decisions, AI metric reviews, or AI policy updates. Decision trail is the audit gold.
How Matproof Helps
From gap analysis to certificate.
FAQ
Frequently asked questions
How long does ISO 42001 certification take from start to finish?+
For an organization with a mature ISO 27001 ISMS already in place, 4 to 9 months: gap analysis (4-6 weeks), AIMS implementation (3-5 months), Stage 1 (documentation audit, 1-2 days), Stage 2 (operational effectiveness, 3-5 days). Greenfield organizations without an existing management system should plan for 9 to 18 months. The biggest accelerator is whether you can reuse ISO 27001 evidence, supplier registers, training records, and risk processes — which Matproof maps automatically.
What's the difference between Stage 1 and Stage 2?+
Stage 1 is the documentation audit (1-2 days, typically remote). The auditor reviews your AIMS scope, AI policy, Statement of Applicability, AI risk assessment, AI impact assessment process, management review records, and internal audit results. The goal is to confirm you're ready for Stage 2 and identify any major gaps. Stage 2 is the certification audit (3-5 days, typically on-site). The auditor tests operational effectiveness: interviews with AI operators, sampling of Annex A controls, walkthroughs of AI system change management, incident handling, supplier oversight. Most major findings happen at Stage 2 — Stage 1 is usually a dress rehearsal.
What does ISO 42001 certification cost realistically?+
For a mid-sized organization (50-500 employees) the first 3-year cycle typically falls in the €15,000-€60,000 range. Breakdown: certification body fees €8,000-€30,000 for the Stage 1 + Stage 2 audits, annual surveillance audits €3,000-€8,000 each in years 2 and 3, and recertification in year 3 at roughly 70 percent of the original audit cost. Implementation effort runs €5,000-€25,000 if done internally (200-400 hours of work), or €20,000-€80,000 with external consultants. The biggest cost variable is whether you bolt the AIMS onto an existing ISO 27001 program (40 percent savings) or build both from scratch.
Which certification bodies offer accredited ISO 42001 certification?+
As of 2026, accredited certification bodies offering ISO 42001 include: BSI (UKAS-accredited, global), DNV (Norway, global reach), Schellman (US-headquartered, ANAB accreditation), A-LIGN (US, ANAB), TÜV Süd (Germany, DAkkS accreditation), DEKRA (Germany, DAkkS), KIWA, TÜV NORD, and PECB. The market is still maturing — verify a body's accreditation scope on the IAF database before signing. Sector-specific experience matters: a body that has audited dozens of ISO 27001 SaaS firms will move faster on your AIMS than a generalist.
Can ISO 42001 be combined with ISO 27001 in one audit?+
Yes — running ISO 42001 and ISO 27001 as an integrated management system (IMS) is the most cost-effective path for organizations that need both. Combined Stage 1 + Stage 2 audits, shared management review, single internal audit program, shared Statement of Applicability sections, one supplier register, one risk register, one incident log. Realistic IMS cost savings: 30-45 percent versus running both standards in parallel. Most major certification bodies (BSI, DNV, TÜV Süd, DEKRA) offer integrated audit packages.
What are the most common ISO 42001 audit findings?+
From the first wave of ISO 42001 certifications in 2024-2025, the top eight findings are: (1) AI inventory incomplete or stale (shadow AI, deprecated models still listed), (2) Risk and impact assessment not differentiated (treating them as one process), (3) Statement of Applicability missing rationale for excluded Annex A controls, (4) Supplier due diligence missing for foundation model providers (OpenAI, Anthropic, etc.), (5) Human oversight defined in policy but not operationalized, (6) AI literacy training records incomplete or undated, (7) Incident classification framework missing or misaligned with EU AI Act Art. 73, (8) Management review minutes lack documented decisions on AI risks. Matproof's pre-audit checklist surfaces all eight before Stage 1.
Do auditors need AI domain expertise?+
Yes, but the supply is currently short. ISO/IEC 27006-2 (the auditor competence standard for AIMS) requires auditors to demonstrate competence in AI lifecycle management, AI risk assessment, AI ethics, and the technical environment of the audited organization. As of 2026, the auditor pool is heavily weighted toward ISO 27001 auditors with adjacent AI experience — fully accredited ISO 42001 auditors are still rare. Ask any prospective certification body about audit team competence specifically for your AI use cases (generative AI, computer vision, autonomous decision-making, etc.).
How does ISO 42001 certification help with the EU AI Act?+
Three concrete ways. (1) Demonstrable governance maturity — high-risk AI providers need to show they operate a quality management system (Art. 17), risk management system (Art. 9), and post-market monitoring (Art. 72). ISO 42001 directly maps to all three. (2) Vendor due diligence — EU buyers (especially regulated sectors) are increasingly asking for ISO 42001 in RFPs and DPAs for AI components. (3) Future presumption of conformity — once CEN-CENELEC JTC 21 finalizes harmonized standards under AI Act Art. 40 (expected 2026-2027) and ISO 42001 is referenced in them, certification will create a presumption of conformity with the AI Act's relevant requirements.
Start
Skip the months of pre-audit grind.
30-minute demo. See how Matproof turns ISO 42001 from a 12-month project into a 4-month sprint.