SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO

ISO 42001 Certification

ISO 42001 certification. Pass at first attempt.

From gap analysis through Stage 1 + Stage 2 to ongoing surveillance — the complete 3-year cycle, realistic cost, the certification body shortlist, and the eight most common audit findings.

3-year cycle · Stage 1 + Stage 2 · Surveillance · Recertification

The 3-Year Cycle

From Stage 1 to recertification.

Year 0 · Stage 11-2 daysDocumentation audit. Reviewer reads your AIMS scope, AI policy, Statement of Applicability, AI risk + impact assessments, management review minutes, and internal audit results to confirm readiness for Stage 2.
Year 0 · Stage 23-5 daysCertification audit (typically on-site). Interviews with AI operators, sampling of Annex A controls, walkthroughs of AI system change management, incident handling, and supplier oversight. Most major findings land here.
Year 1 · Surveillance1-2 daysReduced audit focused on Annex A control samples, any AI system changes since Stage 2, and follow-up on prior findings. Confirms the AIMS is operating, not just documented.
Year 2 · Surveillance1-2 daysTargets areas not deeply sampled in year 1, plus emerging AI risks (new model deployments, foundation model upgrades, vendor changes, incidents).
Year 3 · Recertification2-3 daysFull re-audit to renew the certificate for another 3 years. Typically 70 percent of the original Stage 2 effort because the auditor knows your AIMS.

Cost Breakdown

What ISO 42001 actually costs.

For a mid-sized organization (50-500 employees) running an integrated management system with existing ISO 27001.

Stage 1 + Stage 2 audit (cert body)

€8,000 – €30,000

One-time, depends on org size and AI scope

Internal implementation effort

€5,000 – €25,000

If done in-house (200-400 hours)

External consultants (optional)

€20,000 – €80,000

Skips most internal effort

Annual surveillance audit

€3,000 – €8,000

Years 2 and 3

Recertification (year 3)

€6,000 – €22,000

Roughly 70 percent of original audit cost

Total 3-year program

€15,000 – €60,000

Mid-sized org, integrated with existing ISO 27001

Certification Bodies

Accredited bodies offering ISO 42001 in 2026.

Verify accreditation scope on the IAF database before signing. Sector experience and audit team competence matter more than brand name.

BSI

UKAS · Global

Largest ISO 42001 portfolio as of 2026

DNV

Norwegian ACCR · Global, EU-strong

Energy & maritime sector depth

Schellman

ANAB (US) · US + EU

SOC 2 + ISO 27001 dual experience

A-LIGN

ANAB (US) · US + EU

Fast-moving on SaaS scopes

TÜV Süd

DAkkS · DACH, global

German market default for industrial AI

DEKRA

DAkkS · DACH, EU

Strong automotive sector depth

TÜV NORD

DAkkS · DACH, EU

Public sector experience

PECB

IAS · Global

Strong in MENA + EU

Common Findings

The eight most common ISO 42001 audit findings — and how to avoid each one.

01

AI inventory incomplete or stale

Shadow AI projects, deprecated model versions still listed, third-party APIs (OpenAI, Anthropic, Azure OpenAI) not classified.

02

Risk and impact assessment not differentiated

Treating Clause 6 risk and A.5 impact as one process. Auditors expect two distinct artifacts with different methodologies.

03

Statement of Applicability lacks rationale

Excluded Annex A controls need a documented reason. "Not applicable" alone is not sufficient — explain why.

04

Supplier due diligence missing for foundation models

Most orgs onboard OpenAI/Anthropic without an A.10.2 supplier risk assessment. Auditors are starting to flag this.

05

Human oversight in policy, not in practice

Policy says "human reviews all decisions" but logs show 0 percent override rate. Operationalize oversight: define triggers, review SLAs, escalation paths.

06

AI literacy training records incomplete

Art. 4 EU AI Act requires demonstrable training. Auditors check completion records by person and date, not just attendance lists.

07

Incident classification framework missing

AIMS needs a defined process for serious AI incidents, aligned with EU AI Act Art. 73 (serious incident reporting) — most orgs lack this.

08

Management review minutes lack AI decisions

Generic minutes that don't show AI-specific risk decisions, AI metric reviews, or AI policy updates. Decision trail is the audit gold.

How Matproof Helps

From gap analysis to certificate.

Pre-audit gap analysis: 38 Annex A controls + 7 clauses scored against your current evidence
Automated AI inventory: OpenAI, Anthropic, Azure OpenAI, Hugging Face, MLflow, internal models
Statement of Applicability auto-generated with per-control rationale
AI risk register + impact assessment register kept as separate artifacts (avoids finding #2)
Foundation model supplier dossiers pre-built for OpenAI, Anthropic, Google, Mistral, Cohere
AI literacy training tracked per person, per role, per AI system
Management review templates with AI decision sections built in
Integrated audit support: shared evidence with ISO 27001, SOC 2, NIS2

FAQ

Frequently asked questions

How long does ISO 42001 certification take from start to finish?+

For an organization with a mature ISO 27001 ISMS already in place, 4 to 9 months: gap analysis (4-6 weeks), AIMS implementation (3-5 months), Stage 1 (documentation audit, 1-2 days), Stage 2 (operational effectiveness, 3-5 days). Greenfield organizations without an existing management system should plan for 9 to 18 months. The biggest accelerator is whether you can reuse ISO 27001 evidence, supplier registers, training records, and risk processes — which Matproof maps automatically.

What's the difference between Stage 1 and Stage 2?+

Stage 1 is the documentation audit (1-2 days, typically remote). The auditor reviews your AIMS scope, AI policy, Statement of Applicability, AI risk assessment, AI impact assessment process, management review records, and internal audit results. The goal is to confirm you're ready for Stage 2 and identify any major gaps. Stage 2 is the certification audit (3-5 days, typically on-site). The auditor tests operational effectiveness: interviews with AI operators, sampling of Annex A controls, walkthroughs of AI system change management, incident handling, supplier oversight. Most major findings happen at Stage 2 — Stage 1 is usually a dress rehearsal.

What does ISO 42001 certification cost realistically?+

For a mid-sized organization (50-500 employees) the first 3-year cycle typically falls in the €15,000-€60,000 range. Breakdown: certification body fees €8,000-€30,000 for the Stage 1 + Stage 2 audits, annual surveillance audits €3,000-€8,000 each in years 2 and 3, and recertification in year 3 at roughly 70 percent of the original audit cost. Implementation effort runs €5,000-€25,000 if done internally (200-400 hours of work), or €20,000-€80,000 with external consultants. The biggest cost variable is whether you bolt the AIMS onto an existing ISO 27001 program (40 percent savings) or build both from scratch.

Which certification bodies offer accredited ISO 42001 certification?+

As of 2026, accredited certification bodies offering ISO 42001 include: BSI (UKAS-accredited, global), DNV (Norway, global reach), Schellman (US-headquartered, ANAB accreditation), A-LIGN (US, ANAB), TÜV Süd (Germany, DAkkS accreditation), DEKRA (Germany, DAkkS), KIWA, TÜV NORD, and PECB. The market is still maturing — verify a body's accreditation scope on the IAF database before signing. Sector-specific experience matters: a body that has audited dozens of ISO 27001 SaaS firms will move faster on your AIMS than a generalist.

Can ISO 42001 be combined with ISO 27001 in one audit?+

Yes — running ISO 42001 and ISO 27001 as an integrated management system (IMS) is the most cost-effective path for organizations that need both. Combined Stage 1 + Stage 2 audits, shared management review, single internal audit program, shared Statement of Applicability sections, one supplier register, one risk register, one incident log. Realistic IMS cost savings: 30-45 percent versus running both standards in parallel. Most major certification bodies (BSI, DNV, TÜV Süd, DEKRA) offer integrated audit packages.

What are the most common ISO 42001 audit findings?+

From the first wave of ISO 42001 certifications in 2024-2025, the top eight findings are: (1) AI inventory incomplete or stale (shadow AI, deprecated models still listed), (2) Risk and impact assessment not differentiated (treating them as one process), (3) Statement of Applicability missing rationale for excluded Annex A controls, (4) Supplier due diligence missing for foundation model providers (OpenAI, Anthropic, etc.), (5) Human oversight defined in policy but not operationalized, (6) AI literacy training records incomplete or undated, (7) Incident classification framework missing or misaligned with EU AI Act Art. 73, (8) Management review minutes lack documented decisions on AI risks. Matproof's pre-audit checklist surfaces all eight before Stage 1.

Do auditors need AI domain expertise?+

Yes, but the supply is currently short. ISO/IEC 27006-2 (the auditor competence standard for AIMS) requires auditors to demonstrate competence in AI lifecycle management, AI risk assessment, AI ethics, and the technical environment of the audited organization. As of 2026, the auditor pool is heavily weighted toward ISO 27001 auditors with adjacent AI experience — fully accredited ISO 42001 auditors are still rare. Ask any prospective certification body about audit team competence specifically for your AI use cases (generative AI, computer vision, autonomous decision-making, etc.).

How does ISO 42001 certification help with the EU AI Act?+

Three concrete ways. (1) Demonstrable governance maturity — high-risk AI providers need to show they operate a quality management system (Art. 17), risk management system (Art. 9), and post-market monitoring (Art. 72). ISO 42001 directly maps to all three. (2) Vendor due diligence — EU buyers (especially regulated sectors) are increasingly asking for ISO 42001 in RFPs and DPAs for AI components. (3) Future presumption of conformity — once CEN-CENELEC JTC 21 finalizes harmonized standards under AI Act Art. 40 (expected 2026-2027) and ISO 42001 is referenced in them, certification will create a presumption of conformity with the AI Act's relevant requirements.

Start

Skip the months of pre-audit grind.

30-minute demo. See how Matproof turns ISO 42001 from a 12-month project into a 4-month sprint.