Certification Guide

ISO 42001 certification: process, timeline and cost

What certification to ISO/IEC 42001 actually involves — the stages, who issues the certificate, what drives the price, and how to tell whether you need certification at all or simply need the governance.

The certification process What drives cost

Last reviewed July 2026 · Bcom — ISO/IEC 42001 specialists, Australia

Do you actually need the certificate?

It is worth answering this before spending anything. Certification and governance are not the same purchase. Implementing ISO/IEC 42001 gives you the management system. Certification gives you an independent third party attesting that the system exists and works.

If your driver is a tender requirement, an enterprise client's due diligence, or a commitment you have made to a regulator or board, you need the certificate. If your driver is that AI has spread through the business faster than your controls have, you need the system — and certification is an optional later step.

A useful test

Ask who the evidence is for. If the answer is "someone outside the organisation who will not take our word for it", certification is doing real work. If the answer is "us, so we can sleep at night", alignment may be sufficient — and considerably cheaper.

How ISO/IEC 42001 certification works

Certification follows the same audit pattern as other ISO management system standards. The certificate is issued by an independent, accredited certification body — never by the consultancy that helped you implement.

1. Define scope

Decide which parts of the organisation, and which AI systems, the management system covers. This is the most consequential decision in the whole exercise: scope drives audit duration, audit fees, implementation effort and every future surveillance audit. Draw it around the AI use that carries real consequence.

2. Build the management system

Establish the AIMS itself — AI policy, an inventory of where AI is actually used, AI risk and impact assessment, defined accountability, human oversight arrangements, data and model governance, competence, and the operating rhythm of internal audit and management review.

3. Operate it, and generate evidence

The step organisations most often underestimate. Auditors assess a system in operation, not a folder of documents. You need a period of the system genuinely running — assessments completed, decisions recorded, at least one internal audit and one management review performed.

4. Stage 1 audit — readiness

The certification body reviews your documented system and scope to confirm you are ready for a full audit. Gaps found here are cheaper to fix than gaps found at Stage 2. Treat a Stage 1 finding as useful information, not failure.

5. Stage 2 audit — implementation

The substantive audit. The auditor tests whether the system described at Stage 1 is genuinely operating, sampling evidence and interviewing people. Nonconformities are raised, and typically must be addressed before the certificate is issued.

6. Certification, then the ongoing cycle

The certificate is issued for a defined validity period, with surveillance audits at intervals during it and a recertification audit at the end. The obligation to keep the system running does not pause between audits.

What actually drives the cost

We do not publish a headline price, because a credible one cannot be quoted without knowing your scope. What we can set out plainly is what moves the number — so you can interrogate any quote you receive.

Cost driverWhy it moves the number
Scope breadthThe dominant factor. More business units, sites and AI systems means more audit days — every cycle, not just the first.
Headcount and sitesCertification bodies size audit duration largely on the number of people and locations in scope.
Existing maturityAn organisation with a live ISO management system reuses most of the machinery. Starting from nothing means building it first.
AI complexitySystems that make or materially inform decisions about people attract deeper scrutiny than low-consequence internal tooling.
Internal capacityWhether you have someone who can own the system day to day, or whether that has to be bought in.
Ongoing maintenanceRecurring, and routinely forgotten in first-year budgets: surveillance audits plus the internal effort to keep evidence current.

The most common budgeting mistake

Budgeting only for the certification body's fees. In most first-time implementations the larger cost is internal: the time to build the system and generate operating evidence. The audit is the cheaper half of the exercise.

What an implementation partner does — and does not do

What we do

Assess where you stand, define a defensible scope, build the management system with your team, and get you to the point where a Stage 2 audit is a formality rather than a gamble.

What we cannot do

Issue your certificate. Certification must come from an independent accredited body — the same organisation cannot both build the system and audit it. That independence is the entire value of the certificate.

Where we start

A gap assessment in plain language: what you have, what ISO/IEC 42001 expects, and the honest distance between the two — including whether certification is worth pursuing at all.

Frequently asked questions

How long does ISO 42001 certification take?

For most small and mid-sized Australian organisations, expect somewhere between six and twelve months from a standing start to a Stage 2 audit. The variable is rarely the paperwork — it is how long it takes for the system to actually be operating, because auditors need to see evidence of it running, not just documented.

Organisations that already hold another ISO certification move faster, because the management-system layer already exists and only the AI-specific substance has to be built.

What does ISO 42001 certification cost?

There is no meaningful standard price, and anyone quoting one without knowing your scope is guessing. Cost splits into two separate budgets: the certification body's audit fees, which are driven by your headcount, number of sites and the complexity of the scope; and the implementation effort to get ready, which is driven by how much governance you already have.

The single biggest cost lever is scope. A tightly drawn scope covering the AI systems that actually matter costs far less to certify — and less to maintain every year after — than an unnecessarily broad one.

Do we have to certify, or can we just align to the standard?

Alignment is a legitimate destination in its own right. You can build an AI management system to ISO/IEC 42001 and never engage a certification body. You get the governance benefit and can evidence a recognised structure in due diligence, without audit fees.

Certify when an external party needs independent assurance — typically a tender requirement, an enterprise client, or a regulator-facing commitment. Certification proves the system to third parties; it does not make the system itself better.

Can Bcom certify us?

No — and no legitimate implementation partner can. Certification must come from an independent, accredited certification body, and the same organisation cannot both build your management system and audit it. That separation is what makes the certificate worth anything.

We prepare you for certification and can work alongside your chosen certification body, but the audit and the certificate come from them.

What happens after we are certified?

Certification is a cycle, not an event. Expect surveillance audits at regular intervals through the certificate's validity period, and a fuller recertification audit at the end of it. Between audits, the system has to keep producing evidence — risk assessments reviewed, incidents logged, management reviews held.

This is why scope discipline matters so much: everything inside your scope has to be maintained and re-audited, every cycle, for as long as you hold the certificate.

Find out what certification would actually take

A gap assessment tells you where your AI governance stands today, what a defensible scope looks like, and whether certification belongs on your roadmap this year or at all. Delivered by a BSI-certified ISO/IEC 42001 Lead Implementer.

Book a gap assessment ISO 42001 vs ISO 27001