What certification to ISO/IEC 42001 actually involves — the stages, who issues the certificate, what drives the price, and how to tell whether you need certification at all or simply need the governance.
It is worth answering this before spending anything. Certification and governance are not the same purchase. Implementing ISO/IEC 42001 gives you the management system. Certification gives you an independent third party attesting that the system exists and works.
If your driver is a tender requirement, an enterprise client's due diligence, or a commitment you have made to a regulator or board, you need the certificate. If your driver is that AI has spread through the business faster than your controls have, you need the system — and certification is an optional later step.
Ask who the evidence is for. If the answer is "someone outside the organisation who will not take our word for it", certification is doing real work. If the answer is "us, so we can sleep at night", alignment may be sufficient — and considerably cheaper.
Certification follows the same audit pattern as other ISO management system standards. The certificate is issued by an independent, accredited certification body — never by the consultancy that helped you implement.
Decide which parts of the organisation, and which AI systems, the management system covers. This is the most consequential decision in the whole exercise: scope drives audit duration, audit fees, implementation effort and every future surveillance audit. Draw it around the AI use that carries real consequence.
Establish the AIMS itself — AI policy, an inventory of where AI is actually used, AI risk and impact assessment, defined accountability, human oversight arrangements, data and model governance, competence, and the operating rhythm of internal audit and management review.
The step organisations most often underestimate. Auditors assess a system in operation, not a folder of documents. You need a period of the system genuinely running — assessments completed, decisions recorded, at least one internal audit and one management review performed.
The certification body reviews your documented system and scope to confirm you are ready for a full audit. Gaps found here are cheaper to fix than gaps found at Stage 2. Treat a Stage 1 finding as useful information, not failure.
The substantive audit. The auditor tests whether the system described at Stage 1 is genuinely operating, sampling evidence and interviewing people. Nonconformities are raised, and typically must be addressed before the certificate is issued.
The certificate is issued for a defined validity period, with surveillance audits at intervals during it and a recertification audit at the end. The obligation to keep the system running does not pause between audits.
We do not publish a headline price, because a credible one cannot be quoted without knowing your scope. What we can set out plainly is what moves the number — so you can interrogate any quote you receive.
| Cost driver | Why it moves the number |
|---|---|
| Scope breadth | The dominant factor. More business units, sites and AI systems means more audit days — every cycle, not just the first. |
| Headcount and sites | Certification bodies size audit duration largely on the number of people and locations in scope. |
| Existing maturity | An organisation with a live ISO management system reuses most of the machinery. Starting from nothing means building it first. |
| AI complexity | Systems that make or materially inform decisions about people attract deeper scrutiny than low-consequence internal tooling. |
| Internal capacity | Whether you have someone who can own the system day to day, or whether that has to be bought in. |
| Ongoing maintenance | Recurring, and routinely forgotten in first-year budgets: surveillance audits plus the internal effort to keep evidence current. |
Budgeting only for the certification body's fees. In most first-time implementations the larger cost is internal: the time to build the system and generate operating evidence. The audit is the cheaper half of the exercise.
Assess where you stand, define a defensible scope, build the management system with your team, and get you to the point where a Stage 2 audit is a formality rather than a gamble.
Issue your certificate. Certification must come from an independent accredited body — the same organisation cannot both build the system and audit it. That independence is the entire value of the certificate.
A gap assessment in plain language: what you have, what ISO/IEC 42001 expects, and the honest distance between the two — including whether certification is worth pursuing at all.
For most small and mid-sized Australian organisations, expect somewhere between six and twelve months from a standing start to a Stage 2 audit. The variable is rarely the paperwork — it is how long it takes for the system to actually be operating, because auditors need to see evidence of it running, not just documented.
Organisations that already hold another ISO certification move faster, because the management-system layer already exists and only the AI-specific substance has to be built.
There is no meaningful standard price, and anyone quoting one without knowing your scope is guessing. Cost splits into two separate budgets: the certification body's audit fees, which are driven by your headcount, number of sites and the complexity of the scope; and the implementation effort to get ready, which is driven by how much governance you already have.
The single biggest cost lever is scope. A tightly drawn scope covering the AI systems that actually matter costs far less to certify — and less to maintain every year after — than an unnecessarily broad one.
Alignment is a legitimate destination in its own right. You can build an AI management system to ISO/IEC 42001 and never engage a certification body. You get the governance benefit and can evidence a recognised structure in due diligence, without audit fees.
Certify when an external party needs independent assurance — typically a tender requirement, an enterprise client, or a regulator-facing commitment. Certification proves the system to third parties; it does not make the system itself better.
No — and no legitimate implementation partner can. Certification must come from an independent, accredited certification body, and the same organisation cannot both build your management system and audit it. That separation is what makes the certificate worth anything.
We prepare you for certification and can work alongside your chosen certification body, but the audit and the certificate come from them.
Certification is a cycle, not an event. Expect surveillance audits at regular intervals through the certificate's validity period, and a fuller recertification audit at the end of it. Between audits, the system has to keep producing evidence — risk assessments reviewed, incidents logged, management reviews held.
This is why scope discipline matters so much: everything inside your scope has to be maintained and re-audited, every cycle, for as long as you hold the certificate.
A gap assessment tells you where your AI governance stands today, what a defensible scope looks like, and whether certification belongs on your roadmap this year or at all. Delivered by a BSI-certified ISO/IEC 42001 Lead Implementer.