Skip to main content

Elevate

ISO 42001 Certification: The Path From Gap Analysis to Certificate

ISO 42001 certification is the only accredited third-party attestation available for an AI management system, and the infrastructure behind it changed materially during 2025 and 2026. ISO/IEC 42006:2025 now sets the requirements for the bodies that audit and certify against ISO/IEC 42001:2023, which means the question of who issues a certificate carries as much weight as whether an organization earns one. A certificate from a body without accreditation under that standard will not satisfy the enterprise buyers and regulators most organizations are pursuing certification to reach.

This guide covers what the standard requires, how the two-stage audit works, how to verify a certification body, realistic timelines, and the failure modes that push certification dates to the right.

What ISO/IEC 42001:2023 Requires

ISO/IEC 42001:2023 was published on December 18, 2023 by ISO/IEC JTC 1/SC 42. It is the first international management system standard for artificial intelligence and remains the only certifiable one. Its structure parallels ISO/IEC 27001 for information security, which matters practically: organizations already running a certified ISMS have a substantial head start, because the management system scaffolding is shared.

The standard certifies a system of governance rather than any individual model. That distinction is the source of most early scoping confusion. An organization does not certify its recommendation engine. It certifies the AI management system, or AIMS, that governs how it develops, procures, deploys and monitors AI across the defined scope.

The Management System Clauses

Clauses 4 through 10 carry the management system requirements and follow the harmonized structure common to ISO management standards.

ClauseRequirementWhat auditors look for
4, ContextInternal and external issues, interested parties, AIMS scopeA scope statement that matches what the organization actually does with AI
5, LeadershipPolicy, roles, responsibilities, authoritiesNamed owners with authority, not a committee with no decision rights
6, PlanningRisk assessment, AI impact assessment, objectivesDocumented methodology, applied and repeated, not performed once
7, SupportResources, competence, awareness, documented informationTraining records tied to the roles that need them
8, OperationOperational planning and control across the AI lifecycleEvidence that the controls ran, not that they exist
9, PerformanceMonitoring, internal audit, management reviewDated internal audit records and management review minutes with decisions
10, ImprovementNonconformity, corrective action, continual improvementClosed corrective actions traceable to the finding that triggered them

Annex A carries the AI-specific controls, with Annex B providing implementation guidance. The controls are subject to a statement of applicability in the same way Annex A works under ISO 27001, so an organization justifies inclusion or exclusion rather than implementing everything by default.

The clause that surprises organizations most often is Clause 9. Internal audit and management review are mandatory, they need to have happened before the certification audit, and they need records. An organization with strong controls and no internal audit history is not ready, regardless of how well the controls perform.

Elevate’s breakdown of ISO 42001 requirements covers the clause set in more detail.

Why Accreditation Now Decides Certificate Value

This is the part of the process that changed most since early 2025, and it is the part most published guidance still omits.

ISO does not issue certificates. Accredited certification bodies conduct audits under ISO/IEC 17021-1, the general standard for bodies providing management system certification. ISO/IEC 42006:2025 supplements that with AI-specific requirements for those bodies, covering auditor competence and audit duration among other things. Certification bodies are in turn accredited by national accreditation bodies such as ANAB in the United States, UKAS in the United Kingdom, and RvA in the Netherlands.

The European co-operation for Accreditation voted in November 2025 to make ISO/IEC 42006:2025 the mandatory standard for accrediting certification bodies that certify AI management systems. Accreditation grants followed through 2026 across ANAB, UKAS, RvA and several other national bodies, though the population of accredited bodies remains small and is still growing on a rolling basis.

What to Verify Before Signing

The practical consequence is that a prospective client should verify three things before engaging a certification body, and none of them can be taken from the body’s own marketing.

Confirm the body holds accreditation from an accreditation body recognized under the International Accreditation Forum Multilateral Recognition Arrangement, which is what makes a certificate internationally portable. Confirm that ISO/IEC 42001 sits explicitly within the scope of that accreditation, because a body accredited for ISO 27001 is not thereby accredited for ISO 42001. Check the accreditation body’s own public register rather than accepting a claim, and ask the certification body to provide its accreditation certificate directly.

Two states are frequently presented as accreditation and are not. An applicant listed on an accreditation body’s applicants page is not accredited. A participant in an accreditation pilot programme is not accredited. Both appear in vendor material as though they were.

Elevate’s guidance on choosing a partner for ISO 42001 certification covers the evaluation in full.

The Certification Audit, Stage by Stage

Accredited certification follows a two-stage audit, and organizations that plan for a single event are the ones that miss dates.

Stage 1

Stage 1 is a readiness review. The auditor examines documented information, confirms the AIMS scope, reviews the statement of applicability, checks that internal audit and management review have occurred, and evaluates whether the organization is prepared for Stage 2. Findings at this stage are usually described as areas of concern rather than nonconformities.

Stage 1 exists to prevent a failed Stage 2, and organizations should treat it that way. A Stage 1 that surfaces significant gaps is working correctly, and the sensible response is to remediate before scheduling Stage 2 rather than proceeding on the original calendar.

Stage 2

Stage 2 is the certification audit proper. The auditor tests whether the AIMS is implemented and effective, sampling evidence against the clause requirements and the applicable Annex A controls. This is where the distinction between documented and operating becomes decisive, because an auditor grades what the organization can produce rather than what its policy asserts.

Findings are classified as major or minor nonconformities. Major nonconformities must be closed before a certificate issues. Minor nonconformities are typically addressed through a corrective action plan with an agreed timeline. Elevate’s overview of what to expect during an ISO 42001 certification review walks the audit experience.

The Certification Cycle

A certificate runs on a three-year cycle. Surveillance audits occur during the cycle to confirm continued conformity, and recertification at the end of it. The cycle is not a formality: surveillance findings can suspend or withdraw a certificate, and an AIMS that stopped operating after the certificate arrived will surface at the first surveillance visit.

Realistic Timelines and What Moves Them

Certification duration varies with AIMS scope, existing management system maturity and the number of AI systems in scope. Rather than quoting a range that will not fit a specific environment, it is more useful to name what actually controls the schedule.

FactorEffect on timeline
Existing certified ISMS under ISO 27001Shortens materially, because Clauses 4 through 10 scaffolding already exists
Number and diversity of AI systems in scopeExtends, because each requires impact assessment and lifecycle evidence
Availability of an accredited certification bodyExtends where the accredited population is thin in a given market
Internal audit and management review historyHard gate, cannot be compressed below the time it takes to actually run them
Evidence accumulation for operational controlsHard gate, accrues on calendar time and cannot be recovered retroactively

The last two rows are the ones that break schedules. An organization can accelerate documentation with resources. It cannot accelerate the passage of time required to demonstrate that a control operated across a period, and it cannot conduct a credible internal audit of a system that has been running for two weeks.

Scope discipline is the strongest lever available. A narrower AIMS scope that is defensible and expandable at recertification reaches a certificate faster than an enterprise-wide scope that cannot produce evidence everywhere.

Steps to Certification

Define the AI Inventory and the AIMS Scope

Certification cannot begin without knowing what AI the organization actually uses. That inventory extends past models developed internally to procured AI features embedded in SaaS tools, which is where most organizations discover systems nobody had catalogued.

From the inventory, define the AIMS scope: which organizational units, which AI systems, which lifecycle stages. The scope statement appears on the certificate and is what buyers read, so it needs to cover what the organization wants credit for while remaining something it can evidence.

Run a Gap Analysis

Compare current practice against the clause requirements and the applicable Annex A controls. The output should identify each gap, its risk, and a remediation path with an owner, rather than a conformity percentage. Elevate’s approach to an ISO 42001 gap analysis covers the method.

Build the AIMS

Integrate the AIMS with existing management processes rather than constructing a parallel structure. Organizations running ISO 27001 should extend, not duplicate: a second risk register, a second management review and a second internal audit programme produce two sets of records that eventually disagree, and auditors notice.

Establish the AI policy, assign roles with real authority, define objectives with measures, and build the mechanism through which staff raise AI concerns to the people responsible.

Conduct Risk and AI Impact Assessments

Risk assessment covers the organization’s exposure. AI impact assessment covers effects on individuals, groups and society, which is the requirement most distinctly specific to this standard and the one organizations coming from ISO 27001 most often underestimate. Guidance for AI impact assessment sits in a companion ISO publication and shapes what auditors expect to see. Elevate covers the mechanics in its guide to designing the AI impact assessment for ISO 42001.

Both assessments need a documented methodology, applied consistently, repeated on a defined cadence, with records.

Run Internal Audit and Management Review

Both are mandatory and both need to precede the certification audit. Internal audit tests the AIMS against the standard and produces findings. Management review takes those findings, along with performance data and improvement opportunities, to leadership for decisions that are recorded.

An organization with a strong environment and no internal audit records is not ready. This is the most common reason a Stage 1 goes badly.

Select the Certification Body and Schedule

Verify accreditation as described above, confirm ISO/IEC 42001 is in scope, and hold a pre-audit discussion to align on scope interpretation and evidence expectations before Stage 1.

Organizations that want an independent read on readiness before committing to a certification body can book a readiness call with an Elevate advisor.

Where Organizations Stall

Scope That Cannot Be Evidenced

An AIMS scope drawn to impress buyers rather than to match operational reality produces an audit the organization cannot pass. The corrective action is always the same and always painful: narrow the scope, lose the certification date, restart the evidence clock for the reduced scope.

Documentation That Describes Intent

Policies describing how the organization intends to govern AI, written during the certification project and never operationalized, fail at Stage 2. The test an organization can run internally is to pick three Annex A controls at random, ask the person responsible to demonstrate the control, and see whether the demonstration matches the document.

Regulatory Complexity Treated as Separate Work

Organizations deploying AI across jurisdictions face obligations beyond ISO 42001, and the EU AI Act is the most consequential of them. Certification does not satisfy those obligations, and the obligations do not satisfy certification. Building the AIMS to also produce the evidence those regimes require avoids two parallel programmes, which is the more efficient design and the one most organizations discover second.

Leadership Commitment That Is Nominal

Clause 5 requires leadership commitment, and auditors test it by asking what decisions leadership actually made. A management review with attendance and no decisions is a finding. This is not a documentation problem, it is a governance problem that documentation cannot cover.

Conclusion

ISO 42001 certification has moved from an emerging option to an established one in under three years, and the infrastructure matured faster than most published guidance reflects. The consequential change is ISO/IEC 42006:2025 and the accreditation regime built on it, which means the certificate an organization receives is only worth what the accreditation behind the issuing body is worth.

The path itself is not novel for organizations that have been through ISO 27001. Define scope, close gaps, build the management system, run the assessments, audit internally, review at leadership level, then face a two-stage external audit. What is distinctly new is the AI impact assessment, which examines effects on individuals and society rather than on the organization, and which has no direct analogue in the information security standard.

The constraints that actually move certification dates are internal audit history and evidence accumulation, and neither responds to additional budget. Organizations that start the evidence clock early and keep the scope defensible reach a certificate sooner than those that do the reverse, regardless of how much they spend in the final quarter. Organizations ready to assess where they stand can book a readiness call with an Elevate advisor.

Key Takeaways

ISO 42001 certification depends as much on who issues the certificate as on what the organization does to earn it.

  • Accreditation determines certificate value. ISO/IEC 42006:2025 sets requirements for bodies certifying AI management systems, and European co-operation for Accreditation made it mandatory for accrediting those bodies in November 2025. Verify accreditation on the accreditation body’s own register, and confirm ISO/IEC 42001 sits explicitly in scope.
  • Applicant status and pilot participation are not accreditation. Both appear in vendor material as though they were. Ask for the accreditation certificate directly.
  • The audit has two stages. Stage 1 is a readiness review of documentation, scope and internal audit history. Stage 2 tests implementation and effectiveness. Major nonconformities must close before a certificate issues.
  • Internal audit and management review are hard gates. Both are mandatory, both must precede the certification audit, and both need records. A strong control environment with no internal audit history is not ready.
  • The AI impact assessment is the distinctly new requirement. It examines effects on individuals, groups and society rather than on the organization, and it is the element that ISO 27001 experience does not prepare a team for.
  • Scope discipline beats scope ambition. A narrower AIMS scope that can be evidenced reaches a certificate faster than a broad one that cannot, and scope expands at recertification.

FAQs

How does an organization get ISO 42001 certified? Build an AI inventory and define the AIMS scope, run a gap analysis against the clause requirements and applicable Annex A controls, build the management system, complete risk and AI impact assessments, run an internal audit and a management review with records, then engage an accredited certification body for a two-stage audit. Stage 1 reviews readiness and documentation; Stage 2 tests implementation and effectiveness. A certificate runs on a three-year cycle with surveillance audits in between.

Who can issue an ISO 42001 certificate? Only a certification body accredited to certify AI management systems. Those bodies audit under ISO/IEC 17021-1 supplemented by ISO/IEC 42006:2025, and they are accredited by national accreditation bodies such as ANAB, UKAS and RvA. Verify the accreditation on the accreditation body’s public register and confirm ISO/IEC 42001 is explicitly within the accredited scope. A body listed as an applicant, or as a participant in an accreditation pilot, is not accredited.

How long does ISO 42001 certification take? It depends on AIMS scope, the number and diversity of AI systems in scope, and whether the organization already runs a certified ISO 27001 management system, which shortens the path materially because the Clause 4 through 10 scaffolding is shared. Two constraints cannot be compressed with budget: internal audit and management review must actually happen before the certification audit, and evidence of operational controls accrues on calendar time.

What is the difference between ISO 42001 and the EU AI Act? ISO 42001 is a voluntary, certifiable management system standard. The EU AI Act is binding law with obligations that vary by risk classification. Certification does not satisfy the Act, and complying with the Act does not produce a certificate. An AIMS designed to generate the evidence both regimes require avoids running two parallel programmes, which is the efficient design.

Does ISO 42001 certify an AI model? No. It certifies the management system that governs how an organization develops, procures, deploys and monitors AI within a defined scope. The scope statement appears on the certificate, and it is usually narrower than the entire organization. Buyers evaluating a certificate should read the scope rather than assuming enterprise-wide coverage.