The ISO 42001 certification review is a two-stage audit that tests whether your AI management system (AIMS) is documented, implemented, and operating the way the standard requires. ISO/IEC 42001:2023, published in December 2023, is the first international standard for governing artificial intelligence, and the number of organizations pursuing it is growing as customers and regulators start to ask for evidence of AI governance. Most buyers preparing for the audit are not asking how to build the AIMS. They are asking what the auditor will actually look at, how long each stage takes, and what happens after the certificate is issued. This piece answers those three questions in order.
One correction worth making up front, because search queries show confusion on this point: ISO/IEC 42001:2023 defines 38 controls organized under 9 control objectives in Annex A, not the 70 controls sometimes cited. Getting that number right matters, because the Statement of Applicability the auditor reviews is built directly against those 38 controls.
Why the ISO 42001 Certification Review Matters Now
ISO 42001 is the first certifiable AIMS standard, which means there is limited precedent for what a “good” AI governance program looks like in an audit. Certification bodies are still refining how they assess AI-specific controls, and organizations often need to interpret requirements rather than copy a settled playbook. That uncertainty is exactly why understanding the ISO 42001 certification review ahead of time reduces risk. [Likely] An organization that walks into Stage 1 knowing what evidence the auditor expects avoids the most common outcome for first-time applicants: a delayed Stage 2 while gaps get remediated.
The certification also functions as market access. As enterprise buyers add AI governance questions to vendor due diligence, an accredited ISO 42001 certificate becomes a way to answer those questions once instead of repeatedly. The review is the gate to that signal, so the quality of your preparation determines whether the certificate arrives on your timeline or slips a quarter.
How the Two-Stage Certification Review Works
The ISO 42001 certification review follows a two-stage audit conducted by an accredited certification body. The two stages test different things: Stage 1 tests whether your documentation is ready, and Stage 2 tests whether your AIMS actually operates as documented.
| Stage | What it tests | Typical duration | Frequency |
|---|---|---|---|
| Stage 1 | AIMS documentation and readiness | 1 to 2 days | Year 1 only |
| Stage 2 | Operational effectiveness of controls | Several days, scaled to scope | Year 1 |
| Surveillance | Continued conformity | A fraction of Stage 2 | Years 2 and 3 |
| Recertification | Full AIMS over the cycle | Similar to Stage 2 | Year 3 |
The table shows the rhythm of a full certification cycle, but the durations depend on your scope. Audit effort scales with the number of employees in scope, the number and complexity of AI systems, operational complexity, and the number of locations. A single-product team with one AI system in one location sits at the low end. A multi-system, multi-location deployment sits well above it. Certification bodies estimate the effort per organization, which is why published day counts are ranges rather than fixed figures.
Stage 1: The Document Review
Stage 1 assesses whether your organization is ready for the full audit. The auditor reviews your AIMS documentation against ISO 42001 requirements: scope definition, AI policy, risk assessment methodology, AI impact assessments, the Statement of Applicability, internal audit records, and management review documentation. This stage runs one to two days and may be on-site or remote.
The auditor returns a report with one of three outcomes: proceed to Stage 2, proceed with minor concerns to address, or delay Stage 2 until significant gaps are remediated. Stage 1 is required only in Year 1 of the certification lifecycle. Treat it as a checkpoint rather than a formality. A delayed Stage 2 is the single most avoidable cause of a slipped certification date, and it almost always traces back to documentation that was thin before the auditor arrived.
Stage 2: The Main Certification Audit
Stage 2 verifies that the AIMS is implemented and operating. Auditors interview management and AI teams, review records, observe processes, and perform technical assessments of AI systems and controls. They use risk-based sampling, giving high-risk AI systems more attention while sampling other areas to confirm consistent implementation across the AIMS.
Stage 2 is where design meets reality. Documentation that looked complete in Stage 1 gets tested against what the organization actually does. If a policy says AI models are reviewed before deployment, the auditor will ask to see the review records for a model that shipped last quarter. The organizations that clear Stage 2 cleanly are the ones whose evidence was generated by real operations, not assembled for the audit.
What Auditors Evaluate During Stage 1 and Stage 2
During the ISO 42001 certification review, certification bodies examine specific elements of your AIMS across both stages. Knowing these categories lets you assemble evidence against each one before the review rather than scrambling during it.
AI Governance Framework and Policies
Auditors review your AI policy for top-management approval and alignment with business strategy, and they check that it is reviewed at planned intervals. They look for policies covering AI development, acceptable use, security, bias mitigation, and change management. Integration with your existing organizational policies receives scrutiny, because an AI policy that contradicts the rest of the governance stack signals a program bolted on rather than built in.
Risk Assessment and Impact Analysis
Your documented AI risk assessment methodology must produce results that are consistent, valid, and comparable across assessments. Auditors examine risk identification, likelihood and consequence analysis, risk level determination, and treatment prioritization. AI impact assessments require stakeholder mapping, evaluation of potential harms, ethical considerations, and mitigation strategies. This is the area most specific to ISO 42001, because it is where AI-related harm, not just information security risk, has to be addressed directly.
AI Lifecycle Controls and Data Management
Auditors examine documentation across the AI lifecycle: concept and design, data acquisition, model development, validation, deployment, monitoring, incident response, and retirement. Data management processes must detail acquisition sources, quality requirements, provenance tracking, and preparation methods. The lifecycle view is what separates ISO 42001 from a generic management system audit, because it forces evidence at each phase rather than a single point-in-time snapshot.
Human Oversight, Transparency, and Monitoring
Auditors verify defined roles and responsibilities across the AI system lifecycle, including AI safety and security, and they confirm governance committee structures. They look for evidence that users are informed about AI usage and that reporting mechanisms exist for adverse effects. They also assess monitoring methodologies, key performance indicators, internal audit programs, management review records, and corrective action documentation. These records are also what surveillance audits sample in later years, so the systems that produce them need to run continuously, not just before an audit.
What Ongoing Compliance Requires After Certification
The ISO 42001 certification review does not end at the certificate. It is valid for three years, and keeping it valid is where most of the real work lives. This is the question buyers ask most often before committing, and the answer is that certification is a cycle, not an event.
Surveillance audits occur in Years 2 and 3 to verify continued conformity. Each surveillance audit samples internal audits, management review, corrective actions on previous nonconformities, complaint handling, AIMS effectiveness, and selected operational controls. A recertification audit before the three-year certificate expires confirms the continued suitability of the complete AIMS, assessed across the full cycle rather than a single point in time. Surveillance and recertification are scoped as a fraction of the original audit; the exact effort and fees depend on your scope and your chosen certification body, so confirm them in your contract rather than assuming a fixed percentage.
The practical implication is that the systems generating your audit evidence, internal audits, management reviews, corrective action tracking, monitoring metrics, have to operate on their own schedule between audits. Organizations that treat the AIMS as always-on pass surveillance with sampling. Organizations that let it lapse and rebuild before each audit invite nonconformities. If your team needs a structured way to keep evidence audit-ready between cycles, the CEO’s audit-readiness checklist for ISO 42001 lays out what to maintain.
How to Choose an Accredited Certification Body
The body that issues your certificate is not the same as the firm that helps you prepare for the audit, and the distinction matters. A certification body performs the independent audit and issues the certificate. A readiness partner helps you get ready for it. The two cannot be the same organization for the same scope, because independence is what makes the certificate credible. If you are evaluating who performs your gap analysis and readiness assessment, that is a separate decision covered in ISO 42001 certification readiness and the C3PAO review.
For the certification body itself, accreditation is the first filter. Accredited bodies are evaluated by national accreditation authorities such as UKAS, ANAB, INAB, or SANAS against international standards for competence and impartiality. An accredited certificate is recognized across markets, especially in regulated industries. A non-accredited certificate is issued without that oversight and can create recognition problems with customers, regulators, and industry stakeholders later.
Beyond accreditation, compare bodies on auditor qualifications and sector experience, depth of ISO 42001 knowledge, ability to audit alongside frameworks you already hold, and client references. Ask potential bodies about audit scope and process before you commit. Because ISO 42001 is new, auditor experience with AI systems varies more than it does for mature standards, and that variation shows up directly in how efficient and useful your audit is.
Timeline and Cost Expectations
A full ISO 42001 certification review, from the start of implementation to certificate issuance, typically spans several months to roughly a year, depending on the maturity of your AI governance when you begin. The gap between Stage 1 and Stage 2 usually runs a few weeks and should not stretch past six months. Organizations that already hold ISO 27001 can move faster, because Clauses 4 through 10 of the two standards overlap substantially and existing management-system documentation carries over. The ISO 42001 and ISO 27001 Annex A overlap shows where that reuse applies and where it does not.
Certification cost depends on the same scope factors that drive audit duration: employees in scope, number and complexity of AI systems, and locations. Rather than anchor to a single figure, price it against your actual scope and get quotes from accredited bodies. For a detailed breakdown of what to budget, see the ISO 42001 certification cost breakdown.
Elevate helps organizations prepare for the ISO 42001 certification review, so that Stage 1 does not surface avoidable gaps and Stage 2 tests evidence that already exists. To map your current AI governance against what auditors evaluate, book a readiness call with an Elevate advisor.
Conclusion
The ISO 42001 certification review is predictable once you know its shape: Stage 1 tests your documentation, Stage 2 tests whether your AIMS operates as documented, and the three-year surveillance cycle tests whether it keeps operating. The organizations that clear the review on schedule are the ones whose evidence comes from a governance program that already runs, not one assembled for the audit. The controls under scrutiny, the 38 in Annex A across risk, lifecycle, oversight, transparency, and monitoring, are the same ones the surveillance audits will sample for the next three years.
Preparation is the variable you control. A rigorous internal audit and management review before Stage 1, complete documentation mapped to each control, and a clear-eyed choice of accredited certification body are what separate a clean certification from a delayed one. To prepare against what auditors actually evaluate, book a readiness call with an Elevate advisor.
Key Takeaways
A structured understanding of the ISO 42001 certification review lets your organization prepare against what auditors evaluate rather than guess at it.
- Two stages test two different things: Stage 1 reviews documentation readiness in one to two days; Stage 2 tests operational effectiveness over several days scaled to your scope.
- Annex A has 38 controls under 9 objectives: the Statement of Applicability the auditor reviews is built against those 38 controls, not the 70 sometimes cited.
- Certification is a three-year cycle, not an event: surveillance audits in Years 2 and 3 and a recertification audit before expiry sample the same evidence your program should already produce.
- The certification body is not your readiness partner: the body that audits and certifies must be independent from the firm that helps you prepare, and accreditation through UKAS, ANAB, or similar is the first filter.
- Scope drives timeline and cost: employees, AI systems, complexity, and locations set both audit duration and fees, so price and schedule against your actual scope rather than a fixed figure.
FAQs
Q1. What happens during an ISO 42001 certification review? The ISO 42001 certification review is a two-stage audit by an accredited certification body. Stage 1 checks that your AIMS documentation is complete and ready, usually over one to two days. Stage 2 verifies that the system operates as documented, through interviews, record reviews, process observation, and technical assessment of AI systems. The auditor uses risk-based sampling, focusing on high-risk AI systems, before recommending certification.
Q2. How many controls does ISO 42001 have? ISO/IEC 42001:2023 defines 38 controls organized under 9 control objectives in Annex A. Some sources incorrectly cite 70 or other figures. The 38 controls are what the Statement of Applicability is built against and what auditors assess during the certification review.
Q3. What are the ongoing compliance requirements after ISO 42001 certification? The certificate is valid for three years. Surveillance audits in Years 2 and 3 verify continued conformity by sampling internal audits, management reviews, corrective actions, complaint handling, and selected operational controls. A recertification audit before the certificate expires reassesses the full AIMS across the cycle. In practice, the governance program has to run continuously between audits, because that is what surveillance samples.
Q4. Is ISO 42001 certification faster if we already have ISO 27001? Organizations with ISO 27001 can generally move faster, because Clauses 4 through 10 of the two standards overlap substantially and existing management-system documentation carries over to the AIMS. The AI-specific work, risk and impact assessments for AI systems, lifecycle controls, and Annex A controls, still has to be built, so ISO 27001 shortens the timeline without eliminating the AI governance work.
Q5. Can the same firm prepare us for the audit and certify us? No. The certification body that performs the independent audit and issues the certificate must be separate from any firm that helps you prepare for it. Independence is what makes the certificate credible to customers and regulators. A readiness partner helps you close gaps before the audit; an accredited certification body conducts the audit itself.