Written and maintained by CASRAI Editorial Board
Last updated
Organisations evaluating ISO/IEC 42001 certification often start from a mistaken premise: that it certifies an AI model, or a specific AI-powered product, as safe or compliant. It does not. ISO/IEC 42001:2023 is a management system standard — it specifies requirements for how an organisation governs its own development, provision, or use of AI systems, in the same structural family as ISO/IEC 27001 (information security) or ISO 9001 (quality). Certification tells a customer, regulator, or partner that the organisation runs a documented, auditable process for identifying AI-related risks and managing them consistently, not that any particular model has been evaluated or approved.
This guide covers what the standard actually requires, the real certification path from first gap assessment to certificate in hand, a realistic timeline, and what the Annex A control areas cover at a high level.
What ISO/IEC 42001 Actually Certifies
Published in December 2023, ISO/IEC 42001 is the first international standard for an Artificial Intelligence Management System (AIMS). It specifies requirements for establishing, implementing, maintaining, and continually improving a management system for the responsible development, provision, or use of AI within an organisation, following the same plan-do-check-act structure used across other ISO management-system standards. The standard applies to organisations of any size or sector that develop, provide, or use AI systems — it does not single out a particular type of model, deployment context, or risk tier.
The distinction matters in practice. An organisation can hold ISO/IEC 42001 certification while its underlying models change, are retired, or are replaced entirely, because what is certified is the governance process wrapped around those systems — the policies, risk assessments, role definitions, and monitoring — not a fixed technical artefact. This is also why ISO/IEC 42001 certification is a different kind of claim from a specific AI governance credential held by an individual professional: it is an organisational certification, assessed by an accredited third-party certification body against a fixed set of requirements and controls, not a training-based qualification.
The Certification Path
The path to certification follows a sequence that is broadly consistent across the certification bodies and consultancies that work in this space, even though none of it is mandated word-for-word by the standard itself:
1. Gap assessment
A structured comparison of current AI governance practice against ISO/IEC 42001’s clauses and Annex A controls, identifying what already exists (often reusable from an existing ISO 27001 or quality management system), what is missing, and what needs to change before a credible AIMS can be documented.
2. Implementation
Building the AIMS itself: an AI policy, a defined scope statement, risk assessment and AI impact assessment methodologies, a Statement of Applicability explaining which Annex A controls apply and why, role and responsibility definitions, and the operational records (an AI system inventory, data provenance documentation, incident logs) that make the system auditable rather than theoretical.
3. Internal audit and management review
Before inviting an external auditor in, the organisation runs its own internal audit against the AIMS and holds a formal management review, the standard mechanism ISO management systems use to confirm leadership has actually engaged with the results rather than delegated the whole exercise.
4. Stage 1 external audit
The certification body reviews documentation and AIMS design: does the AI policy, scope statement, risk methodology, Statement of Applicability, and role definitions exist and hold together internally. Stage 1 typically surfaces a short list of gaps — incomplete AI system inventories and inconsistent use-case records are common findings — rather than missing policies outright.
5. Stage 2 external audit
The operational test: the auditor samples evidence, interviews staff, observes processes, and reviews audit trails and completed impact assessments to confirm the organisation actually runs the system its documentation describes, not just that the documentation exists.
6. Certification decision, surveillance, and recertification
Following a successful Stage 2 (and resolution of any nonconformities raised), the certification body issues the certificate. As with other ISO management-system certifications, it is typically valid for three years, maintained through annual surveillance audits that sample a subset of the AIMS rather than reassessing everything, and followed by a full recertification audit at the end of the three-year cycle.
A Realistic Timeline
Certification bodies and consultancies that specialise in ISO/IEC 42001 commonly report a total timeline of roughly six to twelve months from the first gap assessment to certificate issuance for an organisation starting without a mature adjacent management system. Within that:
- Gap assessment and initial risk analysis: commonly a few weeks.
- AIMS design and policy development: commonly several weeks to a few months, depending on how much of the governance structure already exists.
- Monitoring, documentation, and internal audit setup: run partly in parallel with implementation.
- Gap between Stage 1 and Stage 2 audits: commonly reported as four to twelve weeks, giving the organisation time to close Stage 1 findings before the operational audit. This gap must not exceed six months, or Stage 1 has to be repeated in full.
Organisations that already hold ISO/IEC 27001 or a comparable mature management system tend to move faster, because the organisational scaffolding — document control, internal audit process, management review cadence — already exists and does not need to be built from scratch. These figures come from certification-body and consultancy reporting rather than from the standard itself, which does not prescribe a timeline; actual duration depends heavily on how much AI governance infrastructure the organisation already has in place.
Annex A Controls at a High Level
Annex A of ISO/IEC 42001 sets out 38 controls organised into nine categories, numbered A.2 through A.10 (there is no A.1). An organisation does not need to implement every control — the Statement of Applicability produced during implementation records which controls apply given the organisation’s actual AI activities, and which are excluded and why. At a high level, the nine categories are:
- A.2 — Policies related to AI. Documenting a policy (or policies) for the development or use of AI systems, and determining how existing policies — information security, privacy, ethics — already apply versus where AI-specific policy is genuinely new.
- A.3 — Internal organisation. Defined roles, responsibilities, and reporting lines for AI governance, including a route for staff to raise AI-related concerns.
- A.4 — Resources for AI systems. Identifying and documenting the resources an AI system actually depends on: data, tooling, compute infrastructure, and the human expertise required to run and oversee it.
- A.5 — Assessing impacts of AI systems. A structured process for evaluating the consequences an AI system may have for individuals and society across its lifecycle, not just at deployment.
- A.6 — AI system life cycle. Managing the distinct stages of development, deployment, operation, and monitoring, with verification built in at each stage rather than only at the end.
- A.7 — Data for AI systems. Requirements around data quality, provenance, acquisition, and preparation — the record-keeping that lets an organisation actually answer where its training or operational data came from.
- A.8 — Information for interested parties. What gets communicated to users and other stakeholders about an AI system, including how incidents are communicated when something goes wrong.
- A.9 — Use of AI systems. Processes that keep deployment and operation aligned with the system’s intended purpose and the organisation’s own policies, rather than drifting into unreviewed use cases.
- A.10 — Third-party and customer relationships. How responsibility for AI-related risk is allocated between the organisation and its suppliers, partners, and customers — relevant wherever an organisation builds on a third-party model or provides AI capability to others.
Who Should Consider Certification
ISO/IEC 42001 certification tends to make sense for organisations that develop AI systems for others, provide AI-enabled products or services under contracts that already reference security or quality certifications, or operate in sectors where a customer or regulator will accept — or require — third-party assurance over self-attestation. It is a heavier undertaking than a policy document or an internal checklist, and organisations early in their AI governance work are often better served by first building the underlying practices — an AI use inventory, a risk assessment method, a written AI policy — before committing to an external audit against them.
Where NIKOLAI Fits
Certification tells an outside party that an organisation’s AI management system meets a fixed set of requirements. It does not, on its own, tell that party which specific safety commitments, evaluation practices, or disclosure elements the organisation’s own frameworks actually contain, or how those compare to what other AI developers publish. NIKOLAI is CASRAI’s open dictionary of frontier-AI-safety terminology — capability thresholds, safety cases, incident reporting, evaluator independence, and related elements — each with a stable identifier and a crosswalk showing how major AI labs and governments use the concept in their own published frameworks. For an organisation documenting its AIMS scope, risk methodology, or Statement of Applicability under ISO/IEC 42001, having a consistent, citable vocabulary for the safety concepts referenced inside that documentation is a genuinely useful adjacent resource, independent of certification itself.
Frequently Asked Questions
Does ISO/IEC 42001 certify that our AI system is safe?
No. It certifies that the organisation operates a documented management system for governing how it develops, provides, or uses AI — the processes around the system, not a technical evaluation of any specific model’s safety or performance.
Is ISO/IEC 42001 certification the same as an individual AI governance credential?
No. Individual professional credentials in AI governance certify a person’s knowledge. ISO/IEC 42001 certification is an organisational certification, issued to a company or institution by an accredited third-party certification body after an external audit of its management system.
Do we need to implement all 38 Annex A controls?
Not necessarily. The Statement of Applicability produced during implementation documents which controls apply to the organisation’s actual AI activities and which are justifiably excluded; the certification body then audits against that documented scope.
How long does certification actually take?
Certification bodies and consultancies working in this space commonly report roughly six to twelve months from the first gap assessment to certificate issuance, with organisations that already hold a mature ISO 27001 or comparable system typically moving faster. The standard itself does not set a fixed timeline.
Does certification expire?
As with other ISO management-system certifications, it is typically issued for a three-year cycle, maintained through annual surveillance audits, with a full recertification audit required at the end of the cycle.







