AI governance has moved from a talking point to a purchasing condition. ISO/IEC 42001:2023, the first certifiable standard for AI management systems, is now appearing in enterprise procurement questionnaires, vendor-risk forms, and tender criteria, and several major cloud and AI providers have already achieved certification.

Yet industry estimates still put the number of certified organizations in the low hundreds worldwide, which means a certificate today is a genuine differentiator rather than a box everyone has ticked. This guide, from the AI Governance Certification Institute (AIGCI), lays out exactly how an organization gets ISO 42001 certified, from scoping your AI management system to holding the certificate and keeping it.

To get ISO 42001 certified, an organization implements an AI management system, audits it internally, then passes a two-stage audit by an accredited certification body, which issues a certificate valid for three years and maintained through annual surveillance.

What organizational certification means and what it does not

First, a distinction that saves a lot of confusion. There are two different things people call ISO 42001 certification:

  • Organizational certification. A certificate awarded to a company after an accredited body audits its AI management system. This is what this guide covers.
  • Professional certification. A credential an individual earns, such as Foundation or Lead Implementer, by passing an exam. It is not the same thing, though your organization will need people who hold it.

Organizational certification certifies the AIMS you certify, the actual management system your company builds and runs, not the knowledge of any one person. Keep that difference clear and every step below makes sense. It also explains why the project is owned by the organization rather than by an individual: the certificate says something about the company, so the whole company has to stand behind it, from the board that sets the mandate to the teams that operate the AI day to day.

Before you begin: five questions worth answering

A little clarity up front prevents most of the pain later. Before you start the journey, answer these five questions honestly:

  • What is our role: do we build AI, provide it in a product, or use tools built by others?
  • Which AI systems are in scope for certification, and which are deliberately out?
  • Who will own the AI management system day to day, once the project is over?
  • What governance do we already have, such as ISO 27001 or a risk function, that we can reuse?
  • Why are we certifying now: procurement pressure, regulation, competitive advantage, or all three?

Write the answers down. They become the backbone of both your AIMS scope and the business case you will use to fund the project.

The ISO 42001 certification journey, step by step

The path runs in three phases: prepare, certify and maintain. The figure below shows the whole journey at a glance, and the steps are explained beneath it.

Figure 1. The ISO 42001 certification journey, from scoping the AIMS to staying certified.

Phase 1: Prepare your AI management system

Most of the work happens here, before any external auditor is involved.

  1. Understand the standard and define your scope. Decide your role in the AI value chain, whether you develop, provide, or use AI, and set the boundary of the AIMS.
  2. Run a gap analysis. Compare what you do today against the standard. This typically takes a few weeks and produces your to-do list.
  3. Implement the AIMS. Put policies, roles, risk and impact assessments, controls, and documentation in place. This is the longest stretch, commonly three to twelve months depending on your size.
  4. Run an internal audit and management review. Check the system against the standard yourself first. This first-party audit is required by Clause 9.2 and is the rehearsal for the real thing.

Phase 2: Pass the certification audit

Now an external, accredited body assesses you in two stages.

  1. Choose an accredited certification body. Not every certifier is accredited for ISO 42001. Confirm accreditation before you commit; our guide on choosing a certification body covers what to check.
  2. Stage 1 audit. A documentation and design review, usually one to two days, confirming your AIMS is ready to be assessed in practice.
  3. Stage 2 audit. A deeper assessment of how the system actually operates, typically several days. For the full detail of both stages, see the Stage 1 and 2 audit.
  4. Certification decision. The auditor recommends a decision, any nonconformities are resolved, and the certificate is issued.

Phase 3: Maintain your certification

A certificate is not the finish line. It is valid for three years, subject to annual surveillance audits, with a full recertification at year three. In practice you keep the AIMS running, keep the evidence current and keep improving. Certification is a commitment the certifier keeps checking, not a one-time award.

The organizations that find surveillance easy are the ones that built a system they actually use, rather than a set of documents assembled to pass an audit and then quietly abandoned.

Who owns the certification project

Certification is a team effort, and clear ownership is what keeps it moving. A typical project has four roles:

  • Executive sponsor. Sets the mandate, funds the work, and unblocks decisions.
  • AIMS owner. Accountable for the management system day to day, during the project and long after.
  • Lead Implementer. Builds the system, writes the documentation, and prepares the evidence for audit.
  • Internal auditor. Tests the system against the standard before the external certifier does.

In a small company one person may wear several of these hats; in a large one each may be a team. Either way, every role should be named, because Clause 5.3 of ISO 42001 expects roles, responsibilities and authorities to be assigned and communicated. Ambiguity here is one of the most common reasons projects stall.

How long ISO 42001 certification takes, and what drives it

There is no single answer, because timelines scale with the size of your organization and the maturity of your existing governance. As a rough guide:

Stage

Typical duration

What decides it

Gap analysis

2 to 4 weeks

Complexity of your AI use

Implementation

3 to 12 months

Organization size and starting maturity

Internal audit

About 1 week

Scope of the AIMS

Stage 1 audit

1 to 2 days

Documentation readiness

Stage 2 audit

Several days

Number of AI systems and controls

For a full breakdown of what it costs as well as how long it takes, including the factors that move the numbers, see our dedicated guide to the cost and timeline.

The single biggest lever is how much governance you already have: an organization with a mature ISO 27001 system, for instance, will move considerably faster.

If you already hold ISO 27001, you are closer than you think

Organizations with a mature ISO 27001 information security system have a genuine head start, because ISO 42001 is built on the same management-system structure.

The leadership, planning, risk, internal-audit and improvement machinery you already run carries straight over; what you add is the AI-specific content, such as impact assessment and AI data governance.

Our comparison of how the two standards relate breaks down exactly what transfers and what is new, and for many organizations it turns a daunting project into a manageable extension of what they already do.

Choosing a certification body that will actually count

The value of your certificate depends on who issues it. Two checks matter most:

  • Accreditation. Confirm the body is accredited by a recognised accreditation body, such as UKAS or an equivalent, with ISO 42001 specifically in its scope.
  • Recognition. Accredited certification is accepted internationally through mutual-recognition arrangements, as the accreditation forum explains, so an accredited certificate travels with your business.

An unaccredited certificate may be cheaper and faster, but it will not carry the same weight with the customers and regulators you are trying to reassure.

Why organizations are pursuing ISO 42001 certification now

The business case has sharpened quickly. Three forces are pushing organizations toward certification:

  • Procurement pressure. Enterprise buyers increasingly ask vendors for third-party proof that their AI is governed, and ISO 42001 is becoming the standard answer.
  • Regulation. Frameworks such as the EU AI Act expect organizations to govern AI, and a certified AIMS is strong evidence of exactly that.
  • Trust and advantage. With relatively few organizations certified so far, an early certificate is a visible signal of responsible AI that competitors cannot yet match.

Put together, certification is shifting from a nice-to-have to a condition of doing business in AI and the organizations moving first are setting the bar.

For a business that sells AI-enabled products, a certificate can shorten sales cycles, unlock enterprise deals that require governance evidence and reduce the burden of answering the same vendor-risk questionnaires over and over. The credential does commercial work, not just compliance work.

Common mistakes that slow certification down

Most delays are avoidable. Watch for these:

  • Scoping too broadly at first, which turns a manageable project into an unmanageable one.
  • Writing policies nobody follows, so the Stage 2 audit finds a gap between paper and practice.
  • Skipping or rushing the internal audit, which is the cheapest place to catch problems.
  • Choosing an unaccredited body to save time, then finding the certificate is not recognised.
  • Treating certification as a project that ends, rather than a system that runs.

Frequently asked questions

How long does it take to get ISO 42001 certified?

For most organizations, several months to a year. Implementation is the longest phase, usually three to twelve months, followed by the two-stage audit. Timelines shorten considerably if you already run a mature management system such as ISO 27001.

Do we need a Lead Implementer to get certified?

Not by rule, but in practice yes. Building an AIMS that passes audit needs someone who knows the standard well and a certified Lead Implementer is the usual choice to lead the work, whether an employee or a consultant.

What is the difference between Stage 1 and Stage 2?

Stage 1 reviews your documentation and design to confirm you are ready. Stage 2 assesses how the AIMS actually operates in practice. You must pass both and Stage 2 is the more demanding of the two.

How long is the certificate valid?

Three years, provided you pass annual surveillance audits during the cycle. A recertification audit at the end renews it for another three years.

Does certification prove our AI is compliant with the law?

No. Certification proves you have a management system that governs AI to the standard. It supports legal compliance and reassures regulators, but it is not a substitute for meeting specific legal obligations in your jurisdiction.

Can a small company or startup get certified?

Yes. ISO 42001 scales to the organization. A startup with one AI product can certify a tight, well-defined scope faster than a large enterprise with dozens of systems. The standard asks for governance proportionate to your risk, not a fixed amount of bureaucracy, which makes early certification realistic for smaller AI companies.

What happens if the audit finds a problem?

Minor issues, called nonconformities, are normal and are simply corrected within an agreed time. Only serious, unresolved problems block certification. The Stage 1 audit exists partly to surface issues early, so few organizations are genuinely surprised at Stage 2.

Give your certification project the right people

Certification is won or lost in the implementation, and implementation needs people who know the standard from the inside. AIGCI's ISO 42001 Lead Implementer training prepares your team to build and run an AI management system that stands up to a Stage 2 audit, so your certification project starts with the expertise it depends on rather than learning the standard on the job.

Whether you train an internal owner or bring in a certified consultant, the principle is the same: skilled people are the shortest path to a certificate that holds. To see how the institute supports organizations pursuing certification, read more about the institute.