The ISO 42001 Certification Path
ISO/IEC 42001 is the certifiable management system standard for artificial intelligence, and the path to a certificate has five parts: scope the AI management system, build it, audit it internally, pass a two-stage certification audit with an accredited body, then maintain the certificate through annual surveillance. The companies that need it are the ones selling AI into enterprise and regulated buyers, and the ones that need it soonest are already seeing AI governance sections in procurement questionnaires. From a standing start, plan six to twelve months and $45,000 to $130,000 through certification; with an existing ISO 27001 program, both numbers drop by roughly a third to a half. One boundary up front: BD Emerson implements and prepares, and an accredited certification body issues the certificate.
Who needs it, and when
Three buyer groups are driving demand. Enterprise procurement teams have started adding AI governance sections to vendor questionnaires, and a certificate answers those questions without a meeting. Regulated buyers, banks, insurers, and healthcare systems among them, are pushing their model risk and third-party risk frameworks onto AI vendors contractually, and a certified management system is the artifact their vendor risk teams can file. And European-facing companies are positioning for the EU AI Act, whose obligations phase in through 2026 and 2027. The timing logic mirrors SOC 2 a decade ago: the certificate takes six to twelve months to obtain, so the moment AI governance language appears in your pipeline, the clock is already running. Vendors who wait for a signed requirement discover that procurement does not pause while a management system gets built and operated long enough to audit.
Scoping the AIMS
The unit of certification is the AI management system, or AIMS, and scope is the first real decision. Which AI systems are covered, in which role, as a provider building models, a deployer running someone else's, or both, and across which lifecycle stages. Start from an AI inventory, because most organizations discover systems they forgot they were running, including the ones embedded in vendor products. Then scope deliberately: the product your customers are asking about, not every internal copilot experiment. An overscoped AIMS costs more to build, more to audit, and produces a certificate no more persuasive than a tight one. The constraint on tightness is honesty: the scope statement must still cover what your customers are actually buying, or the certificate fails at its only job.
The relationship to ISO 27001
ISO 42001 follows the same Annex SL structure as ISO 27001: clauses 4 through 10 running from context to continual improvement, with Annex A supplying 38 AI-specific controls across policy, roles, impact assessment, data governance, the model lifecycle, third parties, and decommissioning. If you already run a certified ISMS, roughly half the management system work already exists: document control, internal audit machinery, management review, corrective action, supplier management. Most organizations in that position bolt the AIMS onto the existing system rather than building a second one, and certification bodies discount integrated audits because the shared clauses get audited once. Companies holding neither standard increasingly pursue both together on one management system, which costs meaningfully less than running two sequential programs and ends with both credentials in the same audit cycle.
The relationship to the EU AI Act
A 42001 certificate is not EU AI Act compliance, and any vendor implying otherwise is selling ahead of the law. The Act imposes legal obligations by risk class, and the harmonized standards that would grant a presumption of conformity are still working through the European standardization process. What the certificate does provide is the management scaffolding the Act assumes: risk management, data governance, human oversight, logging, post-market monitoring, all running as a system with owners and records. Organizations that build a real AIMS find the Act's high-risk requirements land on existing structure instead of bare ground, which is why we treat them as one program with two outputs, and why EU AI Act advisory and 42001 implementation share a team here.
Implementation, stage by stage
- Inventory and impact assessment: catalog the AI systems, classify each by role and risk, and run impact assessments on the ones in scope
- Risk assessment and treatment: identify AI-specific risks, from training data provenance to model behavior in production, and decide treatments
- Statement of Applicability: justify each Annex A control as applicable or excluded, since this is the document Stage 1 auditors read first
- Controls and lifecycle: policies, an accountable owner for every system, data governance, model documentation, human oversight, monitoring, and decommissioning
- Operate and gather evidence: run the system long enough to produce real records, because auditors certify what has happened, not what is planned
- Internal audit and management review: the Clause 9.2 audit performed by someone independent of the build, with findings closed before the certification body arrives
From a standing start this takes four to nine months depending on AI footprint and how much management system muscle already exists. The most common failure is treating it as a documentation project. An AIMS written in a quarter but never operated produces Stage 2 nonconformities on evidence, which are the hardest kind to fix quickly, because the only remedy is time.
The certification audit
Certification comes only from an accredited certification body. Accreditation for 42001 is still rolling out, and fewer bodies hold it than for ISO 27001, so verify two things before signing: that the body's accreditation from ANAB, UKAS, or a peer actually covers ISO/IEC 42001, and that the auditors assigned have assessed an AIMS before rather than learning on yours. Stage 1 is a documentation and readiness review, typically remote across one or two days, ending in a list of concerns to resolve. Stage 2 follows weeks later and is the full operating audit: interviews, records, and control evidence across the scope. Nonconformities become findings, and major ones must be closed before the certificate issues. The certificate then runs three years, with surveillance audits in years two and three and recertification at the end of the cycle. Stated plainly for the second time because it matters: BD Emerson is not a certification body. We build, prepare, and internally audit AI management systems, and an accredited registrar issues the certificate. A firm offering to do both sides in one contract is grading its own homework, and buyers eventually notice.
Timeline and cost, realistically
Implementation with consultant support runs $25,000 to $70,000, scaled by AI footprint, headcount, and whether an ISMS already exists. An outsourced Clause 9.2 internal audit adds $5,000 to $15,000. Certification body fees follow auditor-day math at day rates of $1,200 to $2,000: expect $10,000 to $30,000 for Stage 1 plus Stage 2 at small and mid-market scope, carrying a modest premium over comparable ISO 27001 audits while accredited capacity remains thin, then $5,000 to $15,000 per surveillance year. Add compliance platform costs if your tooling charges per framework, and training for the people who will own the system. Total through the certificate: $45,000 to $130,000 for most mid-sized programs, on a timeline of six to twelve months from a standing start or four to seven with a certified ISMS in place. Certifying an immature program is possible and pointless: the certificate reads the same, but the surveillance audits arrive on schedule and the customers arrive with questions, and both find whatever the rush left behind.
Where BD Emerson fits
Our ISO 42001 consulting practice takes the AIMS from inventory through Stage 2 readiness, inside a broader AI governance practice that builds programs engineering teams can actually operate rather than binders they route around. We help select and manage the certification body from your side of the table, and we stay out of the registrar's chair on purpose. If AI governance questions have started appearing in your deals, start with the scoping conversation, because every number above narrows considerably once someone has seen your actual AI inventory.
