Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How does the ISO 42001 certification audit process work?
Last verifiedISO 42001 certification uses Stage 1 documentation review, Stage 2 implementation audit, then a three-year certificate with annual surveillance. NCs require CAPA. Not legal advice.
Certification process, last verified 10 September 2026 against ISO/IEC 17021-1 and ISO/IEC 42001:2023. Distinguishes accredited vs unaccredited certificates and auditor vs consultant roles. Not legal advice.
Accredited vs unaccredited certificates
An accredited certificate is issued by a certification body listed on a national accreditation body register for ISO/IEC 42001 scope, recognised through IAF arrangements where applicable. An unaccredited 'certificate' from a body not on those registers may have no market recognition — treat as UNKNOWN until verified. Last verified 10 September 2026.
- Verify on IAF CertSearch or national AB site before relying on any certificate.
- Marketing PDFs are not substitutes for register entries.
Stage 1 and Stage 2
| Stage | Focus | Typical outcome |
|---|---|---|
| Stage 1 | Documentation, scope, readiness | Major gaps flagged before Stage 2 |
| Stage 2 | Implementation sampling, interviews, records | Certificate, NCs, or deferral |
| Surveillance | Ongoing operation, prior NC closure | Continued certification |
| Recertification | Full system review before cycle end | New three-year cycle if successful |
Nonconformities and CAPA
- Major NC: systemic failure or absence of a required element — usually needs corrective action before certificate.
- Minor NC: isolated lapse — CAPA with evidence of closure at surveillance.
- Opportunities for improvement: advisory, not mandatory closure for certification.
- CAPA must show root cause and operation over time, not a one-line fix on audit day.
Auditor vs consultant — independence
ISO/IEC 17021-1 requires certification bodies to manage impartiality. A firm that helped YOU write policies or implement controls should not audit the same scope as YOUR CB. Consultants prepare; CB auditors attest. Same brand with separate legal entities still needs verification on the register.
What to do now
- Confirm YOUR CB's accreditation scope includes ISO/IEC 42001 for YOUR sites.
- Separate consultant engagements from the CB contract in writing.
- Prepare NC response templates before Stage 2.
Checklist
- ☐ CB accreditation verified on public register?
- ☐ Stage 1 report findings closed or accepted with plan?
- ☐ CAPA owners named for any open NCs?
- ☐ Surveillance dates in calendar with evidence refresh plan?
Where this shows up in ShipReady Metrics
Met-verdict overlay and evidence review give auditors timestamped samples of control operation. ShipReadyMetrics is not the CB, does not close NCs, and does not issue certificates.