Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How does the ISO 42001 certification audit process work?

Last verified

ISO 42001 certification uses Stage 1 documentation review, Stage 2 implementation audit, then a three-year certificate with annual surveillance. NCs require CAPA. Not legal advice.

Certification process, last verified 10 September 2026 against ISO/IEC 17021-1 and ISO/IEC 42001:2023. Distinguishes accredited vs unaccredited certificates and auditor vs consultant roles. Not legal advice.

Accredited vs unaccredited certificates

An accredited certificate is issued by a certification body listed on a national accreditation body register for ISO/IEC 42001 scope, recognised through IAF arrangements where applicable. An unaccredited 'certificate' from a body not on those registers may have no market recognition — treat as UNKNOWN until verified. Last verified 10 September 2026.

  • Verify on IAF CertSearch or national AB site before relying on any certificate.
  • Marketing PDFs are not substitutes for register entries.

Stage 1 and Stage 2

Audit stages under ISO/IEC 17021-1 (not YOUR audit plan)
StageFocusTypical outcome
Stage 1Documentation, scope, readinessMajor gaps flagged before Stage 2
Stage 2Implementation sampling, interviews, recordsCertificate, NCs, or deferral
SurveillanceOngoing operation, prior NC closureContinued certification
RecertificationFull system review before cycle endNew three-year cycle if successful

Nonconformities and CAPA

  • Major NC: systemic failure or absence of a required element — usually needs corrective action before certificate.
  • Minor NC: isolated lapse — CAPA with evidence of closure at surveillance.
  • Opportunities for improvement: advisory, not mandatory closure for certification.
  • CAPA must show root cause and operation over time, not a one-line fix on audit day.

Auditor vs consultant — independence

ISO/IEC 17021-1 requires certification bodies to manage impartiality. A firm that helped YOU write policies or implement controls should not audit the same scope as YOUR CB. Consultants prepare; CB auditors attest. Same brand with separate legal entities still needs verification on the register.

What to do now

  • Confirm YOUR CB's accreditation scope includes ISO/IEC 42001 for YOUR sites.
  • Separate consultant engagements from the CB contract in writing.
  • Prepare NC response templates before Stage 2.

Checklist

  • ☐ CB accreditation verified on public register?
  • ☐ Stage 1 report findings closed or accepted with plan?
  • ☐ CAPA owners named for any open NCs?
  • ☐ Surveillance dates in calendar with evidence refresh plan?

Where this shows up in ShipReady Metrics

Met-verdict overlay and evidence review give auditors timestamped samples of control operation. ShipReadyMetrics is not the CB, does not close NCs, and does not issue certificates.

Frequently asked questions