Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do you get ISO 42001 certified?
Last verifiedGet ISO 42001 certified by building an AIMS, then passing Stage 1 documentation and Stage 2 implementation audits with an accredited certification body. Cost and timeline vary by scope. Not legal advice.
Certification roadmap, last verified 10 September 2026 against ISO/IEC 42001:2023 and ISO/IEC 17021-1. Distinguishes accredited certification, self-attestation, and readiness-only. Does not issue certificates. Not legal advice.
Accredited certification vs self-attestation vs readiness
Accredited certification: an AB-accredited CB audits YOUR AIMS under ISO/IEC 17021-1 and issues a certificate on a three-year cycle with surveillance. Self-attestation: YOU assert conformity without third-party certificate — may satisfy internal policy but not customer clauses requiring accredited certification. Readiness: gap work before engaging a CB. Last verified 10 September 2026.
- Legal requirement: none to hold any of these — unless YOUR contract names accredited certification.
- Professional standard: ISO/IEC 42001:2023 for the AIMS; ISO/IEC 17021-1 for the CB audit process.
- Best practice: internal audit and management review before Stage 1.
Stage-gated roadmap
Timelines and fees are engagement-specific. National CB fee schedules and consultant day rates vary; this page does not quote dollar figures. Ask shortlisted CBs for written proposals against YOUR scope.
| Stage | What happens | Kind of text |
|---|---|---|
| 0 — Scoping | Define AIMS scope, inventory AI systems, secure leadership | Best practice |
| 1 — Build | Policies, SoA, impact assessments, operational controls | Standard requirement |
| 2 — Internal audit | Clause 9 internal audit and management review | Standard requirement |
| 3 — Stage 1 | CB reviews documentation and readiness | ISO/IEC 17021-1 audit stage |
| 4 — Stage 2 | CB audits implementation; certificate if successful | ISO/IEC 17021-1 audit stage |
| 5 — Surveillance | Annual surveillance audits; recertification at cycle end | ISO/IEC 17021-1 cycle |
What to do now
- Complete the readiness-checklist self-assessment against clauses 4–10.
- Shortlist accredited CBs via IAF CertSearch — see choosing-a-certification-body page.
- Book a Stage 1 date only after internal audit closes major gaps.
Checklist
- ☐ Scope statement and AI inventory complete?
- ☐ SoA with justified Annex A selections?
- ☐ Internal audit report and management review minutes?
- ☐ CB accreditation verified for ISO/IEC 42001 scope?
Where this shows up in ShipReady Metrics
Evidence collection and met-verdict overlay help assemble control-mapped artifacts before Stage 1. The AI risk register tracks ISO 42001 / EU AI Act risks YOU recorded. Tooling supports preparation; it does not replace the CB audit or issue a certificate.