ISO 42001 Certification Process: Stage 1, Stage 2, and Timelines
A step-by-step walkthrough of the ISO/IEC 42001:2023 certification journey, from gap analysis through Stage 2 audit, typical timelines, accredited certification bodies, and the evidence auditors look for.
What ISO 42001 certification actually is
ISO/IEC 42001:2023 is the international standard for Artificial Intelligence Management Systems (AIMS). Certification is the process by which an accredited third party (a "certification body") reviews your AIMS against the standard's requirements and issues a certificate confirming conformance. Certification is voluntary, the standard itself can be implemented without certification, but many organisations pursue certification because it satisfies procurement requirements (Microsoft SSPA, enterprise vendor questionnaires), supports EU AI Act readiness, and signals AI governance maturity to customers, regulators, and insurers.
The three-stage certification journey
The process follows a well-established pattern used for ISO 27001, ISO 9001, and other ISO management-system standards. Since December 2023 (when ISO 42001 was published), accreditation bodies reference the in-development ISO/IEC 42006, the forthcoming international standard that governs how certification bodies operate.
Stage 0, Implementation and internal readiness (3–12 months)
Before engaging a certification body, you must implement the AIMS itself: establish scope, define AI policy, run the risk assessment, build the Statement of Applicability, operate the internal audit and management-review cycles, and collect evidence that the system is actually functioning. This is where the bulk of the work happens. Our Starter and Professional tiers give you the documentation foundation for this stage.
Typical duration: 4–6 months if you already have ISO 27001 or NIST AI RMF; 8–14 months greenfield.
Stage 1 audit, Documentation review (1–3 days)
The certification body reviews your documented information: AI Policy, Scope, Statement of Applicability, Risk Register, Impact Assessment records, policies, procedures, internal audit reports, management-review minutes. The auditor is checking that the documentation is complete, internally consistent, and that you're ready for Stage 2 operational testing. Stage 1 findings are usually minor, gaps in documentation, missing signatures, out-of-date procedures, and are typically cleared before Stage 2 begins.
Typical outcome: A short report identifying any documentation-level findings; scheduling of Stage 2.
Stage 2 audit, Implementation and operation (3–8 days)
The certification body tests your AIMS in operation. They interview staff, review evidence that controls are actually working, sample AI system impact assessments, check incident-response records, and verify that risk treatment has been performed. Stage 2 is where most non-conformities emerge: a control is documented but not operating; an impact assessment is missing for a system in scope; incident-response runbooks haven't been tested.
Typical outcome: Zero, one, or more non-conformities graded "minor" or "major". Minor NCs must be addressed with a corrective-action plan before the certificate is issued. Major NCs typically require a follow-up audit before certification is granted.
Certificate issued, valid 3 years, with annual surveillance
Once all Stage 2 findings are cleared, the certification body issues the ISO/IEC 42001:2023 certificate. It typically has a three-year validity, with annual surveillance audits (usually 1–3 days each) during that period and full re-certification at the end of year 3.
Typical end-to-end timeline
| Organisation profile | Implementation | Stage 1 → Stage 2 | Total to certificate |
|---|---|---|---|
| Greenfield, no prior ISO framework | 8–14 months | 4–12 weeks | ~10–17 months |
| Existing ISO 27001 | 4–6 months | 4–8 weeks | ~5–8 months |
| Existing NIST AI RMF maturity | 4–6 months | 4–8 weeks | ~5–8 months |
| Existing 27001 + NIST AI RMF + mature governance | 2–4 months | 4–6 weeks | ~3–6 months |
Accredited certification bodies
Only certification bodies accredited by a recognised national accreditation body (ANAB in the US, UKAS in the UK, DAkkS in Germany, etc.) can issue ISO/IEC 42001 certificates that are internationally recognised. As of April 2026, accredited bodies include:
- Schellman, ANAB-accredited; one of the earliest to certify (AWS, Anthropic)
- BSI, first globally to certify to 42001 (KPMG Australia, October 2024)
- A-LIGN, accredited; certified Synthesia and others
- SGS, accredited; certified OrionStar Robotics (July 2024)
- DNV, accredited for ISO 42001
- Palindrome Technologies, newly ANAB-accredited as of April 2026
- Several other bodies in Europe, UK, and Asia-Pacific are accredited or in-process
Cost varies by scope and organisation size; certification-body fees typically run $20,000–$40,000 for year-one Stage 1 + Stage 2 audit combined at a small-to-mid organisation.
What auditors look for
The auditor's job is to verify that your AIMS satisfies all applicable Clause 4–10 requirements and that Annex A controls listed as "applicable" in your Statement of Applicability are actually implemented and operating. Concretely, expect questions and evidence requests around:
- Clause 4, How did you define AIMS scope? Why these systems, why not others?
- Clause 5, Who signed the AI Policy? Is it current? Does top management actually review AIMS performance?
- Clause 6, Show the risk methodology. Show the risk register. For a sampled AI system, show the impact assessment.
- Clause 7, Show competence records. Show communication plan in operation.
- Clause 8, Show operational lifecycle records for a sampled system: development, testing, deployment, monitoring, retirement.
- Clause 9, Show internal audit reports. Show management-review minutes.
- Clause 10, Show nonconformity and corrective-action records.
- Annex A (all 38 controls), For each "applicable" control, show the evidence that it's implemented.
How the toolkit accelerates certification
Our tiers map directly to the certification journey:
- Starter ($199), the 23 core documents (AI Policy, Scope, SoA, risk methodology, risk register, impact assessment procedure, all operational procedures) that auditors will ask for in Stage 1.
- Professional ($697), adds the 9 Annex A deep-dive guides (so you know what evidence to prepare for each of the 38 controls), the 7 Clause playbooks (what auditors test at each clause), the Four-Way Crosswalk (to reuse ISO 27001/NIST evidence), and the 64-formula Gap Analysis Workbook (to track readiness honestly).
- Audit-Ready ($1,497), adds the Pre-Audit Self-Assessment (pass your own audit before booking the real one), Stage 1 and Stage 2 Evidence Binders, and the Auditor Briefing Pack.