AI certification: what can be certified
Nobody issues a certificate for a model. What is certifiable is the management system around the model, which is a narrower and more useful thing than the phrase AI certification suggests.
There is no certificate for an AI system. No accredited body will inspect a model and attest that it is safe, fair or accurate, and any organization offering to is selling something outside the accreditation system. What can be certified is your AI management system, under ISO/IEC 42001, and what that certificate says is that you have a governed process for deciding what your AI is for, assessing who it affects, controlling how it is built and run, and correcting it when it goes wrong.
That distinction is the whole subject of this page, because almost every purchasing conversation about AI assurance starts with somebody using the phrase "AI certification" to mean one of four different things.
The four things people mean by AI certification
| What is asked for | What exists | Who issues it |
|---|---|---|
| Certify our AI governance | ISO/IEC 42001 certification of an AI management system | An accredited certification body, on a three-year cycle |
| Certify the model itself | Nothing equivalent. Model evaluations, red teaming and audits exist, and they are reports rather than certificates | Testing firms and research groups. No accreditation scheme behind them |
| Prove we comply with the EU AI Act | Conformity assessment under the Act itself, for the systems the Act classifies as high risk | Notified bodies designated under EU law, or self-assessment depending on the system |
| Show us you follow a recognised AI framework | The NIST AI Risk Management Framework and similar. Voluntary guidance, no certification scheme | Nobody. You can align to it and describe how, and that is all |
When a customer writes "AI certification" into a security schedule, they almost always mean the first row and do not know it yet. Ask them what evidence would satisfy the requirement. In practice the answer is usually a certificate they can file, plus somebody able to answer questions about how models are approved and monitored, which is exactly what an ISO 42001 certificate plus your own documentation gives them.
What an ISO 42001 certificate actually asserts
It asserts that an accredited body audited a management system, of a stated scope, and found it conforming to the standard. Read the scope line on any certificate before you rely on it, yours or a supplier's, because that line is where the meaning is. A certificate scoped to "the development and operation of the recommendation service" says nothing about the chatbot launched afterwards.
Inside that scope, certification means an auditor tested that you can produce records of the things the standard requires: a defined AI policy with executive accountability, an inventory of the AI systems in scope and your role for each of them, AI risk assessment, an assessment of the system's impact on the individuals and groups it affects, controls over data and over the system life cycle, information provided to users about the system, an internal audit and a management review. The guide to the standard sets out the clause structure and Annex A themes.
What it does not assert is that any model performs well, that your outputs are unbiased, or that you comply with any statute. Those are separate questions with separate evidence, and a supplier who answers a fairness question by attaching an ISO 42001 certificate has misunderstood their own certificate.
Provider, deployer, or both
The single most useful thing to settle before any of this is which role you play for each AI system. Building and shipping a model is a different set of obligations from buying somebody else's and putting it in front of your customers, and most companies do both without having written down which is which. The role determines the scope, the scope determines the audit, and the audit determines the cost. Getting this wrong at the start is the most expensive available mistake, because it is discovered at stage 1.
Who this is genuinely for right now
ISO 42001 published in December 2023, and the market for it is early enough that being certified is still unusual. That cuts both ways.
- Worth doing now: you sell AI features into enterprise or public sector procurement and the questionnaires have started asking about AI governance. Being the vendor with a certificate while competitors are writing paragraphs is a live commercial advantage, and it will not stay one.
- Worth doing now: you already hold ISO 27001 and AI is becoming core to the product. The management system skeleton is shared, the audits can be combined, and the incremental cost is far below a standalone certification.
- Worth doing now: you sell into the European Union and will fall inside the EU AI Act as a provider of a high risk system. The certificate is not compliance with the Act, and the governance you build for it covers a meaningful part of what the Act asks you to have.
- Not yet: you use AI internally, as a tool, and nobody is asking. Internal use of a commercial assistant does not need a certified management system, and buying one is a cost with no revenue attached to it.
- Not yet: you have no ISO 27001 and no management system discipline of any kind, and a customer has asked about AI. Certifying to ISO 42001 from a standing start means building the whole management system skeleton for the first time, and if the same customer will eventually want information security assurance too, the sequencing question is worth thinking about before committing.
Where it sits against the EU AI Act
The Act is law and ISO 42001 is a voluntary standard, and holding the certificate does not make you compliant with the Act. Under EU law, presumption of conformity comes from harmonised standards cited in the Official Journal, and the AI Act's harmonised standards are being developed by the European standardisation bodies rather than adopted wholesale from ISO. ISO 42001 is not one of them.
What it does do is get you most of the organizational machinery the Act expects a provider to have: a risk management system, data governance, technical documentation, record keeping, human oversight arrangements and post-market monitoring all have recognisable counterparts in the standard. If you are going to be inside the Act's scope, building an ISO 42001 management system is a reasonable way to prepare for it, provided nobody in your organization starts describing the certificate as compliance.
Where Canada sits
Canada has no AI statute in force. The Artificial Intelligence and Data Act was part of Bill C-27, which did not become law before Parliament was prorogued, so there is currently no Canadian equivalent of the EU regime and no Canadian certification requirement. What does exist is worth knowing about: a voluntary code of conduct for advanced generative AI systems that several Canadian companies have signed, and, for federal institutions, the Treasury Board directive on automated decision-making with its algorithmic impact assessment, which shows up in federal procurement.
The practical Canadian point is a different one. Privacy law applies to AI systems now, without any new statute. If your models are trained on or make decisions about personal information, PIPEDA or the provincial statute that displaces it governs that handling, and Quebec's Law 25 includes a right to be informed when a decision is based exclusively on automated processing. That obligation is in force today, it applies whether or not you certify anything, and it is the one most often missed by companies focused on the international standards.
What it takes to get certified
Six to twelve months for a company that already runs a management system, and longer from nothing. The audit mechanics are the same as ISO 27001: a stage 1 documentation review, a stage 2 audit of the operating system, then surveillance across a three-year cycle. Budget $15,000 to $45,000 CAD for the certification body on a standalone first certification, or $10,000 to $25,000 CAD to add it to an existing ISO 27001 audit, plus readiness support. The certification process, cost and timeline covers it in detail, including how to check that a body's accreditation actually extends to ISO 42001, which is the check that matters most here because the accredited pool is small and growing.
Before any of that, work out whether you are in scope and what the effort would look like. The ISO 42001 readiness check asks the questions a certification body would ask at scoping and tells you where you stand.
Work out whether AI certification applies to you
Send us what your customer asked for and a sentence about what your AI does. We will tell you which of the four things they meant.
Get matchedCommon questions
Can an AI model be certified?
No. There is no accredited certification scheme for a model, and no body issues a certificate attesting that a model is safe, accurate or fair. What exists at the model level is evaluation and audit work, delivered as reports. Certification applies to the management system around the model, under ISO/IEC 42001.
Our customer asked for AI certification. What do they want?
Ask them what evidence would close the requirement. Nearly always the answer is a certificate they can file plus somebody who can answer questions about how AI systems are approved and monitored, which is what ISO 42001 certification provides. Occasionally they mean EU AI Act conformity, which is a legal assessment and a different thing entirely.
Does ISO 42001 make us compliant with the EU AI Act?
No. The Act is law and the standard is voluntary, and presumption of conformity under EU law comes from harmonised standards cited in the Official Journal rather than from ISO certification. The governance you build for ISO 42001 covers much of what the Act expects an organization to have, which makes it useful preparation rather than a substitute.
Is there a Canadian AI certification requirement?
No. Canada has no AI statute in force, since the Artificial Intelligence and Data Act did not pass. Canadian privacy law still applies to AI systems that handle personal information, and Quebec's Law 25 gives individuals a right to be informed about decisions made exclusively by automated processing. Those obligations exist now, independent of any certification.
Should we do ISO 27001 or ISO 42001 first?
ISO 27001 first in most cases, because buyers ask for it far more often and the management system it builds is the foundation the AI standard reuses. The exception is a company whose entire value proposition is an AI product being sold to buyers asking specifically about AI governance, where the order can reasonably reverse. Running both from nothing in the same quarter is the version that goes badly.