ISO 42001 certification: process, cost, timeline
ISO 42001 certification follows the same audit mechanics as ISO 27001: a stage 1 documentation review, a stage 2 audit of the working management system, then surveillance audits across a three-year cycle. The difference is the small and shifting pool of bodies accredited to do it.
Getting certified to ISO/IEC 42001 means an independent certification body audits your AI management system against the standard and, if it holds up, issues a certificate naming the scope it covers. The audit itself is not mysterious and it is not different in kind from an ISO 27001 audit. The two things that are different are the amount of preparation the impact assessments demand, and the fact that far fewer bodies hold accreditation for this standard than for information security. Budget your effort for the first and your diligence for the second.
If you have not yet decided whether certification is the right move, read what the standard covers and who needs it first. This page assumes the decision is made.
How the audit works
Certification bodies audit management system standards to a common set of rules, so the sequence below holds whether the subject is quality, information security or AI.
| Step | What happens | Typical timing |
|---|---|---|
| Scope definition | You decide which AI systems, teams, sites and roles the management system covers. This wording ends up on the certificate. | Before anything else |
| Build and run | Policy, risk assessment, impact assessments, Statement of Applicability, controls in operation. | The bulk of the project |
| Internal audit and management review | Both must have happened before a stage 2 audit. Auditors check for them early. | 4 to 8 weeks before stage 2 |
| Stage 1 audit | Documentation and readiness review. The auditor confirms the management system exists on paper and tells you what will fail at stage 2. | 1 to 2 days |
| Gap closure | Fix what stage 1 surfaced. | 4 to 12 weeks |
| Stage 2 audit | Evidence that the system is genuinely operating. Interviews, records, sampling of AI systems in scope. | 2 to 5 days depending on size |
| Nonconformity closure | Major findings must be closed before a certificate issues. Minor ones usually get a corrective action plan. | 2 to 12 weeks |
| Certificate issued | Valid for three years, subject to surveillance. | |
| Surveillance audits | Shorter audits in years one and two, sampling parts of the system. | 1 to 3 days each |
| Recertification | A full audit in year three to renew. | Similar to stage 2 |
Where first-time applicants get stopped
Two items catch people out at stage 2 more than anything else. The first is an internal audit that was run as a formality and found nothing, which an auditor reads as evidence the internal audit does not work. The second is an AI system in production that never made it into the inventory, usually a feature built on a third-party model API. Find it yourself before the auditor samples it.
Checking accreditation, and why it matters more here
Anyone can print a certificate. What gives one weight is accreditation: a national accreditation body has assessed the certification body against the rules for certifying that specific standard, and those accreditation bodies recognize each other through the International Accreditation Forum. In Canada the national accreditation body is the Standards Council of Canada, and certificates from bodies accredited by peer members such as ANAB in the United States or UKAS in the United Kingdom are accepted here in the same way.
ISO published a separate standard setting requirements for bodies auditing and certifying AI management systems, and accreditation programs have been built out against it since. The pool of bodies with accreditation specifically for ISO 42001 is still much smaller than for ISO 27001, and it keeps changing. That produces two failure modes worth avoiding.
- Unaccredited certificates. A body may audit and certify you without accreditation for this standard. The certificate is not worthless, but a sophisticated buyer will check, and you may end up paying twice.
- Accreditation claimed for the wrong scope. A body accredited for ISO 27001 is not automatically accredited for ISO 42001. Accreditation is granted per standard.
The check takes ten minutes. Ask the body which accreditation body granted its accreditation and for which standard, then confirm it on that accreditation body's own public register rather than on the certification body's website. Verify before you sign, not after.
Impartiality rules apply here too
An accredited certification body cannot consult you into shape and then certify you. If a firm offers to build your management system and audit it, one of those two things is not accredited work. Use separate suppliers for readiness and for certification, the same way you would for ISO 27001.
What it costs in Canada
Every figure here is Canadian dollars and every one is a range. Pricing for ISO 42001 is less settled than for information security work, because fewer bodies are quoting it and audit days depend heavily on how many distinct AI systems sit in scope. Treat these as planning bands for a first certification, not as a quote.
| Line item | Range (CAD) |
|---|---|
| Certification body, stage 1 and stage 2 combined | $15,000 to $45,000 |
| Surveillance audit, each of years one and two | $5,000 to $15,000 |
| Readiness or implementation consulting | $30,000 to $90,000 |
| Impact assessments, if scoped separately | $5,000 to $20,000 |
| Copies of the standard and related documents | $500 to $1,500 |
| Internal effort, first year | Several hundred hours |
Three things move the certification body number more than anything else: the number of AI systems in scope, the number of sites and legal entities, and headcount. Two things move the consulting number: whether you already run a management system, and whether anyone internally can write the AI system inventory without help.
An organization already certified to ISO 27001 should expect the combined figure to land well under a first ISO 27001 project, because the clause 4 to 10 machinery already exists and often the same certification body will run the two audits together. Ask about a combined or integrated audit explicitly. It is usually cheaper in audit days than two separate visits, and it stops your management review calendar from doubling. For the comparable information security numbers see ISO 27001 cost in Canada.
How long it takes
From decision to certificate, plan on four to eight months if you already operate a certified ISMS, and nine to fifteen months starting from nothing. The audit days themselves are a small part of that. What sets the pace is building an AI system inventory that is actually complete, running impact assessments that have real analysis in them, and accumulating enough operating records that a stage 2 auditor can sample something.
You cannot compress the last item much. A management system that started running four weeks before stage 2 has four weeks of records, and an auditor will say so. Two to three months of the system genuinely operating before stage 2 is a reasonable floor.
Choosing a certification body
Ask each shortlisted body the same short list of questions and compare the answers rather than the quotes.
- Which accreditation body granted your accreditation for ISO 42001, and under what certificate number.
- How many audit days are you proposing, split across stage 1, stage 2 and each surveillance visit. Day count is the honest basis for comparing price.
- Will the audit team include someone with AI experience, or only management system auditors.
- Can you combine this with our ISO 27001 audit cycle, and what does that save in days.
- What is the three-year total, including surveillance and recertification. A cheap stage 2 with expensive surveillance is a common shape.
Price the engagement over three years, never one. The certificate is a cycle, not a purchase, and the difference between two quotes usually shows up in years two and three rather than in the headline.
Get quotes for ISO 42001 certification
Tell us what your AI systems do and how big the scope is, and we will put you in front of firms that do this work in Canada.
Get matchedCommon questions
How long is an ISO 42001 certificate valid?
Three years, on the standard management system cycle, provided you pass the surveillance audits in years one and two. A full recertification audit renews it for another three years.
Can the same firm help us prepare and then certify us?
No, not if the certification is accredited. Impartiality rules stop a certification body from consulting on the management system it later audits. Use one supplier for readiness and a separate accredited body for certification.
Do we have to include every AI system in the scope?
No. You define the scope and it is printed on the certificate. A narrow first scope covering the systems customers ask about is a reasonable starting point and can be widened at recertification. The limit is credibility: if the scope excludes the AI feature you sell, buyers who read the certificate will notice.
Is a certificate from an unaccredited body worth anything?
Less than it costs, in most cases. It may satisfy a buyer who does not check, and it will not satisfy one who does. Given how new this standard is, expect the buyers who care about AI governance to be exactly the ones who verify accreditation.
Can we audit ISO 42001 and ISO 27001 together?
Yes, if one body is accredited for both, and it is usually the cheaper path. The shared management system clauses are audited once rather than twice, so the combined day count is lower than two separate audits. Ask for the integrated day count in writing when you request a quote.
What happens if the auditor raises a major nonconformity?
The certificate does not issue until it is closed. You submit a root cause analysis and corrective action, and the body verifies the fix, often remotely if the evidence is clear. It delays certification by weeks rather than restarting the process.