ISO 42001 readiness check
The AI management standard is new enough that most of what is written about it is vague. This asks the questions a certification body asks at scoping and tells you where you stand.
Two questions decide most of this: what role you play for each AI system, and whether anyone has actually asked. Everything else changes the scope and the cost rather than the answer. The result appears on this page.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
What certification would actually involve
ISO/IEC 42001 published in December 2023 and certifies a management system, not a model. No accredited body inspects an AI and attests that it is safe, fair or accurate, and the certificate says that you have a governed process for deciding what your AI is for, assessing who it affects, controlling how it is built and run, and correcting it when it goes wrong. That distinction is set out on what can and cannot be certified.
The audit mechanics are the same as ISO 27001: a stage 1 documentation review, a stage 2 audit of the working system, then surveillance across a three-year cycle. Two things differ in practice. The impact assessment work is heavier than anything in ISO 27001, because assessing effects on individuals and on groups is a genuinely new discipline for most engineering organizations. And the pool of bodies accredited specifically for ISO 42001 is much smaller than for information security, so checking the scope of accreditation matters more here. Process, cost and timeline covers both.
Canada has no AI statute in force
The Artificial Intelligence and Data Act was part of Bill C-27, which did not become law, so there is currently no Canadian certification requirement for AI. What does apply now is privacy law: if your models are trained on or make decisions about personal information, PIPEDA or the provincial statute that displaces it governs that handling, and Quebec's Law 25 gives individuals a right to be informed when a decision is based exclusively on automated processing. Those obligations exist independently of anything on this page.
Common questions
Are we in scope for ISO 42001 if we only use AI internally?
You can certify internal use, and there is usually little reason to. ISO 42001 is bought because a customer, a tender or an investor is asking how you govern AI, and internal use of a commercial assistant rarely prompts that question. What internal use does deserve is an acceptable use policy and a record of which tools have been approved and what data may go into them, which is a fraction of the effort.
Do we need ISO 27001 before ISO 42001?
No, they are independent certifications. In practice most companies do ISO 27001 first because buyers ask for it far more often, and because the management system it builds is reused almost entirely by the AI standard. A company whose whole value proposition is an AI product, facing buyers asking specifically about AI governance, can reasonably reverse the order.
How much does ISO 42001 cost in Canada?
$15,000 to $45,000 CAD for the certification body on a standalone first certification, or $10,000 to $25,000 CAD to add it to an existing ISO 27001 audit with the same body, plus readiness support of $15,000 to $90,000 CAD depending on how much exists already. Combining the audits saves days, because the shared management system clauses are covered once.
Does certification prove our model is unbiased?
No, and a supplier who answers a fairness question by attaching an ISO 42001 certificate has misunderstood their own certificate. What it shows is that you assess impact, control the life cycle and act on what you find. Evidence about a specific model's behaviour comes from evaluation and testing work, which produces reports rather than certificates.