ISO27K

Who needs ISO 42001, and who should wait

Nobody is required by law anywhere to hold an ISO 42001 certificate. Roughly one company in ten that asks about it has a reason to buy one this year. This page is the test that separates the two, and the cheaper thing to do when the answer is no.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

You need ISO 42001 when a buyer, a tender or a regulator has put a governance requirement in writing that a certificate answers faster than a document pack would, and when the AI you run reaches people outside your own company. If both of those are true, certifying is a normal commercial decision costing roughly $45,000 to $120,000 CAD across the first year. If either is false, buying a certificate this year is early, and the useful work costs a week.

The reason this question is hard to answer from a vendor page is that the standard is new enough that almost nothing written about it says no to anybody. Certification bodies and consultancies have a straightforward interest in the answer being yes. What follows is the test, the counter-case, and the price of being wrong in either direction.

Zero Jurisdictions where an ISO 42001 certificate is legally required

$45,000 to $120,000 First year, all in, CAD, for a first certification

About a week Effort for the alternative, if you fail the test

The four-question test

Work down this ladder and stop at the first no. Each question is the one a certification body asks on a scoping call, in roughly this order, and each one on its own is enough to make the project the wrong purchase right now.

  1. Has someone outside the company asked, in writing, for AI governance evidence? A questionnaire section, a tender clause, a contract renewal, a regulator's letter, an insurer's schedule. A conversation at a conference is not a written ask, and neither is a board member reading an article. If the answer is no, you are at question one of a five-year project and the rest of this page is the counter-case.
  2. Does an AI system you run affect someone who is not your employee? Customers, applicants, patients, claimants, members of the public. If every AI system in the building is an internal productivity tool bought off the shelf, you are a user of AI, not a governor of it, and the standard is aimed past you.
  3. Would a document pack fail where a certificate would succeed? This is the question almost nobody asks and it is the one that saves the most money. Most 2026 AI questionnaires can be answered completely with an inventory, a written policy and vendor terms. A certificate wins where the buyer's process cannot accept a self-assertion: public-sector procurement, a regulated financial or health buyer, or a security team that has been told to collect third-party attestations rather than read answers.
  4. Can you keep it running? A certificate is a three-year commitment with a surveillance audit every year and an internal audit and management review behind each one. If nobody has an accountable name against the AI systems today, the certificate will surface that at the first surveillance visit rather than fix it.

The most common wrong answer is question two

A company using a commercial AI assistant internally and shipping no AI in its own product is not the subject of ISO 42001. Buying software with AI in it makes you a customer of somebody else's AI management system. The right artefact is a paragraph in the acceptable use policy and a vendor review, both of which you were going to need for the privacy statute anyway.

Who has a real reason this year

Four situations survive the test regularly enough to name. The table gives the trigger, what the buyer is actually trying to establish, and whether a certificate is the cheapest way to establish it.

Triggers for ISO 42001, and whether certification is the right answer
TriggerWhat the asker wants to knowCertificate, or something cheaper
Enterprise vendor questionnaire with an AI section That someone owns the model in production and that training data has a lawful basis Usually cheaper. An inventory, a policy and vendor terms clear most of these. Certify when the same buyer asks twice, or when the questionnaire says attestation.
Public-sector or broader-public-sector tender Whether you can be scored against a documented governance standard Certificate. Evaluation matrices award points for third-party certification and cannot award them for a self-assertion.
Provider of a high-risk AI system under the EU AI Act That a quality management system exists and is auditable Certificate, but understand what it is not. It is not presumption of conformity. See what the Act actually requires of a Canadian company.
Already ISO 27001 certified and AI is now material to the product That the existing management system covers the new subject Certificate, and it is the cheapest version of this decision anyone gets. The clause machinery is already running, so the marginal cost is a fraction of the first certification.
Board, auditor or insurer asking who is accountable for the model That a named human is answerable for an automated decision Cheaper. Clause 5.3 accountability and one impact assessment answer this. Certification answers it too, at twenty times the price.

Who should wait, and what to do instead

Waiting is the right answer for most companies reading this, and it is not the same as doing nothing. The work below is the part that has value whether or not you ever certify, and it is what a readiness firm would do in its first two weeks anyway. Doing it yourself first makes a later certification cheaper, because the scoping conversation stops being guesswork.

0 of 0 done ·

  • How to run one

That list is a week of work spread across two people. It answers most questionnaires arriving in the next year, and every item becomes an input to a certification project if you later decide to run one. Nothing on it is wasted by waiting. If the buyer who asked named the NIST AI Risk Management Framework rather than ISO 42001, that is a different and cheaper answer, because nothing certifies against it.

What does waiting actually cost?

The honest risk of waiting is not regulatory. There is no Canadian AI statute in force, so nobody is going to fine you for lacking a certificate. The risk is commercial and it lands on a deal timeline.

Cost of not holding ISO 42001 when it is asked for, CAD and calendar
SituationDelay if you start from nothingWhat it costs
Questionnaire arrives, document pack accepted1 to 3 weeksStaff time only, if the inventory exists. Four to six weeks if it does not.
Tender requires certification at submission9 to 14 monthsThe bid, entirely. No certification body can compress the operating period a stage 2 auditor samples.
Enterprise renewal adds a governance clause6 to 12 monthsUsually a conditional renewal with a remediation date attached, which is survivable but weakens your position on price.
EU customer asks as a high-risk deployer9 to 15 monthsContractual obligations flow down from their own compliance date, so their deadline becomes yours.

Read the middle row as the real argument for starting early. The one input no budget shortens is calendar time: a management system has to have been operating before an auditor can sample records against it, and three months is the practical floor. Everything else on an ISO 42001 project can be bought faster with money. That one cannot.

Does any Canadian rule make this decision for you?

No, and anyone telling you otherwise is describing a bill that did not pass. AIDA sat inside Bill C-27, which died on the order paper, so Canada has no AI statute in force. What binds Canadian companies today is privacy law applied to AI systems rather than AI law.

Quebec, Law 25
Where a decision is based exclusively on automated processing, the individual has to be informed of it at or before the decision, and can ask for the personal information used and the reasons behind the outcome. This is in force, it is specific, and it reaches any company with Quebec customers regardless of where the company sits.
PIPEDA, and its provincial equivalents
Purpose limitation is where most AI projects actually break. Personal information collected to deliver a service does not automatically carry a purpose that covers training a model on it. That question arrives long before any AI-specific rule does.
PHIPA and health information
Health custodians in Ontario face the same consent and purpose questions with a stricter statute and a regulator that has published on the subject. A clinical decision-support tool is not a productivity tool.
The EU AI Act, for anyone selling there
Extraterritorial by design, with obligations that depend on your role for each system. It is the only instrument in this list with hard dates attached, and the dates that already bind a Canadian company are worth checking before you decide the question is theoretical.

One genuinely Canadian consideration

If you do decide to certify, the accreditation question is different for ISO 42001 than for ISO 27001 because the pool of accredited bodies is much smaller and only recently national. The Standards Council of Canada has granted accreditation for ISO/IEC 42001 audits domestically, and the number of bodies holding it in Canada is countable on one hand. That affects your scheduling more than your price. Ask a body for its accreditation scope document and check that ISO/IEC 42001 is named on it, using the same verification procedure that works for ISO 27001, before you sign anything.

What ISO 42001 is not a substitute for

Three substitutions get made on vendor pages and each one costs somebody a project.

  • It does not certify a model. Nothing certifies a model. The certificate asserts that a management system governing AI meets the standard, on a defined scope, on the date the certificate was issued. A buyer asking whether your model is safe has asked a question no certificate answers, and the four things people mean by AI certification is the page that untangles that conversation.
  • It is not EU AI Act compliance. Presumption of conformity comes from harmonised standards cited in the Official Journal. ISO 42001 is not one of them. It is useful evidence toward the quality management system a provider needs, and it is not a shortcut past the Act.
  • It is not information security. If your buyer's actual worry is that customer data leaks, they want ISO 27001 or SOC 2, and an AI governance certificate answers a different question at a similar price. Read the words they wrote, not the words they said on the call.

Work out whether it is worth it yet

The readiness tool asks the same four questions and gives you a verdict. If the verdict is yes, tell us your scope and we will match you with Canadian firms that do this work.

Get matched

Common questions

Is ISO 42001 mandatory anywhere?

No. There is no jurisdiction in the world where holding an ISO 42001 certificate is required by law. It is a voluntary certification against a voluntary standard. What can be mandatory is a contract term or a tender condition that names it, and that is a commercial obligation rather than a legal one.

We only use ChatGPT and Copilot internally. Do we need ISO 42001?

No. Using commercial AI tools internally makes you a user of somebody else's AI systems. What you need is an acceptable use policy saying what may be put into those tools, the vendor terms on training and retention, and a line in your inventory. Certifying a management system around a purchased chatbot is expensive theatre and an auditor will find very little scope to audit.

How small is too small for ISO 42001?

Size is the wrong axis. A twelve-person company shipping a credit decisioning model has a stronger case than a four-hundred-person company whose only AI is a support ticket summariser. What decides it is whether an AI system you control affects people outside the company and whether someone has asked you in writing. Below roughly twenty people the practical constraint is different: clause 9.2 requires an internal audit by someone who did not build the system, and in a small company that means buying it.

Should we do ISO 27001 first?

If you have neither and are choosing, yes. Access control, change management, logging and supplier management all sit underneath the ISO 42001 controls, so certifying an AI management system with no information security management system underneath it means building most of ISO 27001 anyway without getting the certificate that buyers already recognise. The exception is a company whose entire commercial pressure is AI governance and whose security posture is already covered by a SOC 2 report.

How long is an ISO 42001 certificate valid?

Three years, with a surveillance audit in each of the two intervening years and a recertification audit before it expires. That cycle is the same as ISO 27001 and it is the part people underestimate: the ongoing cost is not the certificate, it is the internal audit, the management review and the evidence that the system kept running.

Can we get certified before the standard settles?

Yes, and there is a real argument for it. ISO/IEC 42001:2023 is stable and certifiable today, and supporting documents around it are still being published. Waiting for the supporting documents to finish means waiting several years. The genuine risk of early certification is not that the standard changes, it is that you certify a scope drawn around AI systems that look very different in eighteen months, which is an argument for a narrow first scope rather than for delay.