Compyl
GRC Your Way

ISO 42001 Certification Process: What to Expect at Every Stage

Last updated: July 23, 2026

The ISO 42001 certification process is a two-stage audit conducted by an accredited certification body: Stage 1 reviews the design and documentation of your artificial intelligence management system (AIMS), and Stage 2 tests whether it operates effectively in practice. A successful Stage 2 earns a certificate valid for three years, maintained through annual surveillance audits. Including preparation, most organizations complete the journey in 6 to 12 months.

Key takeaways

  • Certification requires passing a Stage 1 (documentation and readiness) audit and a Stage 2 (operating effectiveness) audit.
  • Certificates are valid for three years, with surveillance audits in years two and three and a full recertification audit in year four.
  • Preparation typically takes 3 to 9 months; the end-to-end process usually lands between 6 and 12 months.
  • Certification bodies auditing ISO 42001 are themselves held to ISO/IEC 42006:2025, published in July 2025.
  • An internal audit and management review are mandatory prerequisites, not optional extras.

What are the steps in the ISO 42001 certification process?

The path to certification follows seven steps: scope and gap analysis, AIMS implementation, internal audit, management review, Stage 1 audit, Stage 2 audit, and ongoing surveillance. The first four are within your control and determine how smoothly the last three go. Certification is the formal validation of an AI governance program; it cannot substitute for one. If you have not yet chosen the standard, our explainer on what ISO 42001 is covers why it has become the leading AI management system framework.

How do you prepare before engaging an auditor?

Step 1: Scope the AIMS and run a gap analysis

Define which entities, products, and AI systems the AIMS covers, inventory your AI use, and assess your current state against clauses 4 to 10 and the 38 Annex A controls. The gap analysis becomes your implementation roadmap and tells you honestly how far you are from audit readiness.

Step 2: Implement the management system

Build the governance layer (AI policy, roles, objectives), run AI risk and impact assessments, draft the Statement of Applicability, and implement the applicable controls. This is the longest step; our ISO 42001 checklist breaks it into six phases, and the clause-by-clause requirements guide explains what auditors expect for each.

Step 3: Complete an internal audit and management review

Both are hard prerequisites. The internal audit must cover the full AIMS scope and be performed by someone independent of the work audited. The management review must show top management engaging with audit results, risk posture, and objective performance, with documented decisions. Certification bodies routinely issue findings when either is thin or performed at the last minute.

What happens in the Stage 1 audit?

Stage 1 is a readiness review, typically lasting one to two days and often conducted remotely. The auditor examines your AIMS scope, AI policy, Statement of Applicability, risk and impact assessment methodology, and internal audit and management review records. The output is a report of findings and areas of concern: issues that would likely become nonconformities at Stage 2 if left unaddressed. Treat Stage 1 as a diagnostic and remediate everything it surfaces; certification bodies generally schedule Stage 2 within a few weeks to a few months afterward.

What happens in the Stage 2 audit?

Stage 2 is the certification audit proper. Auditors collect evidence that the AIMS operates as documented: they interview process owners, sample AI systems from your inventory, trace risk treatments to implemented controls, and verify records such as training logs, impact assessments, incident reports, and life cycle documentation. Duration scales with the size and complexity of your scope, from a few days to several weeks of audit time.

Findings are classified as major or minor nonconformities. Minor nonconformities require a corrective action plan but rarely block certification; major nonconformities must be remediated and verified before a certificate is issued. Once the audit team recommends certification and the certification body completes its technical review, you receive a certificate valid for three years.

What happens after you are certified?

Certification starts a three-year cycle. In years two and three, the certification body performs annual surveillance audits: abbreviated reviews focused on the operation, performance evaluation, and improvement clauses plus a rotating sample of Annex A controls. In year four, a full recertification audit renews the certificate for another cycle. Material changes to your AI portfolio, such as launching a new high-impact system or a significant scope expansion, should be communicated to your certification body, as they can trigger a special or extended audit.

How long does ISO 42001 certification take?

Plan for 3 to 9 months of preparation, then 1 to 3 months for the two audit stages including scheduling and remediation windows. Organizations with a mature ISO 27001 program move fastest because document control, internal audit, and management review machinery already exist and only need extending to AI. Greenfield programs with large AI portfolios should budget a full year.

How do you choose a certification body?

Select a body accredited to certify against ISO/IEC 42001. Accreditation matters because ISO/IEC 42006:2025, published in July 2025, defines the competence, audit time calculation, and personnel requirements these bodies must meet, and national accreditation bodies are actively transitioning certifiers onto it. Ask candidates about their AI auditor bench, sector experience, and whether they can run integrated audits if you also hold ISO 27001. A certificate from an unaccredited issuer carries little weight with customers or regulators.

Why pursue certification now?

Buyers increasingly ask for evidence of AI governance in security questionnaires, and regulators are formalizing expectations. Under the EU AI Act, transparency obligations apply from August 2, 2026, and the Digital Omnibus agreed in mid-2026 moved most Annex III high-risk obligations to December 2, 2027. That deferral gives organizations a realistic window to certify before the heaviest obligations bite; our guide to EU AI Act compliance for GRC teams maps the full timeline.

Frequently asked questions

Can you fail an ISO 42001 audit?

Yes. Major nonconformities at Stage 2, such as a missing internal audit or unimplemented applicable controls, block certification until remediated and verified. Most well-prepared organizations receive only minor findings.

How much of the process can be done remotely?

Stage 1 is frequently remote. Stage 2 usually includes on-site or live-video activity so auditors can interview staff and observe processes, though practices vary by certification body and scope.

Do surveillance audits cover the whole standard?

No. Surveillance audits are narrower, concentrating on operation, performance evaluation, and improvement, plus a sample of controls and any prior findings. The full system is reassessed at recertification.

Can ISO 42001 audits be combined with ISO 27001?

Yes. Both standards share the harmonized management system structure, and many certification bodies offer integrated audits that reuse common evidence, reducing total audit days and cost.

Does certification cover every AI system we use?

Only systems inside your declared AIMS scope. Auditors verify that the scope statement is defensible, so excluding a material AI system without justification will itself draw a finding.

Make the audit the easy part

Teams that struggle with certification usually struggle with evidence, not intent. Compyl centralizes your ISO 42001 program: AI system inventory, risk and impact assessments, control ownership, and audit-ready evidence collection in one place, so when the certification body arrives, the answers are already organized.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies