ISO 42001 is the international standard for AI management systems. The standard helps you to develop, implement and use artificial intelligence responsibly. From chatbots to predictive models, from image recognition to decision support.
In this guide you will read everything you need to know: from the basic principles to the costs, from preparation to choosing a certifier. No sales pitches, just clear information.
1. What is ISO 42001?
ISO/IEC 42001:2023 is the first international standard for an Artificial Intelligence Management System (AIMS). The standard describes requirements for the responsible development, implementation and use of AI systems within your organisation.
In short: ISO 42001 helps you systematically identify, manage and reduce AI risks. From bias in algorithms to privacy impact, from transparency to human control.
With an ISO 42001 certificate you demonstrate that your company has a working AI management system, actively manages risks and continuously improves in the field of responsible AI.
1.1 The core of ISO 42001
ISO 42001 revolves around four core areas:
| Core area | What it means |
|---|---|
| AI governance | Clear policies, roles and responsibilities for AI |
| Risk Management | Systematically identify and manage AI risks |
| Life cycle | From development to phase-out: every phase controlled |
| Continuous improvement | Learning from incidents, adapting to new insights |
The standard is not limited to high-risk AI. Any organisation that develops or uses AI can certify, regardless of the risk profile.
1.2 Annex A: the 38 controls
An important part of ISO 42001 is Annex A. This is a catalogue of 38 AI-specific management measures (controls) divided over nine domains:
| Domain | Core focus |
|---|---|
| Policies and procedures | AI governance framework |
| Resources | Budget, people, resources |
| Accountability | Roles and ownership |
| AI inventory | Overview of all AI systems |
| Life cycle | From development to phase-out |
| Data governance | Data quality and origin |
| Transparency | Information to stakeholders |
| Use | Deploy safely and responsibly |
| Customer Relations | Agreements and contracts |
You don’t have to apply all 38 controls. In your Statement of Applicability you record which controls are relevant to your organisation and why.
1.3 Current version: ISO/IEC 42001:2023
The current and first version is ISO/IEC 42001:2023, published in December 2023. It is the first certifiable AI management system standard in the world.
Accreditation: Since January 2025, DNV and BSI have been accredited by the RvA for ISO 42001 certification in the Netherlands.
2. Why certify ISO 42001?
A certificate is not a goal in itself. It is a means. The question is: does it help your business?
2.1 Five concrete benefits
In addition to access to assignments, there are more benefits:
- Better risk management - You systematically identify and manage AI risks. From bias to privacy, from transparency to security.
- Demonstrated compliance - Prepare for the EU AI Act and demonstrate that you handle AI responsibly. Supervisors and customers appreciate a certificate.
- Customer Trust - You show that you take AI seriously. This makes a difference, especially in sensitive applications (HR, finance, healthcare).
- Foundation for extension - ISO 42001 shares the same structure with ISO 9001 and ISO 27001. Integration is simple.
- Competitive advantage - The standard is new. Early certification sets you apart from competitors.
2.2 For whom is it relevant?
ISO 42001 is relevant for any organisation that develops, implements or uses AI. But some benefit more from it:
| Sector | Why relevant |
|---|---|
| IT and software | Developing AI solutions, customers demand it |
| Finance | Credit assessment, fraud detection, compliance requirements |
| Care | Diagnostic support, patient data, high risks |
| HR and recruitment | CV screening, interview tools, bias risk |
| Government | Procurement requirements, public accountability |
| Ecommerce | Recommendation algorithms, personalization |
2.3 When it may not be necessary
Honest advice: certification is not the best choice for everyone.
Ask yourself this question: Do I use AI in my business processes? Do my customers or clients expect it? If not, carefully consider whether the investment is worth it.
Other situations in which you have to be critical:
- If you only use standard office tools without AI components
- Very small organisations without AI systems are unlikely to have the ROI
- If you just want a certificate for the sake of having it, without really improving the processes
3. The ISO 42001 certification process
You go through six steps from decision to certificate. Count on nine to eighteen months, depending on your starting position and AI complexity.
3.1 The six steps to certification
Determine scope - Which AI systems, processes and departments are covered by the AIMS? If necessary, start with your most important AI applications.
AI inventory and risk analysis - Take an overview of all AI systems and identify the risks. This is the heart of ISO 42001.
Set up AIMS - Implement controls, establish policies, train employees, and document processes.
Complete Evidence Period - Work under your AIMS for a minimum of three months. Auditors want proof that the system works in practice.
Internal audit and management review - Verify that everything is working and have management formally assess the AIMS.
External audit - The certifier carries out the audit in two phases. If successful you will receive the certificate.
3.2 The external audit: phases one and two
Phase 1 (Stage 1) is a documentation and readiness check. The auditor reviews your AIMS documentation, AI inventory and risk analysis. Usually lasts one to two days.
Phase 2 (Stage 2) is the on-site practical audit. The auditor speaks with employees, checks processes and verifies whether paper and practice correspond. Lasts two to four days.
3.3 Timeline
| Your situation | Lead time | Audit duration |
|---|---|---|
| Already have a management system (e.g. ISO 9001/27001) | 6-9 months | 2-3 days |
| Good basis, but no AIMS yet | 9-15 months | 3-4 days |
| Complex AI environment or multiple systems | 12-18 months | 4-5 days |
3.4 Who does what?
| Party | Role |
|---|---|
| You | AI inventory, risk analysis, setting up AIMS, internal audits |
| IT/Data team | Documenting AI systems, technical measures |
| Consultant (optional) | Guidance, gap analysis, templates, training |
| Certifier | Perform audit, issue certificate |
| Accreditation body | Checks the certifier (RvA, UKAS, etc.) |
Good to know: A consultant is not mandatory. Organisations with experienced IT and compliance people can do it themselves. However, guidance can speed up the process.
4. What does ISO 42001 cost?
The costs vary. They depend on your company size, AI complexity and whether you hire a consultant. ISO 42001 is comparable to ISO 27001 in terms of investment.
Rule of thumb for SMEs: Count on €15,000 - €35,000 in the first year, then €3,000 - €7,000 per year.
4.1 Cost items overview
| Cost item | Indication |
|---|---|
| Certification audit (year 1) | €6,000 - €12,000 |
| Surveillance audit (per year) | €2,000 - €4,000 |
| Recertification (every three years) | €5,000 - €10,000 |
| Consultant (optional) | €10,000 - €25,000 |
| Training | €500 - €2,500 per person |
| Internal hours | 150 - 300+ hours |
4.2 Price indication per company size
| Company size | First year | Annually thereafter |
|---|---|---|
| Small (up to 20 FTE) | €10,000 - €25,000 | €2,000 - €4,000 |
| Medium (20-100 FTE) | €25,000 - €50,000 | €4,000 - €7,000 |
| Large (100+ FTE) | €40,000 - €80,000+ | €7,000 - €15,000+ |
Prices indicative, excl. VAT, including consultant and internal hours.
4.3 What influences the price?
Five factors determine your costs:
- Number of AI systems (more = more audit time)
- AI complexity (own development vs purchased tools)
- Number of employees (scope of the AIMS)
- Current maturity (starting from scratch is more expensive than optimizing)
- Certifier’s choice (prices vary 20-40%)
5. Preparation for ISO 42001
Good preparation is half the battle. Most of the time is spent on the AI ​​inventory and setting up your AIMS, not on the audit itself.
5.1 What do you need to arrange internally?
Then follow these steps:
- Appoint project leader - Someone with a mandate, AI knowledge and time to spare
- Create AI inventory - What AI systems do you have? What are they used for?
- Determine scope - Which systems and processes are covered by the AIMS?
- Perform risk analysis - Identify risks per AI system
- Implement measures - Technical and organizational, based on the risk analysis
- Create awareness - Train employees on responsible AI use
- Start proof period - Work for at least three months according to the AIMS
5.2 What documentation is needed?
The standard requires at least:
| Document | What it is |
|---|---|
| AI Policy | Your vision and goals for responsible AI use |
| Scope of the AIMS | Which AI systems and processes are being certified |
| AI inventory | Overview of all AI systems with classification |
| Risk analysis and treatment plan | Identified risks and chosen measures |
| Statement of Applicability (SoA) | Which controls you apply and which you do not, with substantiation |
| Data governance documentation | How to handle data for AI systems |
| Process descriptions | Lifecycle of AI systems |
No need for a thick manual. Many organisations work with a digital system or compact documents. The form is free, as long as it is current and accessible.
5.3 Three common mistakes
Mistake 2: Paper tiger
Your documents must correspond with practice. If you write down that you evaluate AI risks monthly, you really should do that. Auditors ask for evidence.
Mistake 3: Starting the proof period too late
You must have worked under your AIMS for at least three months before the external audit can take place. Plan this, otherwise your certification date will be postponed.
6. The ISO 42001 audit
The external audit is the moment of truth. Exciting, but if you are well prepared there is little to worry about.
6.1 Phases one and two
The audit consists of two parts:
Phase 1: Documentation and readiness check (often partly remote)
The auditor reviews your AIMS documentation: policy, AI inventory, risk analysis, Statement of Applicability. Is everything present and consistent? Are you ready for the on-site audit? After phase one you will receive feedback and time to make adjustments.
Phase 2: On-site audit (on location)
Now the auditor comes along. He or she speaks to employees at all levels, reviews AI systems and processes, checks registrations, and verifies whether paper and practice match.
The gist: The auditor is looking for evidence that your AIMS is effective. Not just that procedures exist, but that they work and actually manage AI risks.
6.2 Possible outcomes
| Outcome | What’s happening? |
|---|---|
| Certificate | You meet the requirements |
| Minor deviations | Certificate, but resolve points for next audit |
| Major deviations | Fix first, then reaudit within 90 days |
| Requirements not met | Restart the process |
6.3 Tips for a smooth audit
- Know your AI systems - Know which ones you have, what they are used for, and who is responsible
- Prepare employees - Tell them what to expect. They do not need to know the standard, but they do need to know their own tasks
- Be honest - Don’t try to hide anything. Auditors value openness more than perfection
- Have evidence ready - Risk assessments, training records, decision making. Make sure you can quickly show what the auditor is asking
- View it as an opportunity - A good auditor provides valuable feedback. Use it to really improve
7. Choosing an ISO 42001 certifier
There are still few certifiers active for ISO 42001 in the Netherlands. The market is young - the first accreditations were awarded in January 2025.
7.1 Five criteria to pay attention to
| Criterion | Why important |
|---|---|
| Accreditation | Non-accredited certificates are often not recognised |
| AI experience | An auditor who understands AI and technology adds more value |
| Price | Differences of 20-40% are normal |
| Service | Permanent contact person? Quick responses? Flexibility? |
| Working relationship with the auditor | You will work together for at least three years |
7.2 What is accreditation?
Accreditation bodies audit certifiers. They check whether auditors are qualified for ISO 42001, whether the certifier works independently, and whether the audit is carried out correctly.
Each country has its own authority: the RvA in the Netherlands, UKAS in the United Kingdom, DAkkS in Germany. They recognise each other’s certificates through the IAF (International Accreditation Forum). A certificate from a UKAS-accredited certifier is therefore just as valid as one from an RvA-accredited one.
7.3 Questions to ask
Before you choose, ask potential certifiers these questions:
- Are you accredited for ISO 42001? At which agency?
- What is your experience with AI management systems?
- Does the auditor have experience with our type of AI applications?
- Who will be my auditor? Can I speak to that person in advance?
- What is the lead time from quotation to certificate?
- What are the total costs for three years (including surveillance)?
- How do you deal with deviations during the audit?
The right choice is not necessarily the cheapest. An auditor who understands your AI environment and provides constructive feedback is worth more than a few hundred euros in savings.
Ready to compare? View our overview of certification bodies in the Netherlands and find one that fits your company.
8. Frequently asked questions about ISO 42001
What is ISO 42001?
ISO/IEC 42001:2023 is the international standard for AI management systems (AIMS). The standard helps organisations to develop, implement and use artificial intelligence responsibly. It is the first certifiable AI standard in the world.
How much does ISO 42001 certification cost?
For an SME (20-100 employees): €25,000 - €50,000 in the first year, then €4,000 - €7,000 per year. Smaller companies pay less. The exact price depends on the number of AI systems, complexity and whether you already have a management system.
How long does certification take?
With an existing management system (e.g. ISO 9001/27001): six to nine months. From scratch: nine to eighteen months. The audit itself takes two to five days.
Is ISO 42001 mandatory?
Not formally. But the market actually makes it mandatory: tenders, insurers and clients increasingly require it. For high-risk AI under the EU AI Act, a quality management system is mandatory - ISO 42001 can meet this.
What is the relationship with the EU AI Act?
ISO 42001 and the EU AI Act overlap by 40-50%. The standard helps prepare you for compliance, especially for risk management, data governance and documentation. But ISO 42001 does not replace the law. Separate requirements apply for CE marking and reporting to supervisors.
What is the difference with ISO 27001?
ISO 27001 focuses on information security (CIA triad: confidentiality, integrity, availability). ISO 42001 focuses on AI governance: responsible development and use of AI systems. The standards share the same structure and complement each other.
Want to know more? Read our complete guide to ISO 27001 certification.
Can I do it without a consultant?
Yes. Especially if you already have experience with management systems or have a strong IT team. A consultant can speed things up and prevent pitfalls, but is not mandatory.
How often is an audit after certification?
A surveillance audit (control) every year. Full recertification every three years. Your certificate is valid for three years, provided you successfully complete the annual audits.
Which certifiers are accredited?
In the Netherlands, DNV and BSI have had RvA accreditation for ISO 42001 since January 2025. Other major certifiers (Kiwa, TÜV, LRQA) also offer it but are still working on their Dutch accreditation.
Can I switch certifiers?
Yes, anytime. Your new certifier will take over your file and plan a transfer audit. Your certificate remains valid during the transfer.
This guide is updated regularly. Last checked: January 2026.
