ISO 42001 certification: responsible AI management

ISO 42001 certification: responsible AI management

A practical guide to ISO 42001 certification for organisations developing or using artificial intelligence.

Last updated: 7 September 2026 | 14 min. read

ISO 42001 is the international standard for AI management systems. The standard helps you to develop, implement and use artificial intelligence responsibly. From chatbots to predictive models, from image recognition to decision support.

In this guide you will read everything you need to know: from the basic principles to the costs, from preparation to choosing a certifier. No sales pitches, just clear information.


1. What is ISO 42001?

ISO/IEC 42001:2023 is the first international standard for an Artificial Intelligence Management System (AIMS). The standard describes requirements for the responsible development, implementation and use of AI systems within your organisation.

In short: ISO 42001 helps you systematically identify, manage and reduce AI risks. From bias in algorithms to privacy impact, from transparency to human control.

With an ISO 42001 certificate you demonstrate that your company has a working AI management system, actively manages risks and continuously improves in the field of responsible AI.

1.1 The core of ISO 42001

ISO 42001 revolves around four core areas:

Core areaWhat it means
AI governanceClear policies, roles and responsibilities for AI
Risk ManagementSystematically identify and manage AI risks
Life cycleFrom development to phase-out: every phase controlled
Continuous improvementLearning from incidents, adapting to new insights

The standard is not limited to high-risk AI. Any organisation that develops or uses AI can certify, regardless of the risk profile.

1.2 Annex A: the 38 controls

An important part of ISO 42001 is Annex A. This is a catalogue of 38 AI-specific management measures (controls) divided over nine domains:

DomainCore focus
Policies and proceduresAI governance framework
ResourcesBudget, people, resources
AccountabilityRoles and ownership
AI inventoryOverview of all AI systems
Life cycleFrom development to phase-out
Data governanceData quality and origin
TransparencyInformation to stakeholders
UseDeploy safely and responsibly
Customer RelationsAgreements and contracts

You don’t have to apply all 38 controls. In your Statement of Applicability you record which controls are relevant to your organisation and why.

1.3 Current version: ISO/IEC 42001:2023

info

The current and first version is ISO/IEC 42001:2023, published in December 2023. It is the first certifiable AI management system standard in the world.

Accreditation: Since January 2025, DNV and BSI have been accredited by the RvA for ISO 42001 certification in the Netherlands.


2. Why certify ISO 42001?

A certificate is not a goal in itself. It is a means. The question is: does it help your business?

2.1 Five concrete benefits

tip
The most important reason for most companies: customers, clients and tenders demand it. ISO 42001 is increasingly becoming a strict requirement, especially for government projects and in sectors where AI risks are high.

In addition to access to assignments, there are more benefits:

  • Better risk management - You systematically identify and manage AI risks. From bias to privacy, from transparency to security.
  • Demonstrated compliance - Prepare for the EU AI Act and demonstrate that you handle AI responsibly. Supervisors and customers appreciate a certificate.
  • Customer Trust - You show that you take AI seriously. This makes a difference, especially in sensitive applications (HR, finance, healthcare).
  • Foundation for extension - ISO 42001 shares the same structure with ISO 9001 and ISO 27001. Integration is simple.
  • Competitive advantage - The standard is new. Early certification sets you apart from competitors.

2.2 For whom is it relevant?

ISO 42001 is relevant for any organisation that develops, implements or uses AI. But some benefit more from it:

SectorWhy relevant
IT and softwareDeveloping AI solutions, customers demand it
FinanceCredit assessment, fraud detection, compliance requirements
CareDiagnostic support, patient data, high risks
HR and recruitmentCV screening, interview tools, bias risk
GovernmentProcurement requirements, public accountability
EcommerceRecommendation algorithms, personalization

2.3 When it may not be necessary

Honest advice: certification is not the best choice for everyone.

Ask yourself this question: Do I use AI in my business processes? Do my customers or clients expect it? If not, carefully consider whether the investment is worth it.

Other situations in which you have to be critical:

  • If you only use standard office tools without AI components
  • Very small organisations without AI systems are unlikely to have the ROI
  • If you just want a certificate for the sake of having it, without really improving the processes
note
Alternative: You can also work according to ISO 42001 without certification. You implement the approach internally, but skip the external audit. No certificate, but better AI governance.

3. The ISO 42001 certification process

You go through six steps from decision to certificate. Count on nine to eighteen months, depending on your starting position and AI complexity.

3.1 The six steps to certification

  1. Determine scope - Which AI systems, processes and departments are covered by the AIMS? If necessary, start with your most important AI applications.

  2. AI inventory and risk analysis - Take an overview of all AI systems and identify the risks. This is the heart of ISO 42001.

  3. Set up AIMS - Implement controls, establish policies, train employees, and document processes.

  4. Complete Evidence Period - Work under your AIMS for a minimum of three months. Auditors want proof that the system works in practice.

  5. Internal audit and management review - Verify that everything is working and have management formally assess the AIMS.

  6. External audit - The certifier carries out the audit in two phases. If successful you will receive the certificate.

3.2 The external audit: phases one and two

info

Phase 1 (Stage 1) is a documentation and readiness check. The auditor reviews your AIMS documentation, AI inventory and risk analysis. Usually lasts one to two days.

Phase 2 (Stage 2) is the on-site practical audit. The auditor speaks with employees, checks processes and verifies whether paper and practice correspond. Lasts two to four days.

3.3 Timeline

Your situationLead timeAudit duration
Already have a management system (e.g. ISO 9001/27001)6-9 months2-3 days
Good basis, but no AIMS yet9-15 months3-4 days
Complex AI environment or multiple systems12-18 months4-5 days

3.4 Who does what?

PartyRole
YouAI inventory, risk analysis, setting up AIMS, internal audits
IT/Data teamDocumenting AI systems, technical measures
Consultant (optional)Guidance, gap analysis, templates, training
CertifierPerform audit, issue certificate
Accreditation bodyChecks the certifier (RvA, UKAS, etc.)

Good to know: A consultant is not mandatory. Organisations with experienced IT and compliance people can do it themselves. However, guidance can speed up the process.


4. What does ISO 42001 cost?

The costs vary. They depend on your company size, AI complexity and whether you hire a consultant. ISO 42001 is comparable to ISO 27001 in terms of investment.

Rule of thumb for SMEs: Count on €15,000 - €35,000 in the first year, then €3,000 - €7,000 per year.

4.1 Cost items overview

Cost itemIndication
Certification audit (year 1)€6,000 - €12,000
Surveillance audit (per year)€2,000 - €4,000
Recertification (every three years)€5,000 - €10,000
Consultant (optional)€10,000 - €25,000
Training€500 - €2,500 per person
Internal hours150 - 300+ hours

4.2 Price indication per company size

Company sizeFirst yearAnnually thereafter
Small (up to 20 FTE)€10,000 - €25,000€2,000 - €4,000
Medium (20-100 FTE)€25,000 - €50,000€4,000 - €7,000
Large (100+ FTE)€40,000 - €80,000+€7,000 - €15,000+

Prices indicative, excl. VAT, including consultant and internal hours.

4.3 What influences the price?

Five factors determine your costs:

  1. Number of AI systems (more = more audit time)
  2. AI complexity (own development vs purchased tools)
  3. Number of employees (scope of the AIMS)
  4. Current maturity (starting from scratch is more expensive than optimizing)
  5. Certifier’s choice (prices vary 20-40%)
tip
Save through integration. Do you already have ISO 9001 or ISO 27001? Then you can save 40-50% on implementation time. Documentation and processes are largely reusable.

5. Preparation for ISO 42001

Good preparation is half the battle. Most of the time is spent on the AI ​​inventory and setting up your AIMS, not on the audit itself.

5.1 What do you need to arrange internally?

note
First step: Ensure commitment from management. AI governance is a management responsibility. Without support from above, certification becomes a difficult process.

Then follow these steps:

  • Appoint project leader - Someone with a mandate, AI knowledge and time to spare
  • Create AI inventory - What AI systems do you have? What are they used for?
  • Determine scope - Which systems and processes are covered by the AIMS?
  • Perform risk analysis - Identify risks per AI system
  • Implement measures - Technical and organizational, based on the risk analysis
  • Create awareness - Train employees on responsible AI use
  • Start proof period - Work for at least three months according to the AIMS

5.2 What documentation is needed?

The standard requires at least:

DocumentWhat it is
AI PolicyYour vision and goals for responsible AI use
Scope of the AIMSWhich AI systems and processes are being certified
AI inventoryOverview of all AI systems with classification
Risk analysis and treatment planIdentified risks and chosen measures
Statement of Applicability (SoA)Which controls you apply and which you do not, with substantiation
Data governance documentationHow to handle data for AI systems
Process descriptionsLifecycle of AI systems

No need for a thick manual. Many organisations work with a digital system or compact documents. The form is free, as long as it is current and accessible.

5.3 Three common mistakes

warning
Mistake 1: Underestimating what AI is. ISO 42001 is not just about complex machine learning. This also includes a simple chatbot or recommendation algorithm. Take a complete inventory.

Mistake 2: Paper tiger

Your documents must correspond with practice. If you write down that you evaluate AI risks monthly, you really should do that. Auditors ask for evidence.

Mistake 3: Starting the proof period too late

You must have worked under your AIMS for at least three months before the external audit can take place. Plan this, otherwise your certification date will be postponed.


6. The ISO 42001 audit

The external audit is the moment of truth. Exciting, but if you are well prepared there is little to worry about.

6.1 Phases one and two

The audit consists of two parts:

Phase 1: Documentation and readiness check (often partly remote)

The auditor reviews your AIMS documentation: policy, AI inventory, risk analysis, Statement of Applicability. Is everything present and consistent? Are you ready for the on-site audit? After phase one you will receive feedback and time to make adjustments.

Phase 2: On-site audit (on location)

Now the auditor comes along. He or she speaks to employees at all levels, reviews AI systems and processes, checks registrations, and verifies whether paper and practice match.

The gist: The auditor is looking for evidence that your AIMS is effective. Not just that procedures exist, but that they work and actually manage AI risks.

6.2 Possible outcomes

OutcomeWhat’s happening?
CertificateYou meet the requirements
Minor deviationsCertificate, but resolve points for next audit
Major deviationsFix first, then reaudit within 90 days
Requirements not metRestart the process
info
Most well-prepared organisations obtain the certificate in one go. Small deviations are common and are not a disaster - they indicate areas for improvement.

6.3 Tips for a smooth audit

  1. Know your AI systems - Know which ones you have, what they are used for, and who is responsible
  2. Prepare employees - Tell them what to expect. They do not need to know the standard, but they do need to know their own tasks
  3. Be honest - Don’t try to hide anything. Auditors value openness more than perfection
  4. Have evidence ready - Risk assessments, training records, decision making. Make sure you can quickly show what the auditor is asking
  5. View it as an opportunity - A good auditor provides valuable feedback. Use it to really improve

7. Choosing an ISO 42001 certifier

There are still few certifiers active for ISO 42001 in the Netherlands. The market is young - the first accreditations were awarded in January 2025.

7.1 Five criteria to pay attention to

CriterionWhy important
AccreditationNon-accredited certificates are often not recognised
AI experienceAn auditor who understands AI and technology adds more value
PriceDifferences of 20-40% are normal
ServicePermanent contact person? Quick responses? Flexibility?
Working relationship with the auditorYou will work together for at least three years
warning
Pay attention to accreditation. Always choose an accredited certifier. Non-accredited certificates are often not recognised by clients. In the Netherlands, DNV and BSI are RvA accredited. Other certifiers such as Kiwa and TÜV are still working on their accreditation.

7.2 What is accreditation?

Accreditation bodies audit certifiers. They check whether auditors are qualified for ISO 42001, whether the certifier works independently, and whether the audit is carried out correctly.

Each country has its own authority: the RvA in the Netherlands, UKAS in the United Kingdom, DAkkS in Germany. They recognise each other’s certificates through the IAF (International Accreditation Forum). A certificate from a UKAS-accredited certifier is therefore just as valid as one from an RvA-accredited one.

7.3 Questions to ask

Before you choose, ask potential certifiers these questions:

  • Are you accredited for ISO 42001? At which agency?
  • What is your experience with AI management systems?
  • Does the auditor have experience with our type of AI applications?
  • Who will be my auditor? Can I speak to that person in advance?
  • What is the lead time from quotation to certificate?
  • What are the total costs for three years (including surveillance)?
  • How do you deal with deviations during the audit?

The right choice is not necessarily the cheapest. An auditor who understands your AI environment and provides constructive feedback is worth more than a few hundred euros in savings.

note

Ready to compare? View our overview of certification bodies in the Netherlands and find one that fits your company.

Compare certification bodies →


8. Frequently asked questions about ISO 42001

What is ISO 42001?

ISO/IEC 42001:2023 is the international standard for AI management systems (AIMS). The standard helps organisations to develop, implement and use artificial intelligence responsibly. It is the first certifiable AI standard in the world.

How much does ISO 42001 certification cost?

For an SME (20-100 employees): €25,000 - €50,000 in the first year, then €4,000 - €7,000 per year. Smaller companies pay less. The exact price depends on the number of AI systems, complexity and whether you already have a management system.

How long does certification take?

With an existing management system (e.g. ISO 9001/27001): six to nine months. From scratch: nine to eighteen months. The audit itself takes two to five days.

Is ISO 42001 mandatory?

Not formally. But the market actually makes it mandatory: tenders, insurers and clients increasingly require it. For high-risk AI under the EU AI Act, a quality management system is mandatory - ISO 42001 can meet this.

What is the relationship with the EU AI Act?

ISO 42001 and the EU AI Act overlap by 40-50%. The standard helps prepare you for compliance, especially for risk management, data governance and documentation. But ISO 42001 does not replace the law. Separate requirements apply for CE marking and reporting to supervisors.

What is the difference with ISO 27001?

ISO 27001 focuses on information security (CIA triad: confidentiality, integrity, availability). ISO 42001 focuses on AI governance: responsible development and use of AI systems. The standards share the same structure and complement each other.

Want to know more? Read our complete guide to ISO 27001 certification.

Can I do it without a consultant?

Yes. Especially if you already have experience with management systems or have a strong IT team. A consultant can speed things up and prevent pitfalls, but is not mandatory.

How often is an audit after certification?

A surveillance audit (control) every year. Full recertification every three years. Your certificate is valid for three years, provided you successfully complete the annual audits.

Which certifiers are accredited?

In the Netherlands, DNV and BSI have had RvA accreditation for ISO 42001 since January 2025. Other major certifiers (Kiwa, TÜV, LRQA) also offer it but are still working on their Dutch accreditation.

Can I switch certifiers?

Yes, anytime. Your new certifier will take over your file and plan a transfer audit. Your certificate remains valid during the transfer.


This guide is updated regularly. Last checked: January 2026.

Compare ISO 42001 certification bodies

Find a certification body with relevant AI governance experience.

Request free quotations