Hael
Book a meeting
ISO/IEC 42001 · Cost

The budget-friendly ways to get ISO 42001 certified

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Scope is the biggest lever. A management system covering more than your buyers asked about costs more in audit days and internal hours.
  • Integrate with ISO 27001 rather than building a second system. Annex D supports it and the saving is substantial.
  • Get quotes from three accredited certification bodies. Fees vary widely in a market with limited capacity.
  • Preparation reduces audit duration. Well-documented organisations can justify shorter audits under ISO/IEC 42006.
  • Do not economise on the impact assessments or the internal audit. Both are where thin work becomes a finding.

Where the money goes

The cheapest route to ISO 42001 is a correctly scoped management system, integrated with what you already run, prepared well enough that the audit is short. Most overspend comes from scoping too broadly, building a parallel system alongside an existing one, or arriving underprepared and paying for a longer audit and a repeat visit.

A realistic first-year total for a small to mid-sized organisation is £20,000 to £70,000 including implementation and certification. The decisions below move you towards the lower end.

LineTypical costAvoidable?
Gap analysis£5,000 to £15,000No, and skipping it usually costs more
Implementation£15,000 to £50,000Partly, through scope and integration
Certification body, initial cycle£4,000 to £20,000Partly, through scope, preparation and quotes
Internal audit£4,000 to £12,000Partly, by combining with ISO 27001
Internal team timeFrequently the largest costPartly, through project management
Surveillance, years two and three20% to 40% of the initial audit feeNo

1. Scope to what your buyers actually ask about

Scope drives audit days, which drives the certification fee, and it drives internal hours, which is the larger cost.

Start from the question you are being asked. If a customer wants assurance about the AI in one product, a management system scoped to that product and the teams supporting it answers them. Certifying the whole organisation because it sounds stronger buys audit days nobody requested.

The counterweight: a scope so narrow that the certificate's scope statement does not cover the system your buyer cares about is the most expensive outcome, because you pay twice.

2. Integrate with ISO 27001

If you hold ISO 27001, this is the single largest saving available. Annex D of ISO/IEC 42001 addresses integration directly.

The management system structure, documented information practices, internal audit discipline, management review, supplier controls and corrective action process all carry over. What is genuinely new is the AI system inventory, the AI system impact assessment, data governance for AI and model lifecycle controls.

Organisations already certified consistently spend materially less. Running two separate management systems, by contrast, doubles the maintenance permanently.

3. Get three quotes, and ask about audit days

Certification body fees vary widely, partly because accredited capacity is limited. Ask each body for its fee, its accreditation scope entry for ISO/IEC 42001, and the number of audit days it proposes.

Audit duration is calculated under ISO/IEC 42006, which allows certification bodies some justified flexibility. A well-structured management system with strong documentation and thorough preparation can support a shorter duration, which reduces the fee directly.

Do not choose on price alone. An auditor with real AI competence makes for a better audit, and a body with no availability for five months costs you more than a higher fee would.

4. Prepare properly so the audit is short

This is the mechanism behind the previous point. Stage 1 exists to find things that would prevent a successful Stage 2. Arriving with an incomplete Statement of Applicability, no internal audit and no management review turns Stage 1 into a rehearsal and pushes Stage 2 out.

A gap analysis before you book the audit is the cheapest form of this preparation. Our readiness and gap assessment is a fixed fee for that reason.

5. Combine the internal audits

Where you hold both ISO 27001 and ISO 42001, one integrated internal audit across both management systems normally costs less than two separate engagements and takes less of your people's time.

The auditor still has to cover both sets of requirements, but the planning, the interviews and the reporting compress.

6. Reuse the governance you already have

Most organisations already do some of this informally. Systems get reviewed before launch. Someone signs off on model changes. Suppliers get assessed.

The work is usually formalising and recording rather than inventing. Before commissioning anything, map what already happens, because a gap analysis that starts from an accurate picture of current practice is shorter and the remediation list is smaller.

7. Name an internal owner

The most expensive arrangement is the implicit one, where the management system belongs to everybody and nobody. Tasks wait, the audit date does not move, and the final stretch gets bought at premium rates.

Naming an owner with protected hours costs nothing and is the highest-return decision available.

8. Plan for surveillance from the start

Surveillance audits in years two and three sample the year. A management system that stopped operating after the certificate arrived produces nonconformities and a remediation bill.

Keeping it running is a small ongoing cost. Rebuilding it under surveillance pressure is not. That is what our continuous governance and assurance service is for.

What not to cut

The AI system impact assessments. Thin ones are the most commonly reported finding, and a finding at Stage 2 costs more than doing them properly would have.

The internal audit. It is required, it cannot come from your certification body, and an audit designed to reassure produces a comfortable report and a surprise at Stage 2.

Accreditation. A cheaper certificate from a body without ISO/IEC 42001 in its accreditation scope is a false economy, because sophisticated buyers check.

What to do next

Settle scope first, then ask three accredited bodies for quotes including proposed audit days. Those two steps set most of your cost.

Our free readiness diagnostic gives an immediate first view, and the ISO/IEC 42001 service page sets out how we run the programme.

References

FAQ

What is the cheapest way to get ISO 42001 certified?

A scope matched to what your buyers ask about, integrated with an existing ISO 27001 management system, prepared well enough to justify a shorter audit, with quotes from three accredited bodies.

Does holding ISO 27001 reduce the cost?

Materially. The management system structure, documentation practices and audit discipline all transfer, and Annex D supports integration.

Can we reduce the certification fee?

Partly. Fees follow audit days, and a well-prepared, well-documented system can support a shorter duration under ISO/IEC 42006. Quotes also vary between bodies.

Is an unaccredited certificate cheaper?

Often, and it is a false economy. Buyers with mature vendor review processes check accreditation scope.

What are the ongoing costs?

Surveillance audits at 20% to 40% of the initial audit fee in years two and three, the annual internal audit, and the internal time to keep the system running.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Every engagement has a named practitioner and an agreed scope, timetable and fee, with certification body costs shown separately. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.