How Best to Proceed with ISO 42001
- Proceed in this order: buyer requirement, scope, gap analysis, build, operate, internal audit, management review, Stage 1, Stage 2, then maintain.
- Scope is the decision that is hardest to reverse and it belongs at the start.
- Book the certification body early. Availability moves dates more than internal delay does.
- The system has to operate long enough to produce records. That period cannot be compressed.
- Plan the annual cycle at the same time as the certificate, because surveillance samples the year.
Stage 1: The requirement
Proceed in this order: establish what your buyer or regulator actually needs, set the scope, run a gap analysis, build the management system, operate it long enough to produce records, complete the internal audit and management review, then Stage 1 and Stage 2, then maintain it. The common mistake is starting with documentation before scope is agreed, which produces work that has to be redone.
Each stage below carries a decision that is hard to reverse. Those are the ones worth slowing down for.
Find out precisely what is being asked. Three questions.
Who is asking, and what will satisfy them? A certificate, a completed questionnaire, or evidence of governance without certification. Some organisations need the management system and not the audit.
What must the certificate cover? The scope statement on the certificate is what a buyer reads. If it does not name the system they care about, it does not answer them.
What is the real deadline, and what happens if it moves? Contractual deadlines and aspirational ones lead to very different plans.
Where Microsoft SSPA applies, or where a customer contract names ISO 42001, the answer is usually fixed. See US ISO 42001 consultants for the SSPA position.
Decision: whether you certify, and what the certificate must say.
Stage 2: Scope
Which organisational units, which AI systems, which locations. Name exclusions as well as inclusions.
Scope drives audit days, which drives the certification fee, and it drives internal hours, which is the larger cost. Too wide and you pay for governance nobody asked about. Too narrow and the certificate does not answer the question.
Decision: the scope statement. This is the hardest thing to change once an audit is booked.
Stage 3: Ownership
Name the person who owns the management system and protect their hours. Decide at this point whether you need external help, and answer honestly: does that person have both management system experience and available time.
Bring a firm in now rather than after the gap analysis. A consultant who joins after scope is set inherits decisions they would have advised against.
Decision: internal, external, or both, and who specifically.
Stage 4: Gap analysis
A clause-by-clause position against Clauses 4 to 10, a control-by-control position against the 38 Annex A controls, a draft Statement of Applicability, and a remediation plan.
Do this before booking the certification body, so remediation happens on your timetable rather than between Stage 1 and Stage 2.
Decision: the remediation plan and who does each item.
Stage 5: Build
The AI policy. Roles and responsibilities. The AI risk assessment and treatment process. The AI system impact assessment method, and the first assessments completed. Data governance for AI. Lifecycle controls. Third-party oversight for bought systems. The Statement of Applicability with justified inclusions and exclusions. The documentation set.
Two items take longest and should start first. The impact assessments, because they require input from people who understand the systems. And any control that needs an engineering change, because those sit in someone else's backlog.
Decision: which processes genuinely change, as opposed to which documents get written.
Stage 6: Operate
The system has to run long enough to generate records an auditor can sample: assessments completed, risks reviewed, decisions logged, controls evidenced, suppliers assessed.
This is the constraint that sets your floor. It cannot be assembled retrospectively, and a Stage 2 auditor is specifically looking for whether it was.
Decision: none, if the earlier stages were done properly. That is the point of them.
Stage 7: Internal audit and management review
The Clause 9.2 internal audit, performed by someone competent and independent of building the system. Then the Clause 9.3 management review, where leadership considers the results and records decisions.
The order matters: audit, then review, then certification audit. The certification body will look for both and will treat a management review that rubber-stamps a report as a finding.
Decision: who performs the internal audit, and how independence is preserved.
Stage 8: Stage 1 and Stage 2
Stage 1 reviews your documentation and readiness and reports anything that would prevent a successful Stage 2. Stage 2 tests whether the system operates, through interviews and sampling.
Brief the people who will be interviewed. What they say should match what the documents claim, and where it does not, the document is usually the thing that is wrong.
Book the body early. Availability is a real constraint while accredited capacity is still spreading.
Stage 9: Maintain
Surveillance audits in years two and three, recertification at year three, and an internal audit every year. Impact assessments when systems are added or materially changed. Risk reviews. Records of decisions.
Plan this at the same time as the certificate, not afterwards. Surveillance samples the year, and a system that stopped in month three is found in month fourteen. Our continuous governance and assurance service covers it.
The order in one table
| Stage | Output | Decision that is hard to reverse |
|---|---|---|
| 1. Requirement | Written statement of what is needed | Whether to certify |
| 2. Scope | The scope statement | The scope itself |
| 3. Ownership | A named owner with protected hours | Internal, external or both |
| 4. Gap analysis | Clause and control position, remediation plan | The remediation plan |
| 5. Build | Policy, processes, assessments, Statement of Applicability | Which processes change |
| 6. Operate | Records across a period | None |
| 7. Internal audit and review | Findings, corrective actions, management decisions | Who audits, and independence |
| 8. Stage 1 and Stage 2 | The certificate | None |
| 9. Maintain | A running management system | Who owns the annual cycle |
What sets the timeline
Three to six months is realistic for an organisation with some governance in place. Faster where ISO 27001 already exists. Slower from nothing.
Two things you cannot compress: the operating period needed to produce records, and the certification body's availability. Both should be planned early rather than discovered late.
What to do next
Settle the requirement and the scope. Those two decisions determine cost, timeline and whether the certificate does its job.
Our free readiness diagnostic gives a first view, and the ISO/IEC 42001 service page sets out how we run each stage.
References
FAQ
What is the first step in an ISO 42001 programme?
Establishing precisely what your buyer or regulator needs, including what the certificate's scope statement must cover.
When should we contact certification bodies?
Early, for availability and quotes, but commit to an audit window only after the gap analysis, so remediation happens on your timetable.
How long does certification take?
Three to six months for an organisation with some governance in place, limited by the operating period and by certification body availability.
Can we shorten the operating period?
Not meaningfully. The auditor samples records across a period, and assembling them afterwards is what Stage 2 is designed to detect.
What happens after the certificate?
Annual internal audit, management review, surveillance audits in years two and three, and recertification at year three.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, taking companies through ISO/IEC 42001 from gap analysis to certificate and maintaining the position afterwards. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.