Hael
Book a meeting
ISO/IEC 42001 · Compliance

ISO 42001 compliance

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Compliance means running an AI management system that meets Clauses 4 to 10 and the Annex A controls you selected.
  • You can comply without certifying. Buyers usually want the certificate, because a claim is not checkable.
  • Total first-year cost commonly runs £20,000 to £70,000 including both implementation and certification.
  • Holding ISO 27001 materially reduces the work, because the management system structure and documentation habits carry over.
  • The annual internal audit and management review are permanent commitments, not one-off steps.

What compliance means

ISO 42001 compliance means operating an AI management system that meets the requirements of ISO/IEC 42001: a defined scope, an AI policy, assigned roles, a risk process, impact assessments, the controls you selected in your Statement of Applicability, internal audit, management review and continual improvement.

Certification is separate. You can meet the standard without being certified, and some organisations do. Most that were asked for it by a customer end up certifying, because a certificate is verifiable and a statement is not.

The five stages of a programme

Scope. Decide which parts of the organisation and which AI systems the management system covers. Too narrow and the certificate does not answer the buyer's question. Too wide and you have committed to governing systems nobody asked about.

Build. The AI policy, roles and responsibilities, the AI risk assessment and treatment process, AI system impact assessments, data governance for AI, lifecycle controls, third-party oversight, and the documentation that ties it together. This is the bulk of the work and where judgement earns its fee.

Operate. The system has to run long enough to generate records. Impact assessments completed, risks reviewed, decisions logged, controls evidenced. An auditor samples this period, so it cannot be assembled retrospectively.

Audit. The Clause 9.2 internal audit, then management review, then the certification body's Stage 1 and Stage 2.

Maintain. Surveillance audits in years two and three, recertification at year three, and the internal audit every year. The management system has to keep operating between audits.

What it costs

ComponentTypical range
Gap analysis£5,000 to £15,000
Implementation and readiness£15,000 to £50,000
Certification body fees, initial cycle£4,000 to £20,000 for a small to mid-sized organisation
Annual surveillance audit20% to 40% of the initial audit fee
Annual internal audit£4,000 to £12,000 where outsourced
Total first year, small to mid-sized organisationRoughly £20,000 to £70,000

Cost is driven by the number of AI systems in scope, the number of sites, whether you already hold a management system certification, and how mature your documentation is. Organisations already certified to ISO 27001 consistently spend materially less, because the framework, the audit familiarity and the documented information practices transfer.

How long it takes

Three to six months end to end for an organisation with some governance already in place. The sequence is what sets the floor: build, operate long enough to produce records, internal audit, management review, Stage 1, Stage 2.

Book the certification body early. Availability is a real constraint in a market where accreditation for this standard is still spreading, and a body's earliest Stage 2 slot can move your date more than any internal delay.

Where programmes go wrong

Impact assessments treated as forms. The AI system impact assessment asks about consequences for individuals, groups and society. A short template answer is the finding auditors report most often.

A Statement of Applicability with no reasoning. Excluding controls is allowed. Excluding them without a justification is a nonconformity.

A policy that describes a company that does not exist. It surfaces in the Stage 2 interviews, when someone describes what actually happens.

Records that only exist for the audit period. Surveillance audits sample the year, and a system that stopped operating in month three shows up in month fourteen.

Internal audit left to the last minute, or attempted by someone with no independence. It is required before certification and every year after, and it has to be done by someone who did not build the thing being audited.

The connection to other frameworks

ISO 27001 is the closest relative. Annex D of ISO/IEC 42001 addresses integration, and running one combined management system is substantially cheaper than two. See our ISO 27001 service page.

The EU AI Act is the reason many organisations start. ISO/IEC 42001 builds the governance substance the Act's high-risk duties assume, so the Act's documentation work becomes mapping rather than writing. It does not make you compliant with the Act on its own. See our EU AI Act service page.

SOC 2 and ISO 27001 cover the security and change control ground. Neither addresses AI-specific risks such as impact on affected people, data provenance for training, or lifecycle governance of models.

What has to keep running

The annual internal audit. The management review. Impact assessments for new or materially changed systems. Risk reviews. Records of decisions. Third-party oversight where AI is bought rather than built.

This is what the surveillance audit tests, and it is the part organisations most often let lapse after the certificate arrives. Our continuous governance and assurance service exists for exactly this.

What to do next

Decide your scope before anything else, because it drives cost, timeline and whether the certificate answers your buyer's question.

Our free readiness diagnostic gives a first view, our readiness and gap assessment produces the detailed position for a fixed fee, and the ISO/IEC 42001 service page sets out how we run the programme.

References

FAQ

Can we comply with ISO 42001 without certifying?

Yes. Certification is voluntary. Most organisations asked for it by a customer certify anyway, because a certificate is verifiable.

How much does ISO 42001 compliance cost?

Commonly £20,000 to £70,000 in the first year including implementation and certification, driven by scope and system count.

Does ISO 27001 make it cheaper?

Materially, yes. The management system structure, documentation practices and audit familiarity all transfer, and Annex D addresses integrating the two.

How long does it take?

Three to six months for an organisation with some governance in place, limited by the need for the system to operate long enough to produce records.

What happens after certification?

Annual internal audit, management review, surveillance audits in years two and three, and recertification at year three. The system has to keep running.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.