Hael
Book a meeting
ISO/IEC 42001 · Consultants

ISO 42001 Compliance Consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Consultants come from three backgrounds: management systems, AI and data science, and regulatory practice. A programme needs all three capabilities.
  • The standard was published in December 2023, so nobody has long experience. Judge on ISO 27001 delivery, regulatory work and written output.
  • Ask to see a redacted Statement of Applicability and an AI system impact assessment they have written.
  • Your consultant cannot certify you, and any firm suggesting otherwise is describing separate legal entities.
  • Day rates commonly run £700 to £1,600. Fixed fees are usually better for a first certification.

What consultants do

ISO 42001 compliance consultants build the AI management system, prepare the documentation, run the internal audit where you have nobody independent, and take you through the certification audit.

This guide is about the people. Where they come from, what their credentials mean in a market this young, and how to test capability when almost nobody can point to a decade of delivery.

Where they come from

Management systems. Practitioners from ISO 27001, ISO 9001 or ISO 14001 implementation and audit. Their strength is building a system that runs and produces evidence repeatedly, which is exactly what the certification audit tests. Their limit tends to be depth on how AI systems actually work, which shows in thin impact assessments.

AI and data science. Practitioners who have built and operated machine learning systems. Their strength is understanding data provenance, lifecycle and model behaviour, which makes the impact assessments substantive. Their limit tends to be the management system discipline, which is a distinct craft.

Regulatory practice. Practitioners who have taken organisations through authorisation, supervision or examination. Their strength is judgement about what an examiner accepts as sufficient, which transfers across frameworks. This is our own background, described on the about page.

A programme needs all three. The question is whether the firm brings them or expects you to.

Judging experience in a young market

ISO/IEC 42001 was published in December 2023, and UKAS granted its first accreditations for it in January 2026. Nobody has ten years of delivery.

Three things transfer meaningfully.

ISO 27001 implementation. The management system structure is the same, and Annex D of ISO/IEC 42001 addresses integrating the two. A practitioner who has implemented ISO 27001 properly has done most of the structural work under a different label.

Internal audit experience. Clause 9.2 audits require a specific discipline: independence, sampling, evidence, findings written so they can be closed. It transfers directly.

Regulatory documentation. Anyone who has written for a supervisor knows what "sufficient" looks like, which is the judgement the whole engagement turns on.

What credentials mean

There is no licence to advise on ISO 42001. Common qualifications include ISO/IEC 42001 Lead Implementer and Lead Auditor, ISO 27001 Lead Implementer and Lead Auditor, and general risk or audit certifications. They indicate training completed rather than systems delivered.

More informative: how many management systems has this person taken through a Stage 2 audit, in organisations of roughly your size, and can they show what they wrote.

The two documents that reveal capability

Ask for a redacted Statement of Applicability and a redacted AI system impact assessment.

The Statement of Applicability shows whether they reason. A good one records why each Annex A control applies or does not, in language specific to the organisation. A weak one is a table of ticks.

The impact assessment shows whether they understand the standard's distinctive ask. It should consider consequences for individuals, groups and society, engage with the actual system, and reach conclusions that affect what gets controlled. If it reads like a data protection impact assessment with the words changed, that is the answer.

Ten minutes with those two documents tells you more than any reference.

What a good consultant does differently

They set scope from what your buyers actually ask about, and can explain why each system is in or out.

They tell you early when your target date is not achievable, and explain the arithmetic: build, operate long enough to produce records, internal audit, management review, Stage 1, Stage 2.

They design controls that leave records automatically, because a control that operates without evidence fails a surveillance audit.

They raise the internal audit question before you ask, because most organisations have nobody independent and discover this late.

They know what accreditation means and check the certification body's scope entry rather than assuming.

How they charge

ModelTypical range
Gap analysis, fixed fee£5,000 to £15,000
Full implementation, fixed fee£15,000 to £50,000
Internal audit, per cycle£4,000 to £12,000
Day rate£700 to £1,600
Continuous assurance retainerScope dependent

Fixed fee per phase generally works better than a day rate for a first certification, because it forces the scope conversation to happen before the work. Confirm in writing that certification body fees sit outside.

What no consultant can do

Certify you. Only an accredited certification body can, and it must be a different organisation.

Perform your internal audit if they built the system, if you want that audit to be genuinely independent. Some firms separate the teams; ask how.

Guarantee certification. The certification body decides. A firm promising the outcome is describing a commercial position, not a regulatory one.

What to do next

Work out which of the three capabilities you are short of. If you hold ISO 27001 and have a compliance function, you may need AI depth. If your data science team is strong but nobody has run a management system, you need the opposite.

Our free readiness diagnostic gives a first view, and the ISO/IEC 42001 service page sets out how we work.

References

FAQ

What qualifications should an ISO 42001 consultant have?

No licence is required. Lead Implementer and Lead Auditor training is common. Management systems taken through Stage 2, and written work you can inspect, matter more.

How do I test a consultant's capability?

Ask for a redacted Statement of Applicability and a redacted AI system impact assessment they have written.

Can our consultant certify us?

No. ISO/IEC 17021 prevents a certification body from consulting on a system it certifies, so the two are always separate organisations.

How much does an ISO 42001 consultant cost?

Day rates commonly £700 to £1,600. Fixed fees for a full implementation commonly £15,000 to £50,000, with certification fees separate.

Can the same firm do implementation and internal audit?

Some do, using separate teams. Ask how independence is preserved, because an internal audit of your own work is worth little to a surveillance auditor.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice advising firms through authorisation, supervision and examination. Every engagement has a named practitioner and an agreed scope, timetable and fee. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.