Hael
Book a meeting
ISO/IEC 42001 · Selection

ISO 42001 consultant recommendation

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • The strongest recommendation comes from an organisation that reached certification, not one that started a programme.
  • Certification bodies see the output of many consultancies and can often name firms they have found well prepared, though they cannot recommend for their own audit.
  • Ask what the certificate covers. A narrow scope certified quickly tells you little about a wider engagement.
  • Verify three things: the named practitioner, whether Stage 2 was reached, and any commercial arrangement.
  • Ask for redacted written work. In a market this young it beats a reference.

Where recommendations come from

The most reliable ISO 42001 consultant recommendation comes from an organisation of roughly your size that reached certification within the last eighteen months. That is a smaller pool than for older standards, because ISO/IEC 42001 was published in December 2023 and UKAS granted its first accreditations for it in January 2026.

A recommendation tells you a firm delivered for somebody. It does not tell you the scope, the fee model, who did the work, or whether the certificate came from an accredited body.

Organisations that hold the certificate. The strongest source. Ask what the certificate covers as well as who helped.

Your certification body. If you have already selected one, it sees the finished work of many consultancies and knows which arrive well prepared. It cannot advise you on passing its own audit, but naming firms it has encountered is a different thing and generally allowed. This is the most underused source in the market.

Your ISO 27001 consultant. Many firms that implemented your information security management system now do ISO 42001, and Annex D supports running the two together. The transfer of management system discipline is real, though AI-specific depth varies.

Your compliance platform's partner directory. Vanta, Drata and others list ISO 42001 partners. Listed firms know that platform well. Ask whether referral fees pass in either direction.

Your investors and board. Investors watching portfolio companies through AI governance work often hold a view. Ask about commercial arrangements.

Sector networks. In regulated sectors, peers facing the same buyer or supervisor questions are a good source, and the conversation is usually specific.

What to ask the person recommending

What does the certificate cover? A narrow scope over one product certified quickly is a different engagement from a whole-organisation management system.

Was the certification body accredited for ISO 42001 at the time? Given the January 2026 UKAS date, this is a live question for anything certified earlier.

What went wrong, and how was it handled? Every first certification has friction. A recommendation with none in it usually means the person was not close to the work.

Who did the work? Names. In a young field the individual matters more than the firm.

Did they do your internal audit, and if so how was independence handled? The answer tells you a lot about how the firm thinks.

Would you use them for the surveillance cycle? Future intent is more honest than past satisfaction.

What a recommendation does not tell you

That your scope is comparable. That the same practitioner is available. That the engagement ran through to certification rather than stopping at documentation. That the management system is still running, which surveillance will eventually test.

None of that is a reason to disregard a recommendation. All of it is a reason to treat it as a starting point.

The verification that beats a reference

Ask the firm for two redacted documents they have written: a Statement of Applicability and an AI system impact assessment.

The Statement of Applicability shows whether they reason. Good ones justify each Annex A control's inclusion or exclusion in language specific to the organisation. Weak ones are tables of ticks.

The impact assessment shows whether they understand the standard's distinctive ask about consequences for individuals, groups and society. If it reads like a data protection impact assessment with words changed, that is your answer.

Ten minutes with those two documents tells you more than two reference calls.

Three checks before you act

The named practitioner and committed hours. Ask who runs your programme and how much of their week it gets.

Whether the referenced programme reached Stage 2. "We worked with them" and "they took us to certification" are different statements.

Commercial arrangements. Ask whether the firm pays or receives referral fees, or takes commission from certification bodies. We take none, which is stated on our about page.

If nobody in your network has certified

Common. Shortlist three firms from different sources, give all three the same scope, and ask each to explain how they would handle your internal audit requirement. That question separates firms faster than any other, because it forces them to address independence.

The full question set is in Recommendations for a Good ISO 42001 Compliance consultant.

What to do next

Draft a provisional scope before asking anyone for a recommendation. Cost and effort scale with what is in scope, so a recommendation given against a vague brief arrives against a vague engagement.

Our free readiness diagnostic gives a starting view, and the ISO/IEC 42001 service page sets out how we work.

References

FAQ

Where can I get an ISO 42001 consultant recommendation?

From organisations that hold the certificate, your certification body, your ISO 27001 consultant, compliance platform partner directories, investors and sector networks.

Can our certification body recommend a consultant?

It can generally name firms it has found well prepared. It cannot advise you on passing its own audit, and it cannot consult on the system it will certify.

How do I check a recommendation is meaningful?

Ask what the certificate covered, whether the certification body was accredited for ISO 42001, and whether the engagement reached Stage 2.

What is the single best verification?

Ask for a redacted Statement of Applicability and AI system impact assessment the firm has written.

Should the same firm do implementation and internal audit?

Only with genuine separation of practitioners. Ask how independence is preserved before accepting the arrangement.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Every engagement has a named practitioner and an agreed scope, timetable and fee. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.