Hael
Book a meeting
ISO/IEC 42001 · Services

ISO 42001 Readiness and Compliance Services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Readiness establishes what the standard requires of you specifically, and what you already have.
  • The deliverable is a clause-by-clause and control-by-control position, plus a Statement of Applicability plan, not an opinion that you are ready.
  • Run readiness before booking a certification body, so remediation happens on your timetable.
  • Readiness typically costs £5,000 to £15,000 and takes two to four weeks.
  • The most common finding is that governance exists informally but leaves no record an auditor can sample.

What readiness services are

ISO 42001 readiness services establish where you stand against the standard before you commit to a certification date. The output is a clause-by-clause position against Clauses 4 to 10, a control-by-control position against Annex A, a draft view of what belongs in your Statement of Applicability, and a remediation plan.

Compliance services then cover the build that follows: writing the management system, running it long enough to generate records, completing the internal audit and management review, and supporting the certification audit.

What a readiness assessment should contain

ElementWhat good looks like
Scope proposalWhich parts of the organisation and which AI systems the management system will cover, and what is excluded
AI system inventoryEvery system in the proposed scope, with owner, purpose and data
Clause-by-clause positionClauses 4 to 10 assessed individually, with current evidence and a judgement on sufficiency
Annex A control positionEach of the 38 controls assessed as applicable or not, with a draft justification for exclusions
Impact assessment approachHow AI system impact assessments will be conducted and what they need to cover
Remediation planWhat closes each gap, who does it, how long it takes
Certification routeWhich accredited bodies are appropriate, and the earliest defensible audit window
Delivery callA conversation where the scope decisions and borderline judgements get explained

Findings should be stated as findings. "These clauses are met, these are not, this is what closes each" is defensible and useful. "You are ready to certify" is a warranty, and the certification body decides that, not your adviser.

When to run readiness

Before you engage a certification body, and before you write any documentation.

Two reasons. Certification bodies price from your scope and maturity, so knowing both produces an accurate quote rather than an optimistic one. And any gap found by the auditor at Stage 1 delays Stage 2, which moves your certificate date by weeks or months in a market where audit slots are not always available at short notice.

Our readiness and gap assessment is delivered as a fixed fee with a delivery call for this reason.

Readiness versus certification

They are different engagements with different purposes and they cannot be combined.

Readiness is advisory. Its purpose is to help you, and the firm doing it can tell you exactly what to fix and how.

Certification is independent. Its purpose is to form a judgement, and under ISO/IEC 17021 the certification body cannot consult on the system it will certify. Your certifier cannot help you prepare, which is precisely why readiness exists as a separate service.

What readiness commonly finds

Governance that happens but leaves no record. Teams often do review AI systems before launch. They do it in meetings and chat threads, so there is nothing an auditor can sample.

No defined scope. Without one, every conversation about controls goes in circles, because nobody has agreed what is in.

Impact assessment confused with risk assessment. The AI system impact assessment looks at consequences for individuals, groups and society. A risk assessment looks at threats to the organisation. Both are required and they are not the same document.

Bought AI systems left out. AI features inside purchased software are systems within scope, and the third-party control requirements apply to them.

No independent internal auditor. Clause 9.2 requires one before certification, and small organisations rarely have anyone who both understands the system and did not build it.

ISO 27001 documentation that could be reused but has not been. Annex D of the standard addresses integration, and organisations already certified are usually further along than they realise.

Cost and timing

ServiceTypical costTypical duration
Readiness and gap analysis£5,000 to £15,0002 to 4 weeks
Implementation and build£15,000 to £50,0002 to 4 months
Operating period before auditInternal effortLong enough to produce records
Internal audit£4,000 to £12,0001 to 2 weeks
Certification body, Stage 1 and Stage 2£4,000 to £20,0004 to 8 weeks including scheduling

Cost scales with the number of AI systems in scope, the number of sites, and whether you already hold a management system certification.

What compliance services cover after readiness

Writing the AI policy and assigning roles. Building the risk assessment and treatment process. Establishing the impact assessment method and completing the first assessments. Data governance for AI. Lifecycle controls. Third-party oversight. The Statement of Applicability with justified inclusions and exclusions. The documentation set. Then running the system, the internal audit, the management review, and supporting both audit stages.

What to do next

Decide your scope first, at least provisionally. It is the input every proposal needs and the decision that most affects cost.

Our free readiness diagnostic gives an immediate first view, and the ISO/IEC 42001 service page sets out how readiness and implementation fit together.

References

FAQ

What is an ISO 42001 readiness assessment?

A clause-by-clause and control-by-control comparison of your current position against the standard, with a remediation plan and a proposed scope.

Can our certification body do the readiness assessment?

No. Under ISO/IEC 17021 a certification body cannot consult on the system it will certify.

How long does readiness take?

Two to four weeks for most organisations, including the delivery call.

What does readiness cost?

Typically £5,000 to £15,000, scaling with the number of AI systems and sites in scope.

Do we need readiness if we hold ISO 27001?

It is usually shorter and cheaper, because much of the management system already exists, but the AI-specific requirements such as impact assessment still need assessing.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Our readiness and gap assessment is delivered as a fixed fee with a delivery call, and states findings clause by clause and control by control rather than issuing an opinion. We are not a certification body and we do not issue certificates. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.