Hael
Book a meeting
ISO/IEC 42001 · Selection

Recommendations for a Good ISO 42001 Compliance consultant

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Score candidates on seven things: scoping, written work, impact assessment depth, internal audit independence, certification body knowledge, honesty about timelines, and no commission arrangements.
  • The internal audit question is the fastest test. A firm that volunteers the independence issue is thinking properly.
  • Ask for a redacted Statement of Applicability. It shows whether they reason or tick.
  • Insist the fee shows certification body costs as a separate line.
  • A good consultant tells you your target date is unachievable on the first call, with the arithmetic.

The seven marks

A good ISO 42001 compliance consultant does three things a weaker one does not. They scope from what your buyers and regulators actually ask about. They write a Statement of Applicability and impact assessments that reason rather than tick. And they raise the internal audit independence problem before you have to.

Everything below tests for those during the selection conversation. Use it as a scorecard across two or three firms.

MarkWhat good looks likeHow to test it
ScopingStarts from your buyers, your regulator and your AI estateAsk how they would scope your management system, before fees
Written workDocuments that reason, specific to the organisationAsk for a redacted Statement of Applicability
Impact assessment depthConsiders consequences for individuals, groups and society, tied to real systemsAsk for a redacted AI system impact assessment
Internal audit independenceRaises it unprompted and proposes a genuine separationAsk who would audit the system they built
Certification body knowledgeKnows accreditation scopes and availabilityAsk which bodies they would recommend and why
Honesty about timelinesDoes the arithmetic out loudGive a deliberately tight date
IndependenceNo commission from certification bodiesAsk directly, in writing

1. How they scope

Scope decides the audit fee, the workload and whether the certificate answers your buyer's question. A good consultant asks who is asking you for this, what they need to see, what AI you build, what you buy, and which parts of the organisation touch it.

A weak approach applies a standard scope. That produces either a certificate covering more than anyone asked about, or one so narrow that a buyer reads the scope statement and comes back with questions.

Ask a candidate to sketch your scope in the conversation. Two minutes of reasoning is more informative than any credential.

2. What they write

Ask for a redacted Statement of Applicability.

Annex A has 38 controls across nine objectives. You include what applies and justify what you exclude. A good Statement of Applicability records why, in language specific to the organisation. A weak one is a grid of ticks with boilerplate justifications, and it is the first document a Stage 1 auditor reads.

3. How deep their impact assessments go

The AI system impact assessment is the standard's distinctive requirement and the one auditors most often find thin.

It asks about consequences for individuals, groups and society, which is a different question from what an information security risk assessment asks. Ask for a redacted example. Look for engagement with a real system, consideration of affected people rather than only the organisation, and conclusions that actually changed what got controlled.

4. How they handle internal audit independence

This is the fastest test in the whole conversation.

Clause 9.2 requires an internal audit before certification and annually after. Your certification body cannot do it. The standard requires objectivity and impartiality, which means the person who built the management system should not audit it.

A good consultant raises this before you ask, and proposes something concrete: a separate practitioner in their firm, a third party, or training someone independent inside your organisation. A weaker one offers to do it themselves without mentioning the issue.

Our own approach is to use a separate practitioner where we built the system, described in ISO 42001 - Internal Audit Consultants.

5. Whether they know the certification market

Ask which certification bodies they would recommend and why, and whether those bodies hold accreditation for ISO/IEC 42001 specifically.

UKAS granted its first accreditations for the standard in January 2026, and ANAB has been building its scheme over a similar period. A consultant who cannot speak to accreditation scope, or who treats all certification bodies as interchangeable, has not been through this recently.

Ask about availability too. In a market with limited accredited capacity, a body's earliest Stage 2 slot affects your date more than any internal delay.

6. Whether they will tell you the date does not work

Give a candidate a deliberately tight target and see what happens.

The sequence is fixed: build the management system, operate it long enough to produce records, complete the internal audit, hold the management review, then Stage 1, then Stage 2. Add certification body scheduling and three months is the practical floor for an organisation with an existing management system, three to six months more typically.

A good consultant does that arithmetic out loud on the first call. The alternative is agreeing to a date and revisiting it in month four, which is expensive and common.

7. Independence

Ask whether the firm takes commission from any certification body, whether it receives referral fees from platform vendors, and whether any related entity performs certification. None of these is improper on its own. You should know before you choose. Our position is on the about page.

What a good proposal contains

Scope stated as systems and organisational units, with exclusions named. Deliverables listed individually: gap analysis, policy set, risk and impact assessment method, Statement of Applicability, documentation, internal audit, certification support. Fees itemised per phase, with certification body costs on a separate line and marked as separate. Dated milestones including the earliest defensible Stage 2. A responsibility table with one name per workstream. The named practitioner and committed hours. And a clear statement on whether support continues through surveillance.

Two proposals cannot be compared until both cover the same scope.

What to do next

Draft a provisional scope, give it to two or three firms, and compare their written answers to the seven marks rather than their fees.

Our free readiness diagnostic gives a first view, our readiness and gap assessment gives the full position for a fixed fee, and the ISO/IEC 42001 service page sets out how we work.

References

FAQ

What makes a good ISO 42001 consultant?

Scoping from your buyers and regulator, written work that reasons, substantive impact assessments, honest handling of internal audit independence, current knowledge of accreditation, realistic timelines, and no commission arrangements.

What is the fastest way to test a consultant?

Ask who would perform your internal audit if they built the management system. A firm that raises the independence issue unprompted is thinking properly.

What documents should I ask to see?

A redacted Statement of Applicability and a redacted AI system impact assessment.

Should certification fees be in the proposal?

As a separate, clearly marked line. They are always paid to a different organisation.

How quickly can certification realistically happen?

Three months at the very fastest with an existing management system, three to six months more typically, and certification body availability can extend it.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice. Every engagement has a named practitioner, a written scope, a responsibility table and a fixed fee, with certification body costs shown separately. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.