UK ISO 42001 consultants
- UKAS granted its first ISO 42001 accreditations in January 2026. Certificates issued before that were unaccredited and carry less weight in procurement.
- The UK has no AI Act. Regulation runs through existing regulators, which makes a certificate more useful here, not less, because there is nothing else to point at.
- The Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D from 5 February 2026, and the safeguards it requires map onto ISO 42001 controls.
- UK certification body fees commonly run £4,000 to £20,000 for the initial cycle, with implementation £15,000 to £50,000 separate.
- Where you already hold ISO 27001, the marginal cost is materially lower and Annex D supports running one integrated system.
UKAS accreditation, and why the date matters
UK organisations pursue ISO 42001 for a different reason than their EU counterparts. In the EU it is often preparation for a statutory regime. In the UK there is no AI Act and no AI bill before Parliament, so a certificate is frequently the only durable answer an organisation has when a customer, an investor or a regulator asks how it governs AI.
A UK ISO 42001 consultant builds the management system and prepares you for audit. The certificate comes from an accredited certification body, which under ISO/IEC 17021 cannot be the same organisation.
UKAS granted its first ISO 42001 accreditations in January 2026. Before that, UK organisations could obtain certificates, but from bodies that did not hold accreditation for this specific standard.
Those certificates are not fraudulent and many followed genuine audits. They simply carry less weight, and buyers with mature vendor review processes now check the accreditation scope rather than the logo.
Ask any certification body three things: do you hold UKAS accreditation for ISO/IEC 42001 specifically, can you show the scope entry, and what is your earliest Stage 2 availability. The third question moves timelines more often than the first two.
How it fits with UK regulation
There is no UK AI statute. Instead:
| Layer | What it means for AI governance |
|---|---|
| UK GDPR and the Data (Use and Access) Act 2025 | Articles 22A to 22D replaced Article 22 from 5 February 2026, permitting solely automated decisions in more circumstances but only with documented safeguards: transparency, human review and a right to contest |
| The ICO | Anything touching personal data, including transparency and meaningful human involvement in automated decisions |
| Sector regulators | The FCA, PRA, MHRA, Ofcom and CMA applying their own rules to AI within their remits |
| Five cross-sector principles | Safety and robustness, transparency and explainability, fairness, accountability and governance, contestability and redress |
None of these requires ISO 42001. What they require is that you can demonstrate governance, and an ISO 42001 management system produces exactly the artefacts a regulator asks for: an inventory, assigned accountability, documented risk and impact assessments, and evidence of review.
The Articles 22A to 22D safeguards map particularly closely. Human review, transparency and contestability are things the standard already asks you to design and record.
For firms regulated by the FCA, this is native ground for Buckingham Capital Consulting, the partner firm we work alongside on regulated engagements.
The EU AI Act still reaches UK firms
A UK organisation is in scope of the EU AI Act where it places an AI system on the EU market, or where the output of its system is used in the EU. Company location is not the test.
ISO 42001 does not make you compliant with the Act. It does build most of the governance substance the Act's high-risk duties assume, which turns the Act's documentation work into mapping rather than writing. See our EU AI Act service page.
Cost in sterling
| Component | Typical UK range |
|---|---|
| Gap analysis | £5,000 to £15,000 |
| Implementation | £15,000 to £50,000 |
| Certification body, initial cycle, small to mid-sized organisation | £4,000 to £20,000 |
| Annual surveillance audit | 20% to 40% of the initial audit fee |
| Annual internal audit, outsourced | £4,000 to £12,000 |
Fees run higher than the ISO 27001 equivalent because fewer bodies hold accreditation, so demand exceeds supply. That should ease as accreditation spreads.
What a UK consultant should add
The same six workstreams as anywhere, plus three things specific to operating here.
They should check the accreditation scope of any certification body they recommend, and be able to explain what changed in January 2026.
They should map the management system to the Articles 22A to 22D safeguards where you make automated decisions about people, because for most UK organisations the same systems are caught by both.
They should ask which regulator supervises you and shape the evidence so it answers that regulator's questions as well as the auditor's. An FCA-regulated firm and an unregulated software company need the same certificate and different supporting narratives.
Where ISO 27001 helps
Most UK organisations pursuing ISO 42001 already hold ISO 27001. Annex D of ISO/IEC 42001 addresses integrating the two, and running one management system covering both is materially cheaper than two.
The transferable parts are the management system structure, documented information practices, internal audit discipline, management review and supplier controls. The genuinely new work is the AI system inventory, the AI system impact assessment, data governance for AI, and lifecycle controls over models. See our ISO 27001 service page.
What to do next
Contact two or three UKAS-accredited certification bodies early to understand availability, then scope the management system against what your buyers and your regulator actually ask.
Our free readiness diagnostic gives a first view, and the ISO/IEC 42001 service page sets out how we run the programme.
References
FAQ
Is ISO 42001 recognised in the UK?
Yes. UKAS granted its first accreditations for the standard in January 2026, so UK-accredited certification is now available.
Is ISO 42001 required by UK law?
No. There is no UK AI statute. It is voluntary, and demand comes from buyers, investors and regulator expectations.
Does it help with the ICO and automated decisions?
It supports them. The safeguards required by Articles 22A to 22D of UK GDPR, in force since 5 February 2026, map closely onto ISO 42001 controls.
Does it cover us for the EU AI Act?
No, but it builds most of the governance the Act's high-risk duties assume, which makes the Act's documentation work substantially smaller.
What does it cost in the UK?
Certification body fees commonly £4,000 to £20,000 for the initial cycle, with implementation £15,000 to £50,000 separate.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of UK and EU regulatory practice. We take companies through ISO/IEC 42001 from gap analysis to certificate and maintain the position afterwards. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised UK payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.