Hael
Book a meeting
ISO/IEC 42001 · United Kingdom

UK ISO 42001 consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • UKAS granted its first ISO 42001 accreditations in January 2026. Certificates issued before that were unaccredited and carry less weight in procurement.
  • The UK has no AI Act. Regulation runs through existing regulators, which makes a certificate more useful here, not less, because there is nothing else to point at.
  • The Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D from 5 February 2026, and the safeguards it requires map onto ISO 42001 controls.
  • UK certification body fees commonly run £4,000 to £20,000 for the initial cycle, with implementation £15,000 to £50,000 separate.
  • Where you already hold ISO 27001, the marginal cost is materially lower and Annex D supports running one integrated system.

UKAS accreditation, and why the date matters

UK organisations pursue ISO 42001 for a different reason than their EU counterparts. In the EU it is often preparation for a statutory regime. In the UK there is no AI Act and no AI bill before Parliament, so a certificate is frequently the only durable answer an organisation has when a customer, an investor or a regulator asks how it governs AI.

A UK ISO 42001 consultant builds the management system and prepares you for audit. The certificate comes from an accredited certification body, which under ISO/IEC 17021 cannot be the same organisation.

UKAS granted its first ISO 42001 accreditations in January 2026. Before that, UK organisations could obtain certificates, but from bodies that did not hold accreditation for this specific standard.

Those certificates are not fraudulent and many followed genuine audits. They simply carry less weight, and buyers with mature vendor review processes now check the accreditation scope rather than the logo.

Ask any certification body three things: do you hold UKAS accreditation for ISO/IEC 42001 specifically, can you show the scope entry, and what is your earliest Stage 2 availability. The third question moves timelines more often than the first two.

How it fits with UK regulation

There is no UK AI statute. Instead:

LayerWhat it means for AI governance
UK GDPR and the Data (Use and Access) Act 2025Articles 22A to 22D replaced Article 22 from 5 February 2026, permitting solely automated decisions in more circumstances but only with documented safeguards: transparency, human review and a right to contest
The ICOAnything touching personal data, including transparency and meaningful human involvement in automated decisions
Sector regulatorsThe FCA, PRA, MHRA, Ofcom and CMA applying their own rules to AI within their remits
Five cross-sector principlesSafety and robustness, transparency and explainability, fairness, accountability and governance, contestability and redress

None of these requires ISO 42001. What they require is that you can demonstrate governance, and an ISO 42001 management system produces exactly the artefacts a regulator asks for: an inventory, assigned accountability, documented risk and impact assessments, and evidence of review.

The Articles 22A to 22D safeguards map particularly closely. Human review, transparency and contestability are things the standard already asks you to design and record.

For firms regulated by the FCA, this is native ground for Buckingham Capital Consulting, the partner firm we work alongside on regulated engagements.

The EU AI Act still reaches UK firms

A UK organisation is in scope of the EU AI Act where it places an AI system on the EU market, or where the output of its system is used in the EU. Company location is not the test.

ISO 42001 does not make you compliant with the Act. It does build most of the governance substance the Act's high-risk duties assume, which turns the Act's documentation work into mapping rather than writing. See our EU AI Act service page.

Cost in sterling

ComponentTypical UK range
Gap analysis£5,000 to £15,000
Implementation£15,000 to £50,000
Certification body, initial cycle, small to mid-sized organisation£4,000 to £20,000
Annual surveillance audit20% to 40% of the initial audit fee
Annual internal audit, outsourced£4,000 to £12,000

Fees run higher than the ISO 27001 equivalent because fewer bodies hold accreditation, so demand exceeds supply. That should ease as accreditation spreads.

What a UK consultant should add

The same six workstreams as anywhere, plus three things specific to operating here.

They should check the accreditation scope of any certification body they recommend, and be able to explain what changed in January 2026.

They should map the management system to the Articles 22A to 22D safeguards where you make automated decisions about people, because for most UK organisations the same systems are caught by both.

They should ask which regulator supervises you and shape the evidence so it answers that regulator's questions as well as the auditor's. An FCA-regulated firm and an unregulated software company need the same certificate and different supporting narratives.

Where ISO 27001 helps

Most UK organisations pursuing ISO 42001 already hold ISO 27001. Annex D of ISO/IEC 42001 addresses integrating the two, and running one management system covering both is materially cheaper than two.

The transferable parts are the management system structure, documented information practices, internal audit discipline, management review and supplier controls. The genuinely new work is the AI system inventory, the AI system impact assessment, data governance for AI, and lifecycle controls over models. See our ISO 27001 service page.

What to do next

Contact two or three UKAS-accredited certification bodies early to understand availability, then scope the management system against what your buyers and your regulator actually ask.

Our free readiness diagnostic gives a first view, and the ISO/IEC 42001 service page sets out how we run the programme.

References

FAQ

Is ISO 42001 recognised in the UK?

Yes. UKAS granted its first accreditations for the standard in January 2026, so UK-accredited certification is now available.

Is ISO 42001 required by UK law?

No. There is no UK AI statute. It is voluntary, and demand comes from buyers, investors and regulator expectations.

Does it help with the ICO and automated decisions?

It supports them. The safeguards required by Articles 22A to 22D of UK GDPR, in force since 5 February 2026, map closely onto ISO 42001 controls.

Does it cover us for the EU AI Act?

No, but it builds most of the governance the Act's high-risk duties assume, which makes the Act's documentation work substantially smaller.

What does it cost in the UK?

Certification body fees commonly £4,000 to £20,000 for the initial cycle, with implementation £15,000 to £50,000 separate.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of UK and EU regulatory practice. We take companies through ISO/IEC 42001 from gap analysis to certificate and maintain the position afterwards. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised UK payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.