ISO 42001 certification
A decision an accredited certification body makes after auditing your AI management system. Readiness work comes first, and it is a different thing.
ISO 42001 certification is issued by an independent, accredited certification body after it audits your AI management system against the standard. We assess readiness and remediate gaps; we do not certify.
To be clear before anything else: this site helps you see where your AI management system stands and where the gaps are, and it stops there. It is not a certification body, it does not audit, and a readiness result never says whether you would pass a certification audit. Certification is a decision only an accredited body can make (ISO/IEC 42001:2023).
What is ISO 42001 certification?
Certification is a finding by an independent, accredited certification body that your AI management system conforms to ISO/IEC 42001 (ISO/IEC 42001:2023). It follows an audit of your management system, not a review of a single model, and it results in a certificate the body issues and maintains.
Readiness is the work you do to get there: putting the management system in place, running it, and closing gaps. The readiness check is a self-assessment that shows where your practice already meets the clauses. It cannot tell you what an external assessor would conclude, and it never issues a certificate.
Who can issue it?
Certification bodies accredited for the standard by a national accreditation body. In the UK that is UKAS, working to ISO/IEC 17021-1, and ISO/IEC 42006:2025 sets the specific requirements for bodies that certify AI management systems (UKAS on the first UK AIMS accreditation). UKAS has begun accrediting UK certification bodies for it.
We name accredited bodies only as a category, and endorse none individually. When you choose one, check that its accreditation covers ISO/IEC 42001 specifically.
What does the process involve?
The audit follows the general management-system model: an initial stage that checks your documentation and readiness, a certification stage that audits the system in operation, and then periodic surveillance across a multi-year cycle (Cloud Security Alliance on the ISO 42001 certification process). ISO/IEC 42001 itself sets no fixed timetable, and no authoritative published duration exists, so treat any single week-count you see with caution.
What the body looks for is a management system that is genuinely running: the roles, the risk work, the operational controls and the review cycle described in the standard, with evidence that they are used rather than only written down.
What readiness work comes first?
Before an audit is worth booking, most organisations put the management system in place and run it for long enough to have evidence. That means settling the scope, naming who owns the AI management system, doing the risk and impact work, and getting the operational controls actually in use.
The readiness check walks through ten themes drawn from Clauses 4 to 10 and returns a ledger of what is in place, partial or a gap. You can also download the blank gap sheet to work through offline. Neither is a substitute for the audit; both help you see whether it is worth starting. If you would rather read than answer questions, the signs an organisation is ready for ISO 42001 covers the same ground in a few minutes.