How to Get ISO 42001 Certification: The Step-by-Step Route for UK Organisations

Jason Holloway
iso-42001-certification iso-42001-process stage-1-stage-2-audit ukas aims

You get ISO 42001 certification by building an AI management system that meets the standard, then passing an independent external audit. The route runs through scoping, gap analysis, AIMS implementation, internal audit and management review, followed by a two-stage certification audit carried out by an accredited certification body. It is a defined, repeatable process and the outcome depends on the standard’s requirements and a competent auditor’s judgement rather than any single tool.

Much of the guidance ranking for ISO 42001 certification is written by software vendors who frame certification as an evidence-collection exercise their platform can automate. Some of that guidance is accurate, but the framing tends to skip the part that actually determines whether you pass. This post walks the route as an auditor sees it.

What ISO 42001 certification actually means and who issues it

ISO 42001 certification is formal confirmation that your AI management system meets the requirements of the standard, issued by an independent certification body after an external audit. You cannot certify yourself, and the consultancy that helps you prepare cannot issue the certificate either.

The two roles must stay separate. A consultancy helps you build and test the management system; a certification body audits it and grants certification. In the UK, look for a certification body recognised by UKAS, the national accreditation service. Accreditation is what gives the certificate credibility with your customers and regulators.

Step 1: scope your AI management system and the AI uses in play

Start by defining what your AI management system covers and every way your organisation uses AI. Scope is the first thing an auditor examines, and a vague or convenient scope is the fastest route to problems later.

List the AI systems you build, buy or embed, including the models sitting inside third-party tools your staff already use. Decide which parts of the organisation fall inside the boundary. A scope drawn to exclude an inconvenient business unit will be challenged, and an honest scope you can defend is worth more than a broad one you cannot evidence.

Step 2: gap analysis against the standard

A gap analysis compares your current practice against every ISO 42001 requirement and produces a prioritised list of what is missing. This is where you find out how far the work really is before you commit to a timeline, and where the cost and timeline drivers become concrete for your own estate.

Go through the management-system clauses and the Annex A controls one by one, marking each as in place, partial or absent. The output is a remediation plan ordered by risk and effort. Organisations already holding ISO 27001 tend to find fewer gaps because the leadership, risk and internal-audit machinery is already running; those starting from nothing find the list longer and the build phase heavier.

Step 3: build the AIMS, controls and evidence

This is the longest phase: writing policies, standing up controls and generating the records that prove the system operates. The build is driven by the gaps you found, not by a template.

You will define your AI policy, risk-assessment method, roles and responsibilities and the controls covering data, model behaviour, human oversight and supplier management. Evidence matters as much as documentation. An auditor wants to see the system running: risk assessments completed, decisions logged, incidents handled. A platform can help collect and organise that evidence, but it cannot decide which controls your context requires or whether they are working.

Step 4: internal audit and management review

Before any external audit, the standard requires you to audit yourself and hold a management review. This is a hard requirement, not an optional dry run.

An internal audit checks the AIMS against the standard and surfaces problems while you can still fix them. The management review puts the results in front of leadership so they can confirm the system is working and resourced. Skipping or rushing these is a common reason organisations stumble at Stage 2, because the external auditor will ask to see both.

Step 5: the Stage 1 and Stage 2 external certification audit

Certification is a two-stage external audit. Stage 1 is a documentation review that checks whether your AIMS is designed correctly and ready to be tested. Stage 2 is the implementation audit that checks whether the system actually operates as described.

At Stage 1 the auditor reviews your scope, policies and internal-audit records and flags anything that would block Stage 2. The two stages typically run a few weeks apart, giving you time to close Stage 1 findings. At Stage 2 the auditor gathers evidence across the whole system, interviews staff and tests controls. If the system holds up, the certification body confirms the result and issues the certificate.

Why a Lead Auditor process beats a software-vendor shortcut

A Lead Auditor prepares you for the judgement an auditor will apply; a software platform prepares you for a checklist. The difference shows up at Stage 2, where controls are tested against context rather than ticked off.

John, who leads our ISO 42001 work, is a BSI-certified ISO 42001 Lead Auditor. That means we prepare your management system the way it will be assessed: scope you can defend, controls matched to your actual AI risk and evidence an auditor will accept. A tool that automates evidence collection is useful once you know what evidence matters. Deciding what matters is the part that determines whether you pass, and that is auditor work, not software work. To put an indicative number against your own scope before you start, use our free ISO 42001 Cost and Timeline Estimator.

Common questions on the ISO 42001 certification route

Can you fail an ISO 42001 Stage 2 audit and what happens next?

Yes. If the auditor finds major non-conformities, the certification body will not issue the certificate until you correct them. You are usually given a defined period to submit a corrective-action plan and evidence of fixes, which the auditor then reviews. Minor non-conformities may allow certification to proceed with a commitment to close them by the next visit.

How often is ISO 42001 certification reviewed after you pass?

Certification is not one-and-done. Certification bodies carry out surveillance audits during the certificate’s life to confirm the AI management system is still operating and improving, followed by a fuller recertification audit at the end of the cycle. Confirm the exact surveillance and recertification intervals with your chosen UKAS-recognised certification body, as cycles can vary between bodies.

Do you need ISO 27001 before you can get ISO 42001 certified?

No, ISO 27001 is not a prerequisite. You can certify to ISO 42001 on its own. That said, organisations already holding ISO 27001 reach certification faster because the shared management-system machinery, leadership commitment, risk process and internal audit is already in place and can be extended to cover AI.

If you want to know which of these steps you have covered and which still need work, book a scoping call with QL Security and we will assess your starting point and outline the steps required for ISO 42001 certification: get in touch.

This article is for information only and does not constitute regulatory or legal advice.

Map your route to certification

If you want to know which of these steps you have covered and which still need work, we will assess your starting point and outline the steps required for ISO 42001 certification.