Is ISO 42001 Worth It for a Company Our Size?

When ISO 42001 certification earns its cost, what it really involves in fees and internal time and which lighter options answer most buyer questions instead.

Probably not yet. Certification earns its cost in three situations: a client has named ISO 42001 in a contract or tender, your sector supervisor expects demonstrable AI oversight or AI is the product rather than a tool you use. Outside those cases, a documented AI policy plus a maintained system inventory answers most buyer questions.

This page covers who benefits from certification, who should wait, what the effort and cost involve and which lighter options satisfy most client requests. Written for SME and mid-market leaders weighing certification against a proportionate AI governance approach.

Reviewed by Jason Holloway, Co-Founder and Managing Director, QL Security.

Do we actually need ISO 42001?

Only if one of those three conditions holds. Otherwise certification usually arrives too early and costs more in management attention than it returns.

The reason is sequencing. ISO 42001 certifies that you run a management system for AI. If you do not yet know which AI systems exist across the business, who authorised them or what data they touch, an auditor will establish that in week one and you will pay for the privilege. Discovery first, then governance, then certification if the market asks for it. We say this to prospects regularly, including ones who arrived intending to buy a certification programme.

What size of organisation does certification suit?

Headcount matters less than AI surface area and buyer pressure. A 40-person AI product company selling into financial services has a stronger case than a 900-person manufacturer using a handful of AI features inside off-the-shelf software.

The practical test is whether you can name an owner for AI risk who has authority to stop a deployment. In organisations under roughly 100 people that person is usually the CTO or COO, and the management system can stay lightweight because decision paths are short. In the 100 to 500 range the difficulty rises: enough teams exist to adopt AI independently, not enough governance structure exists to see it. That band is where we most often find Shadow AI during assessment, and where certification effort is routinely underestimated.

What does certification cost in practice?

Costs fall into three buckets. The ranges below are indicative planning figures for a UK organisation of 50 to 300 people running a modest number of AI systems, not quotations. Pricing varies by certification body, scope and site count and internal effort varies more still.

  • Certification body fees: commonly in the region of £8,000 to £20,000 across stage 1 and stage 2 for a single site, with annual surveillance a fraction of that. Confirm current fees directly with your chosen body.
  • External advisory support, where used: commonly in the region of £15,000 to £40,000, driven almost entirely by how much of the management system already exists.
  • Internal time, consistently the largest and least predictable: plan on the order of 30 to 60 senior days across six to nine months for scoping, risk assessment, control design, evidence collection and internal audit, with further input from IT, legal, HR and the teams operating AI systems.

Organisations budget accurately for the first bucket, roughly for the second and barely at all for the third. The internal owner then absorbs the shortfall alongside a day job and the timeline slips. Before committing, ask who is doing the work and what they will stop doing to make room. Without a clear answer, the business case is not ready regardless of price. Our ISO 42001 certification cost guidance breaks the same figures down in more detail.

Is ISO 42001 worth it, or is a written AI policy enough?

For a large share of buyer requests, a well-evidenced AI policy plus a live AI inventory answers the question being asked. Procurement teams rarely want a certificate for its own sake; they want assurance that you know which AI systems you run, who approved them, what data they process and what happens when one behaves unexpectedly.

A policy alone will not do that. A policy plus an inventory, a documented approval route, a stated position on staff use of public AI tools and evidence that you review it periodically usually will. That package can be assembled in weeks rather than quarters, and it becomes the foundation of a certifiable management system later if the market moves. Our answer on what a client’s AI policy request is really testing covers what goes in the document.

Certification earns its cost when a buyer names the standard explicitly, when several buyers ask overlapping AI assurance questions and you want to answer once or when independent verification of your own claims carries commercial weight. Short of that, you are paying for a signal nobody has requested.

What triggers should make us reconsider?

Four triggers recur:

  • A named requirement in a live tender you intend to win.
  • A supervisory expectation in your sector that references AI management arrangements.
  • A shift in your product where AI moves from feature to dependency.
  • Repeated AI security questionnaires from prospects that your current documentation cannot answer without bespoke drafting each time.

The fourth is the most common and the easiest to miss, because the cost shows up as sales friction rather than a compliance gap. If your pre-sales team rewrites the same AI assurance answers for every deal, certification starts paying for itself.

How does ISO 42001 relate to the EU AI Act?

They answer to different masters. The EU AI Act is law and applies according to what your AI systems do and where they are used. ISO 42001 is a voluntary management system standard. Certification does not create legal compliance and no certificate exempts you from statutory obligations.

The overlap is useful. Much of what the Act expects is exactly what a management system enforces: knowing your systems, classifying risk, keeping records and assigning accountability. Organisations that certify well find their Act obligations easier to evidence. Organisations that certify defensively find they have documented a system nobody operates.

Where should we start if we are not ready to certify?

Establish what you are running. An AI Security Gap Analysis identifies which AI systems exist, who owns them, what data flows through them and where controls are absent. That output is useful whether you certify, adopt a lighter governance model or simply want to answer buyer questionnaires without guesswork.

From there, build a proportionate AI security programme: an inventory you maintain, an approval route people use, a position on public AI tools and verification that deployed systems behave as intended through AI Behaviour Verification. Certification, if it comes, then documents something real.

Can you tell us whether we need it before we commit to anything?

Yes, and we would rather do that than sell a programme you will regret. A short scoping conversation covers your AI footprint, sector obligations, current buyer pressure and internal capacity, then ends with a direct recommendation, including “wait” where that is the right answer.

This page offers general guidance on certification and governance decisions; it is not legal advice on your regulatory obligations.

Related reading: our ISO 42001 service page and ISO 42001 versus ISO 27001. To discuss your position, contact us.

Find out whether you need it before you commit

A short scoping conversation covering your AI footprint, sector obligations, buyer pressure and internal capacity, ending with a direct recommendation.