ISO 42001 · Insight
ISO 42001 in the UK: A Lead Auditor's Complete Guide to Certification, Cost and Timeline
How to get ISO 42001 certified in the UK: the path, what it costs, how long it takes, how it relates to ISO 27001 and where efforts fail. A Lead Auditor's view.
Most guides to ISO 42001 describe what the standard contains. That misses the question organisations actually ask, which is how to get certified, what it costs and how long it takes. We work on the other side of the audit table, so this guide takes a Lead Auditor’s view of the certification path rather than a clause-by-clause walk through the standard.
ISO 42001 certification in the UK follows a defined route: a gap analysis against the standard, building an AI management system, an internal audit and management review, then a two-stage external audit by an accredited certification body. The central argument of this guide is that the work that decides success or failure happens long before the auditor arrives. Weak AI risk assessment, missing impact assessments and undocumented behaviour controls are common reasons certification efforts stall and all three are avoidable.
What follows covers the path step by step, the cost and timeline you should budget for, how the standard relates to ISO 27001 if you already hold it and where we most often see certification efforts come unstuck.
What’s in this guide
- The UK ISO 42001 certification path step by step
- What ISO 42001 certification costs and what drives the figure
- How long certification takes and the stages of the timeline
- ISO 42001 versus ISO 27001 for organisations with existing controls
- A Lead Auditor’s view of where certification efforts fail
- Common questions on ISO 42001 certification
The UK ISO 42001 certification path step by step
ISO 42001 certification in the UK starts with a gap analysis against the standard, then building an AI management system covering policy, risk assessment and controls. An internal audit and management review follow, before an accredited certification body runs a two-stage external audit covering documentation then implementation. Each stage builds on the last, and skipping or rushing the early work tends to surface as findings in the external audit.
The first stage is a gap analysis, which compares your current AI governance against the requirements of the standard. This tells you what already exists, what needs building and how far apart the two are. For an organisation with mature security controls, the gap may be narrow. For one starting from informal AI use with no policy, it is wide. The honest output of this stage is a prioritised list of work rather than a clean bill of health.
The second stage is building the AI management system itself. This is the substantive work and where most of the time goes. It covers an AI policy, an AI risk assessment process, AI impact assessments for relevant systems, defined roles and the controls that govern how AI is developed, procured, deployed and monitored.
The third stage is the internal audit and management review. Before an external body certifies you, you assess yourself against the standard and present the results to senior management. This is not a formality. An internal audit that finds nothing is usually a sign the audit was too shallow, and an experienced certification body will notice.
The final stage is the two-stage certification audit by an accredited body. Stage 1 is a documentation review, where the auditor checks that the management system exists on paper and meets the structural requirements. Stage 2 is an implementation audit, where the auditor tests whether what you have documented actually happens in practice. Passing Stage 1 on paper but failing Stage 2 on evidence is a common pattern, and it usually traces back to controls that were written but never operated.
What ISO 42001 certification costs and what drives the figure
ISO 42001 certification cost in the UK varies with organisation size, number of AI systems and existing control maturity. Costs split between optional consultancy support to build the management system and the accredited certification body’s audit fees. Smaller UK firms typically budget several thousand pounds; larger or multi-site organisations pay considerably more. No single published price exists because the standard scales the audit effort to the scope being certified.
The first cost driver is scope. A single-site organisation using a handful of AI systems has a smaller certifiable scope than a multi-site group running AI across many functions. Certification bodies calculate audit days partly from the number of people in scope and the complexity of the AI use, so a wider scope means more audit days and a higher fee.
The second driver is the maturity of your existing controls. An organisation that already holds ISO 27001 and runs a working management system has much of the structural machinery in place, which reduces the build effort. An organisation starting from no formal governance carries the full cost of designing policy, risk processes and controls from scratch.
The third driver is whether you bring in consultancy support. This cost is optional. Some organisations build the AI management system with internal resource and only pay the certification body’s audit fee. Others engage a consultant to run the gap analysis, design the management system and prepare them for audit. The trade-off is cash against internal time and the risk of building something an auditor may reject.
Separate the two cost categories. The certification body’s audit fee is unavoidable if you want an accredited certificate. Consultancy support is a choice about how you get ready. Conflating the two leads organisations to either overspend on advice they do not need or underspend on preparation they cannot deliver internally. A readiness assessment is the cheapest way to find out which side of that line you sit on.
How long certification takes and the stages of the timeline
ISO 42001 certification typically takes three to six months for a UK SME with reasonable governance already in place, and longer for complex or multi-site organisations. The timeline covers gap analysis, building the AI management system, gathering evidence over a short operating period, then the two-stage certification audit. The single biggest variable is how mature your existing controls are when you start.
The gap analysis is the quickest stage, often a few weeks. It depends mainly on how quickly your organisation can give the assessor access to current policies, systems and the people who run them. Delays here are usually about availability rather than complexity.
Building the AI management system is the longest stage and the one organisations consistently underestimate. Writing a policy is fast; embedding a working risk assessment process, completing AI impact assessments and standing up controls that people actually follow takes time. For an SME with reasonable foundations this might run six to ten weeks. For an organisation building from nothing it runs considerably longer.
The management system needs to operate for a short period before the certification audit. The auditor needs evidence that controls run in practice, not just that they exist on paper. A risk assessment process with no completed risk assessments, or an internal audit schedule with no internal audit conducted, gives the auditor nothing to test. Building in a few weeks of genuine operation is what makes the difference between a documentation exercise and a certifiable management system.
The two-stage audit itself is relatively quick once you are ready. Stage 1 and Stage 2 are scheduled by the certification body, and the time between them gives you a window to close any documentation gaps the Stage 1 review surfaces before the implementation audit. The total elapsed time from starting the gap analysis to holding a certificate is what the three-to-six-month figure describes for a prepared SME.
ISO 42001 versus ISO 27001 for organisations with existing controls
ISO 42001 and ISO 27001 are different standards covering different risks, but they share the same management system structure, which is good news if you already hold ISO 27001. ISO 27001 governs information security; ISO 42001 governs the responsible management of AI, including risks that information security controls do not address such as bias, transparency and the behaviour of AI systems in use. Holding one does not mean you meet the other.
The overlap is structural rather than substantive. Both standards follow the Annex SL high-level structure used across modern ISO management system standards, so the requirements for leadership, context, planning, support, operation, performance evaluation and improvement look familiar if you have been through ISO 27001. The risk assessment machinery, internal audit process and management review can often share the same foundations.
Where the two diverge is the subject matter. ISO 27001 asks whether your information is confidential, available and has integrity. ISO 42001 asks whether your AI is governed responsibly: whether you have assessed its impact on people, whether you understand and control its behaviour and whether accountability for AI decisions is clear. An organisation can have excellent information security and still have no answer to those questions.
For organisations that already hold ISO 27001, the practical implication is that you can integrate ISO 42001 into your existing management system rather than running two parallel structures. This reduces both the build effort and the ongoing maintenance burden. The work that remains is the AI-specific content: the AI policy, the AI risk and impact assessments and the controls particular to how AI behaves. That is the substance the comparison between the two standards tends to gloss over, and it is where the real effort sits.
A Lead Auditor’s view of where certification efforts fail
Many certification efforts that fail or stall do so for the same three reasons: a weak AI risk assessment, missing impact assessments and undocumented behaviour controls. None of these is about the standard being unclear. They are about organisations treating the AI management system as a documentation exercise rather than a working process, and an experienced auditor spots that quickly.
The first failure is a weak AI risk assessment. Organisations often produce a risk register that lists generic AI risks copied from a template, with no evidence that anyone has actually assessed the specific AI systems in use. An auditor will ask which systems you assessed, how you scored the risks and what you decided to do about them. A risk register full of generic entries with no system-level assessment behind it is a frequent Stage 2 finding.
The second failure is missing impact assessments. ISO 42001 expects you to assess the impact of AI systems on individuals and groups, particularly where those systems affect people’s rights, access to services or treatment. Organisations frequently complete the policy and the risk register but skip the impact assessments because they are harder and more specific. The auditor notices the gap, because the policy will reference impact assessments that do not exist.
The third failure is undocumented behaviour controls. AI systems behave in ways that need monitoring and control, and the standard expects you to show how you govern that behaviour. Organisations often have informal controls in practice, someone checks outputs, someone reviews changes, but none of it is documented or auditable. When the auditor asks for evidence, there is a conversation but no record. Informal controls fail at Stage 2 because the auditor can only certify what can be evidenced.
The common thread across all three is the gap between paper and practice. The standard does not reward elaborate documentation; it rewards working governance that produces evidence. The cheapest way to find these gaps is to look for them before the certification body does, which is exactly what a readiness assessment with someone who audits against the standard provides.
Common questions on ISO 42001 certification
Who can issue an accredited ISO 42001 certificate in the UK?
An accredited ISO 42001 certificate in the UK is issued by a certification body that has itself been accredited to certify against the standard, typically by a national accreditation body. Consultants and advisors can prepare you for certification and run readiness assessments, but they cannot issue the certificate. Only the accredited certification body that conducts the two-stage audit can do that.
How long is an ISO 42001 certificate valid before recertification?
In line with other ISO management system standards, an ISO 42001 certificate generally runs on a three-year cycle. The certification body conducts surveillance audits during that period to confirm the AI management system continues to operate, and a recertification audit at the end of the cycle before issuing a fresh certificate. The certificate is not a one-off; it depends on the management system being maintained.
Does ISO 42001 require an AI impact assessment for every system?
ISO 42001 expects AI impact assessments where AI systems affect individuals or groups, particularly their rights, access or treatment, rather than mechanically for every system regardless of risk. The depth of assessment scales with the potential impact. Low-impact internal tools need less than systems that make or influence decisions about people. The judgement about what warrants assessment is part of what the auditor tests.
Map your ISO 42001 certification path
Book an ISO 42001 readiness assessment with our Lead Auditor team to map your certification path, cost and timeline, and find the gaps before the certification body does.