← All insights

ISO 42001 · Guide

How long does ISO 42001 certification actually take?

The honest answer for most organisations is roughly 90 days from kick-off to a Stage 2 audit — provided three conditions hold.

The 90-day baseline

ISO 42001 is the world's first management system standard for artificial intelligence. Because it follows the Annex SL high-level structure shared by ISO 27001 and ISO 27701, organisations that already operate a mature ISMS or PIMS can reach certification meaningfully faster than those starting fresh.

In our work, the typical engagement runs around thirteen weeks. Companies without an existing management system tend to land between four and six months. Larger groups with complex AI estates may run longer still.

What the 90 days look like

  1. Weeks 1–2

    Scoping & AI inventory

    Define the AIMS boundary, identify in-scope AI systems, map suppliers and decision-makers, and confirm certification objectives with leadership.

  2. Weeks 3–5

    Gap analysis

    Benchmark current practice against the ISO 42001 clauses and Annex A controls. Identify what is already evidenced by an existing 27001/27701 programme and where genuine work remains.

  3. Weeks 5–9

    Framework build

    Draft the AI policy, governance committee terms of reference, AI System Impact Assessments (AIIA), model and supplier inventories, and the operational rhythms that keep them current.

  4. Weeks 9–11

    Internal audit & management review

    Run the first internal audit cycle, close findings, and complete a documented management review so the certification body has evidence the system operates.

  5. Weeks 11–13

    Stage 1 & Stage 2 audit

    Stage 1 is a documentation review with the certification body. Stage 2 is the on-site assessment of operating effectiveness. A certificate typically follows within four weeks of a clean Stage 2.

Three conditions for a 90-day path

  • A nominated owner. One named individual with the authority to make decisions about AI governance, scope and risk acceptance.
  • An existing security baseline. A working ISO 27001 (or equivalent) programme means controls, evidence rhythms and audit habits already exist; 42001 layers onto them rather than starting from scratch.
  • An honest AI inventory. Knowing every model, vendor and decision-support tool in use — including shadow AI — before the gap analysis begins.

Where the time actually goes

The clause work is rarely the bottleneck. The longest stretches are usually AI System Impact Assessments for production systems, supplier due-diligence (especially around foundation-model providers), and getting documented sign-off from a governance committee that may not yet exist.

Building that committee, agreeing decision rights and running it through a single full cycle before audit is what separates a certificate that lasts from one that frays under the first surveillance visit.

Faster, slower, or not yet

Faster than 90 days is possible — we have delivered shorter programmes for tightly-scoped AI estates inside mature ISMSes. Slower is common when scope is contested, when leadership has not yet decided which AI systems are strategic, or when the certification body has limited 42001 capacity in your region.

If the answer to “who owns AI here?” is unclear, that is the first piece of work, not the standard itself.

Next step

Map your own ISO 42001 timeline

A short confidential scoping conversation will tell you, within a week, whether the 90-day path is realistic for your organisation.