What is ISO/IEC 42001 certification?
- What it managesHow AI systems are governed across their lifecycle, including impact on the people they affect.
- Who certifies to itAI product companies, SaaS platforms shipping AI features, GCCs building models, and vendors answering AI governance questionnaires.
- Why it matters in IndiaThe credible answer to enterprise AI governance reviews, and it interlocks with DPDP Act obligations on the data side.
ISO/IEC 42001 is the international standard for an artificial intelligence management system, and the first one an organisation can actually be certified against. Its distinctive requirement is the AI system impact assessment: you have to reason about effects on individuals and society, not only about risk to your own business. It layers cleanly on an existing ISO/IEC 27001 system.
Edition status. The first edition, published in December 2023. It is the first certifiable management system standard for artificial intelligence.
Climate action amendment. Published after the 2024 climate amendment cycle, so climate change is already in its clause 4.1 text.
ISO 42001 certifies your management system, not your model
Nobody certifies that a model is fair, accurate or safe, and any certificate claiming to is not what it appears. ISO/IEC 42001 certifies that you have a system for governing AI: an inventory, a risk process, impact assessments, data governance, lifecycle controls, human oversight and monitoring. That distinction matters when a customer asks what your certificate actually proves, and answering it correctly builds more trust than overclaiming.
Who needs ISO/IEC 42001?
Certification is almost always triggered by a specific buyer requirement rather than an internal decision. These are the segments where it comes up.
| Segment | What usually triggers it |
|---|---|
| AI and ML product companies | Enterprise AI governance reviews and investor diligence |
| SaaS platforms shipping AI features | Customer questions about model behaviour, data use and oversight |
| Fintech and lending using models in decisions | Fairness, explainability and oversight expectations |
| Healthtech applying AI to clinical or triage data | High-consequence decisions affecting individuals |
| GCCs and R&D centres building models | Parent-company governance requirements cascading down |
| Vendors integrating third-party foundation models | Accountability for AI components you did not train |
The auditable clauses of ISO/IEC 42001:2023
What each clause actually demands, and what an auditor will ask to see against it.
| Clause | Title | What it requires |
|---|---|---|
| 4 | Context of the organisation | Internal and external issues, interested parties and their requirements, and the certification scope in writing. Since the 2024 climate amendment you must also determine whether climate change is a relevant issue. |
| 5 | Leadership | Top management accountability, a signed policy, and roles and responsibilities assigned and communicated. Auditors interview leadership directly, and delegation to a quality manager is a finding. |
| 6 | Planning | Risks and opportunities, measurable objectives, and documented plans setting out what will be done, by whom, with what resources and how results are evaluated. |
| 7 | Support | Resources, competence, awareness, communication, and control of documented information including version control, access and retention. |
| 8 | Operation | Operational planning and control of the AI system lifecycle, plus the AI risk assessment and risk treatment performed at planned intervals, and the AI system impact assessment covering effects on individuals and groups of individuals and on society. |
| 9 | Performance evaluation | Monitoring and measurement, internal audit covering every clause by independent auditors, and a management review with all required inputs. |
| 10 | Improvement | Nonconformity handling with root cause analysis, corrective action, verification of effectiveness, and continual improvement of the system. |
What ISO/IEC 42001 actually gets you
Answers AI governance reviews
Enterprise buyers have added AI questions to vendor due diligence faster than most vendors have added answers. A certificate is a complete answer.
Impact assessment is the differentiator
Reasoning about effects on people, not only on your business, is what regulators and enterprise ethics reviews look for.
Data provenance stops being folklore
Training data lineage and quality become documented, which is the question that ends most AI procurement conversations.
Human oversight becomes evidence
Defined oversight points and monitoring records replace assurances that a human is somewhere in the loop.
Layers on ISO 27001
Shared clauses 4 to 10 mean an existing ISMS carries most of the management system weight already.
Prepares for AI regulation
The governance artefacts map closely onto the documentation emerging regulatory regimes are asking for.
Documented information ISO/IEC 42001 requires
The records an auditor will ask for, and the clause behind each one.
| Document or record | Why the auditor wants it |
|---|---|
| AI policy and scope of the AIMS | Clauses 4.3 and 5.2, defining which AI systems, teams and use cases the system covers. |
| Inventory of AI systems | The foundation. Most organisations discover models in production that governance had never seen. |
| AI risk assessment methodology and results | Clause 6.1, with criteria that work for model risk, not only information security risk. |
| AI risk treatment plan and Statement of Applicability | Clause 6.1.3, referencing the Annex A controls with justification for inclusion or exclusion. |
| AI system impact assessments | Clause 6.1.4 and Annex A, assessing consequences for individuals, groups and society for each relevant system. |
| AI objectives and plans | Clause 6.2, measurable and owned. |
| Roles, responsibilities and competence records | Clauses 5.3 and 7.2, including who may approve deployment of a model. |
| Data governance records | Annex A. Provenance, quality, preparation and handling of training, validation and production data. |
| AI system lifecycle documentation | Annex A. Objectives, design, verification and validation, deployment, operation and monitoring, and retirement. |
| Third-party and supplier AI records | Annex A, covering foundation models, APIs and vendor-supplied AI components. |
| Incident, monitoring and human oversight records | Evidence that model behaviour is monitored in production and that oversight is real. |
| Internal audit reports and management review minutes | Clauses 9.2 and 9.3, mandatory before stage 2. |
How to get ISO/IEC 42001 certified
Nine stages. The last two are set by ISO/IEC 17021-1 and are the same for every standard, which is why a second certification costs far less than the first.
Gap analysis against the standard
We audit what you already do against every auditable clause of ISO/IEC 42001 and hand back a gap register, not a sales document. Most organisations are already meeting 40 to 60 percent of the requirements without having written them down.
Scope, context and risk
Fix the certification scope in writing, the sites, processes and exclusions it covers, then build the clause 4 context, interested parties and the risk register that the auditor will trace everything else back to.
Documented information
Policy, objectives, process maps, procedures and the records each clause requires. We supply working templates and adapt them to how you actually operate, because an auditor tests the system you run, not the one you filed.
Implementation and training
Roll the system out across the departments in scope and run awareness training, plus competence training for the people who will hold specific responsibilities. Keep attendance and competence records; they are audited.
Internal audit
A full internal audit covering every clause and every process in scope, by someone independent of the work being audited. Findings are logged as nonconformities and closed with corrective action, and this evidence is mandatory before a certification body will proceed.
Management review
Top management formally reviews performance against the standard's required inputs: audit results, objectives, nonconformities, feedback and improvement opportunities. Minutes are a stage 1 audit deliverable.
Stage 1 audit (readiness)
The certification body reviews your documentation, confirms the scope, checks your internal audit and management review are real, and identifies what it will focus on in stage 2. Findings here are usually fixable in days.
Stage 2 audit (implementation)
An on-site or remote audit of the system in operation: interviews, records and evidence sampled against each clause. Major nonconformities must be closed before a recommendation for certification; minors are closed within an agreed window.
Certificate issued, then maintained
The certification body issues a certificate with a three-year cycle. Surveillance audits follow in years one and two, and a recertification audit before the third anniversary. Miss a surveillance audit and the certificate can be suspended or withdrawn.
Check accreditation before you buy a certificate
ISO writes standards. It does not audit anyone, does not issue certificates and does not permit its logo to be used on one, so any certificate that presents itself as issued by ISO is wrong on its face. A certificate is worth what its accreditation is worth. In India the accreditation body is the National Accreditation Board for Certification Bodies (NABCB), which operates under the Quality Council of India, accredits certification bodies against ISO/IEC 17021-1, and is a signatory to the IAF Multilateral Recognition Arrangement, which is what makes an Indian certificate acceptable abroad. Before signing, ask for the certification body's accreditation number, confirm the standard and scope are inside its accredited scope, and verify the certificate on the accreditation body's directory or on IAF CertSearch. A certificate issued in 24 hours with no audit is not a certificate a tender committee, an OEM or an enterprise security review will accept.
Start with a ISO/IEC 42001 gap analysis
A free consultation with an IncorpX certification specialist: what you already meet, what is missing, an honest timeline, and what the audit will cost.
What ISO/IEC 42001 costs
Two separate costs, paid to two different parties. Anyone quoting a single all-in number for an accredited certificate is quoting one of them and hoping you do not ask about the other.
| Cost | Paid to | What drives it |
|---|---|---|
| IncorpX professional fee | IncorpX | Fixed and quoted upfront. From ₹24,999 for ISO/IEC 42001, depending on scope, sites and how much of the system already exists. |
| Certification audit fee | The certification body | Audit days, calculated from effective headcount, number of sites and sector risk category under the IAF mandatory documents. |
| Surveillance audit fees | The certification body | Years 1 and 2 of the cycle. Typically a fraction of the initial certification audit. |
| Recertification audit fee | The certification body | Before the third anniversary, to issue a new three-year certificate. |
| Auditor travel and expenses | The certification body | At actuals, where the audit is conducted on site. |
The cheapest quote is usually the unaccredited one
If one quotation is dramatically below the others, the difference is almost never efficiency. It is the audit days. An accredited certification body cannot reduce audit duration below what the IAF mandatory documents require for your headcount and risk category, so a quote that undercuts that arithmetic is either not accredited for ISO/IEC 42001, or is not planning to conduct the audit it is quoting for.
Other ISO standards for your sector
Ordered by how often they are held alongside ISO/IEC 42001. Because clauses 4 to 10 are shared, a second standard is largely new operational content rather than a new system.
ISO/IEC 42001 guides and reference reading
Longer reference reading on ISO/IEC 42001 and on ISO certification generally.
Frequently asked questions about ISO/IEC 42001
11 questions answered against ISO/IEC 42001:2023 and the ISO/IEC 17021-1 certification rules as they stand in August 2026.
Get ISO/IEC 42001 certified without the guesswork
Talk to an IncorpX certification specialist for free. Accredited certification bodies, an honest timeline, and a gap analysis before you commit.

