Artificial intelligence

ISO 42001: Why AI Certification Is the Future

What ISO 42001 is, who needs it, and how to prepare

Mgr. Jaroslav Surman 10 February 2026 8 min read

ISO/IEC 42001:2023 is the first international standard defining requirements for an Artificial Intelligence Management System (AIMS). Against the backdrop of rapidly growing AI regulation, above all the EU AI Act, this certification is becoming a key competitive advantage and the de facto standard for responsible handling of artificial intelligence. In this article we explain what ISO 42001 brings, who needs it and how to prepare for certification.

What Is an AIMS and Why Does It Exist?

An AIMS (Artificial Intelligence Management System) is a management system that helps an organisation develop, provide or use AI systems responsibly. Much like ISO 27001 for information security or ISO 9001 for quality, ISO 42001 defines a framework of policies, processes and controls for managing AI-related risks.

The standard was published in December 2023 in response to the growing need for a standardised approach to AI governance. It builds on the principles of responsible AI: transparency, explainability, robustness, safety and fairness. It is not an academic document; it is a practical tool for governing AI within an organisation.

Why Now: The AI Act Connection

The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and requires companies to operate a robust AI management system, particularly for high-risk systems. Its obligations are being phased in: prohibitions since 2 February 2025, rules for general-purpose AI models since 2 August 2025, transparency obligations (Article 50) since 2 August 2026 and, following the Digital Omnibus amendment (Regulation (EU) 2026/1744, in force since 27 July 2026), high-risk obligations from 2 December 2027 (Annex III) and from 2 August 2028 (AI embedded in regulated products, Annex I). Postponement does not mean cancellation: companies have gained time, not an exemption.

ISO 42001 provides a recognised framework that meets these requirements. Specifically, the AI Act requires a risk management system (Article 9), and ISO 42001 defines an AI risk assessment process. The AI Act requires a quality management system (Article 17), and ISO 42001 contains quality management requirements. The AI Act requires documentation and traceability, and ISO 42001 sets requirements for records and documentation.

ISO 42001 certification is not required by law, but it is the strongest evidence that your organisation governs AI responsibly. In the event of an inspection by a supervisory authority or an audit by a client, the ISO 42001 certificate is the de facto gold standard.

Who Needs ISO 42001?

ISO 42001 is relevant to three groups of organisations. First, companies developing AI systems (software companies, start-ups, research institutions). The standard helps them manage the entire AI life cycle from design to decommissioning. Second, companies deploying AI (banks, insurers, manufacturers, healthcare providers). If you use AI for decision-making, assessment or automation, ISO 42001 helps you ensure you do so safely and in line with regulation. Third, companies providing AI services (consultancies, cloud providers, IT integrators). Certification increases client trust and is a competitive advantage in tenders.

Company size plays no decisive role. ISO 42001 is scalable: for a small company with one AI system the implementation will be simpler than for a corporation with dozens of AI solutions, but the principle is the same.

Implementation Steps

1. Gap Analysis

The first step is to compare your organisation's current state with the standard's requirements. The gap analysis identifies what you already have (existing policies, processes, documentation) and what is missing. It typically takes 1 to 2 weeks and forms the basis for planning the whole implementation.

2. AIMS Design

Based on the gap analysis, the AIMS architecture is designed to fit your organisation. This defines the scope of the system, the organisation's AI policy, the organisational structure and roles (AI governance board, AI risk manager), the inventory of AI systems and their classification, and the risk management process.

3. Implementation

The most extensive phase covers creating documentation (policies, procedures, records), implementing the controls from Annex A of the standard, training staff, integrating the AIMS into existing business processes and carrying out a risk assessment for every AI system in scope. This phase typically takes 2 to 4 months.

4. Internal Audit and Management Review

Before the certification audit, an internal audit of the AIMS is required, i.e. an independent assessment of whether the system works as planned. Any non-conformities are corrected. This is followed by the management review, which confirms readiness for certification.

5. Certification Audit

The certification audit is carried out by an accredited certification body (accredited under ISO/IEC 42006:2025; for example BSI, Bureau Veritas, TÜV SÜD or DNV), not by the consultant who helped with implementation. The audit takes place in two stages: Stage 1 (documentation review) and Stage 2 (on-site verification of implementation). After a successful audit you receive a certificate valid for 3 years, with annual surveillance audits.

Costs

The cost of ISO 42001 certification depends on the size of the organisation, the number of AI systems and the current level of readiness. As a guide, costs consist of consulting and implementation (100,000 to 500,000 CZK for small and medium-sized companies, more for larger organisations), the certification audit (50,000 to 150,000 CZK, depending on scope and certification body) and ongoing costs for maintaining the system and surveillance audits (roughly 30 to 50 % of the certification audit cost per year). A significant and often overlooked item is your own staff's time. For a small company with one or two AI systems, expect total costs from 200,000 CZK; for a medium-sized company with a broader AI portfolio, from 500,000 CZK.

Timeline

A typical timeline from zero to certification looks like this. Gap analysis takes 1 to 2 weeks. AIMS design 2 to 4 weeks. Implementation 2 to 4 months. Internal audit and corrective actions 2 to 3 weeks. Certification audit 1 to 2 weeks. In total, roughly 4 to 6 months; longer for larger organisations without an existing management system. If you already operate ISO 27001 or another management system, implementation will be faster thanks to synergies with existing processes.

Competitive Advantage

ISO 42001 certification brings a number of concrete benefits. Trust of clients and partners: the certificate is internationally recognised evidence of a responsible approach to AI. Regulatory readiness: you meet the AI Act's requirements before they become enforceable. Advantage in tenders: more and more companies and public institutions require suppliers to demonstrate AI governance. Internal benefits: systematised AI processes, better risk management, clear responsibilities. Reputation: in an environment full of concern about AI, certification is a strong signal of responsibility.

Comparison with ISO 27001

If you know ISO 27001 (information security), ISO 42001 will feel structurally familiar. Both standards share the harmonised structure (Annex SL), take a risk-based approach and require an internal audit and management review. The main difference lies in focus: ISO 27001 protects the confidentiality, integrity and availability of information, whereas ISO 42001 addresses the responsible development and deployment of AI, including ethical aspects, fairness, transparency and human oversight. Organisations with existing ISO 27001 certification will find that a substantial part of the management-system requirements (context, leadership, planning, support, performance evaluation, improvement) is already in place and can be reused; the specific elements of ISO 42001, such as AI system impact assessment or data governance for AI, are new additions.

How We Can Help

Mgr. Jaroslav Surman is a certified ISO/IEC 42001 Lead Implementer (PECB, 2025) with hands-on experience building AI governance in organisations of various sizes in the Czech Republic and Austria. We offer the full range of services from gap analysis through AIMS design and implementation to preparation for the certification audit. In cooperation with the law office of Mgr. Barbora Surmanová we also cover the legal aspects: AI Act compliance, GDPR for AI systems and contractual documentation.

Interested in ISO 42001 certification? Contact us for a non-binding initial consultation. Find out more on our ISO/IEC 42001 page.

Updated August 2026.

Mgr. Jaroslav Surman

court-certified translator, AI consultant

← Back to the blog

Have a question about a topic from the blog?

Get in touch directly. Whether legal, translation or AI, the initial consultation is always without obligation.