ISO/IEC 42001 is a voluntary AI management standard. No law requires it, certification runs into tens of thousands of dollars over a three-year cycle, and a substantial share of its requirements can be met for free - without the certificate. The question rarely starts in a board meeting. It usually arrives in a vendor security questionnaire from a corporate buyer, in a row that was not there last year. Next to the ticked ISO 27001 box sits an empty one marked ISO 42001. Nobody writes "you must have this". The box is simply there.
That is the clue that matters. Whether you need ISO 42001 depends far more on who is asking than on what your company does with AI. No statute in the United States, the United Kingdom or the European Union requires the standard, nor does Regulation (EU) 2024/1689, the EU AI Act. ISO/IEC 42001 is voluntary, like most ISO management standards.
The more useful distinction is this: a company can be fully aligned with ISO 42001 and hold no certificate at all. Alignment you build yourself. A certificate you buy from an accredited body after a paid audit. Two different things, two different invoices. What follows breaks down both, with cost ranges, a decision table and three steps that cost nothing.
What is ISO 42001 and what does it require?
ISO/IEC 42001:2023 sets out the requirements for an AI management system: how an organization establishes it, runs it, keeps it alive and improves it. It speaks to companies that build and supply AI systems and to those that put AI into their own processes. The requirements sit in two layers. The first is clauses 4 to 10 - context, leadership, planning, support, operation, evaluation, improvement - the backbone every ISO management standard shares. The second is Annex A, with 38 controls grouped into 9 areas, from AI policy and impact assessment through system lifecycle to data management. That second layer is where the AI-specific work actually lives.
The standard itself costs 225 CHF from the official distributors, including the IEC Webstore. It is the only number in this whole topic that comes without an "it depends".
How the three frameworks relate fits in one sentence: the AI Act is law you have to follow if you sell into the EU, ISO 42001 is a voluntary standard you can certify against, and the NIST AI Risk Management Framework is free, with no certification attached. The full comparison, and which one to start with, sits in the piece on AI governance frameworks. This article is about the bill and the decision.
Is ISO 42001 certification mandatory?
A certificate is not a legal permit; it is a ticket into a procurement process. You buy it when the party across the table will not open the envelope without it: a corporate vendor management team, a public tender committee, an investor running due diligence. No regulation compels it. More importantly, an ISO 42001 certificate does not give you a presumption of conformity with the EU AI Act.
That distinction is worth knowing before a salesperson calls to explain that ISO 42001 "covers your AI Act obligations". Presumption of conformity attaches only to harmonized standards cited in the Official Journal of the European Union, under Article 40 of Regulation (EU) 2024/1689. As of today, no AI management system standard holds that status.
The European Commission concluded that the aims and definitions of ISO/IEC 42001 do not fully line up with the quality management requirement in the AI Act, so the CEN-CENELEC committee JTC 21 drafted a separate European standard, prEN 18286, instead of adopting ISO 42001 wholesale. According to a Cloud Security Alliance research note, it reached public consultation on 30 October 2025, the first AI Act harmonized standard to get that far, and its Annex D maps the requirements onto the Annex A controls of ISO 42001. A certified company is not starting from an empty folder. The gap in the Official Journal, though, is still open, and that gap is where the purchasing decision gets made. The obligations, dates and penalty tiers themselves are unpacked in the EU AI Act guide for business.
For a US or UK company that never touches the European market, the AI Act half of this question is academic. The buyer half is not.
Who actually asks for the certificate?
You buy certification for somebody else's procurement team, not for your own peace of mind - peace of mind is available faster and cheaper. So the question is never "would it be nice to have" but "who specifically is asking, and do they have it in writing". Five common situations point in five different directions.
| Your situation | Recommendation | Why |
|---|---|---|
| You sell AI systems to large enterprises or bid for public contracts | Certify | A self-declaration does not count as third-party evidence in due diligence |
| You use ChatGPT and Copilot in the office and build nothing | Nothing formal, NIST AI RMF as a frame at most | The standard describes a management system for organizations that supply or develop AI; buying an office tool does not make you its subject |
| You already run ISO 27001 | Alignment first, certification as an option | ISO 42001 shares the Annex SL structure with 27001, so bolting on an AI management system costs far less than building one from scratch |
| You build AI agents for clients | Alignment now, certification when the first enterprise client asks | The audit cost is steep relative to agency revenue, and the free route delivers most of the value |
| You are a startup heading into a funding round | Documented process, no certificate | Early-stage investors look at policies and a risk register; the certificate starts to matter when you sell to large accounts |
None of these situations leads automatically to "you must certify". Certifying just in case is the most expensive option on the table, because you pay every year for proof nobody looks at.
How much does ISO 42001 certification cost?
The money in ISO 42001 does not go toward the certificate. It goes toward the housekeeping you have to finish before the certificate. The audit is the smaller line item; the bigger one is usually preparation: a gap assessment, then building the controls you turn out not to have. Published ranges from audit practices, for an organization of up to 20 people, look like this.
| Item | Cost | Can you skip it |
|---|---|---|
| Buying the standard | 225 CHF | Not if you are serious |
| Self-assessment and readiness checklist | 0 | It is the starting point, not a line to cut |
| Gap assessment and building controls | USD 13,000-50,000 | Yes, if you do the work in-house |
| Certification audit, stage 1 and stage 2 | USD 5,000-20,000 | No, this is the certificate |
| Surveillance audit, years 2 and 3 | around USD 2,500 a year | No, or the certificate lapses |
| Full three-year auditor cycle (certification plus two surveillance audits), company under 20 people | around USD 10,000 | No, and the cycle restarts after year three |
A full first year for a company under 20 people lands between USD 20,000 and 70,000. Other estimates put companies of 50-200 people at USD 85,000-150,000. The difference sits in scope and process count, not in a price list, and it shows how far estimates diverge on a market this young.
Certification is also not a one-off purchase. It behaves like a subscription rather than a diploma: two surveillance audits and a recertification spread the cost across a three-year cycle that then starts again.
One practical note on getting a quote. Certification bodies do not publish list prices for ISO 42001 in any market. Every number comes out of a scoping call and depends on headcount, the number of processes in scope and how many sites you run. The absence of a price list is itself a signal about market maturity.
Is there a free ISO 42001 certification?
Free certification does not exist and cannot exist, because a certificate is issued by an independent body after a paid audit. What is free is everything that happens before the audit: self-assessments, readiness checklists and risk management frameworks. A self-assessment costs nothing and tells you where you stand. A certificate costs tens of thousands and says the same thing in somebody else's voice, which is exactly what you are paying for.
Two sources are worth knowing. The first is the NIST AI Risk Management Framework, published on 26 January 2023, free, voluntary and built on four functions: Govern, Map, Measure, Manage. There is no certification against it, and that is a feature - nobody charges you to confirm that you use it. The second is the readiness checklist that certification bodies hand out in exchange for an email address. That is an auditor's lead magnet, not a gift. The material is often good. Take it, use it, and remember what it was built for.
What can you do this week at zero cost?
Three documents cover a substantial share of Annex A and require no invoice: a register, a risk view and a rule. The register says what the company uses. The risk view says what can go wrong. The rule says who may do what. Every auditor and every client questionnaire starts there.
| Step | What you write | Time |
|---|---|---|
| Register | Every AI tool in use: who uses it, for what, on which data, under whose account | 2-3 hours in a spreadsheet |
| Risk | Against each entry: what happens when the tool gets it wrong, and who would notice - three levels are enough | 1-2 hours |
| Rule | A written AI policy: who may use what, what never leaves the company, who signs off output before it reaches a client | Half a day from a template |
The third step does not need to start from a blank page. The AI policy template is on our site as a free download, and what the document is for is covered in the piece on AI policy for business.
The register and the risk classification also have a second life after the audit. They are the raw material that turns into a company knowledge base: one source of truth about what the company runs and under what rules. The move from "we have a spreadsheet" to "we have a knowledge base" happens on its own once people start using the spreadsheet.
How do you get certified, and how many companies have?
Certification takes four steps, three of which you can take yourself; only the last one requires an accredited body. You set the scope and inventory your AI systems. You build the management system: policies, risk and impact assessment, evidence. You run an internal audit and a management review. Then the certification body runs its own audit in two stages, documentation first, implementation second.
The market is still small. The ISO Survey, the official annual count of certificates per standard, does not report ISO 42001 yet, because accredited certification only began in 2024. Press releases from newly certified companies in April 2026 speak of the "first 350 organizations" worldwide, against tens of thousands for ISO 27001. ISO 42001 is a leading indicator today, not a market standard.
The list of who already holds one supports the procurement-ticket reading. Anthropic announced its certification on 13 January 2025. Microsoft brought Azure AI Foundry Models and Security Copilot into scope in July 2025 and in May 2026 announced the recertification of Microsoft 365 Copilot with a wider scope. AWS certifies Bedrock, Q Business, Textract and Transcribe. All three sell AI to other companies as infrastructure, and for them the certificate is a contract clause rather than an ornament.
One practical thing that rarely gets written down: check the accreditation before you sign. Ask which accreditation body has accredited the certifier for this specific standard - ANAB in the United States, or the national accreditation body in your country in Europe - then check that register yourself. A certificate from a body without accreditation for ISO 42001 is worth roughly what your own statement is worth, and costs what a certificate costs.
Frequently asked questions
Is ISO 42001 mandatory?
No. No law in the US, the UK or the EU requires the standard or the certificate. What is mandatory is the AI Act for companies in its scope, and data protection law such as the GDPR. ISO 42001 is one of the tools a company can use to show it has AI under control.
Does an ISO 42001 certificate mean AI Act compliance?
No. Presumption of conformity applies only to harmonized standards cited in the Official Journal of the EU under Article 40 of the AI Act, and no AI management system standard holds that status yet. A certificate organizes your documentation and speeds up the work. AI Act compliance is assessed separately.
How much does ISO 42001 certification cost for a company of 20 people?
The certification audit alone runs USD 5,000-20,000, with preparation adding USD 13,000-50,000. A full first year for a company under 20 people lands between USD 20,000 and 70,000. After that, surveillance audits cost around USD 2,500 a year, and the cycle restarts after three years.
Is there a free ISO 42001 certification?
There is not, and there cannot be, because a certificate is issued by an independent body after a paid audit. The free tools all sit before the audit: self-assessments, readiness checklists from certification bodies, and the NIST AI Risk Management Framework.
How many companies hold ISO 42001?
The ISO Survey does not report the standard yet, because accredited certification only started in 2024. Press releases from newly certified companies in April 2026 speak of the first 350 organizations worldwide. Treat that as a market estimate rather than an official ISO figure.
We have ISO 27001 - is ISO 42001 worth adding?
It is worth considering, because both share the Annex SL structure and an AI management system bolts onto an existing one for far less than it costs to build from scratch. Hold the certification decision itself until the first client writes it into a contract or a questionnaire.
What is the difference between compliance and certification?
Compliance means the company meets the requirements and holds the evidence in-house. Certification means an independent accredited body confirmed it after an audit. You do compliance yourself, for free. You buy certification for someone who needs third-party proof.
Three steps first, the certificate only if someone asks
If nobody asks for a certificate after the register, the risk view and the rule, you have just saved tens of thousands of dollars. If somebody does, you start the audit with material instead of an empty folder. One question the register does not answer: does the AI agent you already use behave the way you think it does? That is what AI Trust Layer is for - a fixed-price audit of one system at $950, with a report showing what the agent does with your data and where it breaks.
Let's talk