Skip to content
EUROTECH Certification logoEUROTECHCertification

Services / ISO 42001 certification

ISO 42001 certification for your AI management system

Certification for organizations, not individuals: we audit how your company governs the AI systems it develops, provides or uses, from $800.

From $800Certified by EUROTECH

Empty modern office with a glass meeting room and a single chair

What ISO 42001 certification covers

ISO/IEC 42001:2023 is the first international standard for an artificial intelligence management system, often shortened to AIMS. Published in December 2023, it applies to any organization that develops, provides or uses AI products and services, whatever its size or sector.

Like other ISO management system standards, it asks for context, leadership, planning, support, operation, performance evaluation and improvement. What makes it different is the AI-specific content: an AI policy, defined roles and responsibilities for AI, AI risk assessment and treatment, AI system impact assessment, and controls over the AI system life cycle, data, third parties and the information you give to users.

An annex of the standard lists reference controls, and, as in ISO 27001, you decide which apply and justify your choice in a Statement of Applicability. The auditor checks that choice against how your AI systems are actually built, deployed and monitored.

Please note: many search results for ISO 42001 are courses for individuals, such as lead auditor training. This page is about certifying your organization's management system. For training, see MEGADEMI.

  • Stage 1 review of AI policy, scope, risk and impact assessment methods and Statement of Applicability
  • Stage 2 audit of AI system life cycle controls and evidence
  • Certification decision and three-year certificate
  • Listing on our verification portal
  • Yearly surveillance audits and recertification

Developer, provider or user: the options for your scope

The scope depends on your role. An AI developer will be audited on design, data management, model development, testing and validation. A provider that offers AI-based services to customers will be audited on deployment, monitoring, incident handling and customer information. An organization that mainly uses AI from others will be audited on how it selects, approves, monitors and controls those systems and their suppliers.

Many organizations are more than one of these. A software company might build its own models, embed third-party models and use AI tools internally. The scope statement on your certificate should say which AI systems and roles it covers, in words your customers can understand.

If you already hold ISO/IEC 27001, the two standards fit together closely. Risk management, supplier control, incident management and document control can be shared, and an integrated audit saves time. Data protection and security controls from your ISMS often serve as evidence for AI data controls as well.

What the price depends on

ISO 42001 certification with EUROTECH starts at $800. Audit time grows with the number and risk of the AI systems in scope.

  • Number of AI systems in scope and how critical they are
  • Your role: developer, provider, user or a combination
  • People involved in AI development, deployment and oversight
  • Sites and teams, including remote teams
  • Integration with ISO 27001 or other management systems

The written quote lists audit days and all fees. A clear inventory of AI systems with their owners and risk ratings is the single most useful document for keeping audit time under control.

Third-party AI components also count. If you rely on external models or AI services, the auditor checks how you assessed them, what contractual commitments you have, and how you monitor their behaviour and changes.

How ISO 42001 certification works with us

  1. Application and scoping

    Step 1

    Scope and AI inventory

    We agree your role and the AI systems in scope, and quote the ISO 42001 audit in writing.

  2. Stage 1 document review

    Step 2

    Stage 1 review

    We check your AI policy, risk and impact assessment methods and Statement of Applicability.

  3. Stage 2 on-site audit

    Step 3

    Stage 2 audit

    The auditor follows selected AI systems through their life cycle with live evidence.

  4. Certificate and surveillance

    Step 4

    Certificate and surveillance

    After the decision you receive the ISO 42001 certificate, with yearly surveillance audits.

AI regulation and customer expectations by region

We certify ISO 42001 for organizations in the USA, Europe, Asia and Africa. The regulatory context is moving quickly. In the European Union, the AI Act sets obligations based on the risk class of AI systems. In the USA, the NIST AI Risk Management Framework is widely used as voluntary guidance, alongside sector and state rules. Other countries are introducing their own frameworks.

ISO 42001 asks you to identify the legal and contractual requirements that apply to your AI systems and to meet them. Certification does not equal compliance with the EU AI Act or any other law, but a working AI management system gives you the structure to show how you manage those obligations.

Customers increasingly ask suppliers how they govern AI: which models are used, how data is handled, how outputs are checked. An ISO 42001 certificate, checkable online, answers the governance part of those questions.

What to expect during the audit

Expect the auditor to pick one or two AI systems from your inventory and follow them through the life cycle: why the system was approved, what data it uses and where that data came from, how it was tested before release, how its impact on people was assessed, how it is monitored in use and who can stop or change it.

Human oversight and transparency are common topics. The auditor will look at how users are told they are interacting with AI where relevant, how outputs are reviewed for higher-risk uses, and how complaints or incidents involving AI are recorded and handled.

Data is a frequent focus. Expect questions on how training and input data are sourced, whether its use is permitted, how quality and bias are checked, and how personal data is protected. Records of these checks are stronger evidence than a policy that says they should happen.

Findings are graded as major or minor, and the certification decision is based on the evidence. You receive a written report explaining each finding.

Keeping the certificate as your AI changes

AI systems change more often than most processes: models are retrained, new tools are adopted and new uses appear. Keep the AI system inventory current, run impact and risk assessments when systems change significantly, and record decisions to deploy or retire systems.

Surveillance audits will look at new AI systems added since the last audit, incidents and how they were handled, monitoring results and progress on objectives. Tell us about large changes in scope, such as launching a new AI product, so the audit plan covers it.

Training for staff on AI risks and responsible use supports the competence requirements of the standard. Training is available through MEGADEMI at megademi.com.

Keep impact assessments proportionate. A low-risk internal tool needs a short assessment; a system that affects decisions about people needs a deeper one, with clear human oversight. The auditor looks for that proportionality.

Questions buyers ask

How much does ISO 42001 certification cost?

With EUROTECH it starts at $800. The number and risk of AI systems, your role, people and integration with ISO 27001 set the final price.

Is ISO 42001 certification for people or companies?

This service certifies an organization's AI management system. Courses for individuals, such as lead auditor training, are a different thing.

Does ISO 42001 make us compliant with the EU AI Act?

Certification alone does not make you compliant. ISO 42001 gives you a management system to identify and meet your obligations, including those under the AI Act.

We only use AI tools from other companies. Can we certify?

Yes. The standard applies to organizations that use AI as well as those that develop or provide it. The audit then focuses on selection, approval, monitoring and supplier control.

Can ISO 42001 be combined with ISO 27001?

Yes. They share structure and many processes, and an integrated audit usually saves time.

When was ISO 42001 published?

ISO/IEC 42001 was published in December 2023.

Get a quote for ISO 42001 certification

Tell us your company, sites and the standard you need. We reply with a written quote and the audit plan.

Prefer to talk? Call +1 307 205 1833
Monday to Friday, 09:00 to 18:00 (US Mountain Time)

We use your details only to reply to this request. See our privacy policy.