Before you start: is your organization ready?

ISO 42001 can be implemented by any organization that uses, develops, or deploys AI systems. Confirm you have:

  • Top management commitment — At least one executive who sponsors the project and signs the AI policy
  • At least one identified AI system — You do not need many; one system to define the initial scope is enough
  • A project owner — CISO, DPO, or someone from compliance or IT with at least 20% dedicated time
  • Estimated budget — Management platform, consulting (optional but recommended), and certification body fees

The 6 implementation phases

1
Initial gap analysis and scope definition
Month 1

Define which AI systems fall within the AIMS scope and what the gap is against ISO 42001. A poorly defined scope extends certification time and increases audit costs.

Deliverables:
  • Initial AI systems inventory with risk classification
  • Clause-by-clause gap analysis report
  • AIMS scope approved by management
  • Project plan with milestones and owners
Tool: SoberanIA includes an automated 45-question diagnostic that generates a gap analysis with clause-by-clause prioritized recommendations.
2
Organizational context and leadership
Month 2

Establish the organizational context (§4), define roles and responsibilities (§5.3), and draft the AI policy that top management will sign (§5.2). This month produces the foundational AIMS documents.

Deliverables:
  • Stakeholder analysis and AI requirements mapping
  • AI policy signed by management
  • AI governance RACI matrix
  • AIMS objectives (§6.2) with tracking indicators
  • AI governance committee constituted (if applicable)
3
AI risk and impact assessment
Month 3

The core of ISO 42001. Identify and evaluate the risks of each AI system in scope: biases, failures, rights impact, opacity. Includes the algorithmic impact assessment (AIA) required by Annex A.5 and executed per §8.2.

Deliverables:
  • Documented AI risk assessment methodology
  • AI risk matrix with acceptance criteria
  • Algorithmic impact assessment (AIA) for each in-scope system
  • Risk treatment plan with selected Annex A controls
  • Statement of Applicability (SoA)
Note: The SoA justifies which of the 38 Annex A controls apply to your organization and which are excluded and why. It is the document the auditor will scrutinize most carefully.
4
Annex A controls implementation
Month 4

Implement the controls selected in your SoA. The 38 Annex A controls are distributed across 9 sections (A.2–A.10). The key controls for this month include:

Deliverables by section:
  • A.2 — AI Policies: AI acquisition policy, training data policy
  • A.3 — Internal organization: AI governance roles, responsible AI training plan
  • A.6 — AI system lifecycle: Design, testing, deployment, and monitoring procedures
  • A.8 — Stakeholder information: Explainability documentation, challenge/appeal procedure
  • A.5 — Impact assessment: Completed and approved algorithmic impact assessments
  • A.10 — Third parties: AI vendor due diligence, contractual clauses
5
Internal audit and management review
Month 5

Before the certification audit, conduct a complete AIMS internal audit. Identify non-conformities, close them with corrective actions, and hold the management review with system performance results.

Deliverables:
  • Internal audit program and plan
  • Internal audit report with findings
  • Corrective actions for identified non-conformities
  • Management review minutes (§9.3)
  • AIMS performance metrics (§6.2 indicators)
Tip: Use an internal auditor different from the implementation lead. If you do not have a certified internal auditor, SoberanIA includes an external auditor support for this stage.
6
Certification audit
Month 6

The certification body (SGS, Bureau Veritas, TÜV SÜD, LRQA, or another accredited body) conducts the Stage 1 audit (document review) and Stage 2 audit (on-site). Minor non-conformities allow up to 90 days to close before the certificate is issued.

What the auditor will review:
  • Complete AIMS documentation (policy, SoA, risks, controls)
  • Implementation evidence (records, minutes, metrics)
  • Updated AI systems inventory
  • Algorithmic impact assessments per in-scope system
  • Internal audit results and management review
Outcome: ISO/IEC 42001:2023 certificate valid for 3 years, subject to annual surveillance audits.

The 5 mistakes that delay implementation

  • Scope too broad — Including all AI systems in the first certification is the most common mistake. Start with 1–3 highest-risk or most strategically visible systems.
  • Lack of genuine management commitment — ISO 42001 requires evidence of "leadership and commitment" (§5.1). Without management signatures and participation in the review, the audit can fail on this point.
  • Confusing ISO 27001 with ISO 42001 — Information security controls do not cover AI risks. The team must understand the difference before leading implementation.
  • Incomplete or unjustified SoA — The Statement of Applicability must justify every Annex A control exclusion. Exclusions without justification generate non-conformities in the audit.
  • Not documenting AI design decisions — ISO 42001 requires lifecycle traceability. If there are no records of how a model was trained or a deployment decision was made, the auditor cannot verify the control.

Frequently asked questions

Between 4 and 18 months, depending on organization size, the number of AI systems in scope, and whether you already have experience with ISO management systems. Small organizations with 1–2 AI systems and consulting support can reach certification in 4–6 months. Large enterprises with many AI systems typically take 12–18 months.

The cost has three components: a management platform (like SoberanIA), implementation consulting, and certification body fees (ICONTEC, SGS, Bureau Veritas, TÜV SÜD). For a mid-size organization, certification audit fees typically range from USD 3,000 to USD 8,000 for the initial audit. Consulting varies by scope. SoberanIA's Professional plan includes consulting support.

It is not mandatory, but highly recommended for a first certification. An experienced ISO 42001 consultant accelerates implementation, reduces errors in the Statement of Applicability, and prepares you better for the audit. Many organizations try to go it alone and end up with major non-conformities that delay certification by 6+ months.

Minor non-conformities allow up to 90 days to close with evidence. Major non-conformities require a re-audit of that clause before the certificate is issued. A well-prepared organization rarely has major non-conformities. The internal audit in month 5 exists precisely to identify and close them before the certification audit.

ISO 42001 maps very closely to the management system requirements of the EU AI Act (especially Articles 9, 10, 11, and 12 for high-risk AI). While the EU AI Act does not explicitly mandate ISO 42001, the European Commission is developing harmonized standards based on it. Holding the certification demonstrates a presumption of conformity and simplifies regulatory audits.

Start your ISO 42001 implementation today

Free 20-question diagnostic. We identify your gap and deliver a prioritized plan. No commitment required.

Free diagnostic

You might also like: ISO 42001 vs ISO 27001 · AI systems inventory guide · ISO 42001 vs NIST AI RMF