Live 16 practitioner certifications live · First lesson free on every course Back to main site →

What actually happens in a twelve-to-eighteen month ISO 42001 certification

A guided walk through the certification journey from decision to certificate. What artefacts you produce at each stage, what the two audit stages actually look like, and what happens in Year 1, Year 2 and Year 3 of the three-year certification cycle.

Free preview 12 min read Under review
Legal basis
ISO/IEC 42001 primary-source stack current to 19 September 2026. Core: ISO/IEC 42001:2023 first edition December 2023 (ten clauses 0-10 plus Annex A with 38 controls across groups A.2 Policies related to AI, A.3 Internal organisation, A.4 Resources for AI systems, A.5 Assessing impacts of AI systems on individuals or groups and societies, A.6 AI system lifecycle, A.7 Data for AI systems, A.8 Information for interested parties of AI systems, A.9 Use of AI systems, A.10 Third-party and customer relationships, plus Annex B implementation guidance, Annex C AI-related organisational objectives, Annex D use of AIMS across domains). Companion standards: ISO/IEC 23894:2023 (guidance on AI risk management), ISO/IEC 23053:2022 (framework for AI systems using machine learning), ISO/IEC 42005:2025 (AI system impact assessment), ISO/IEC 22989:2022 (AI concepts and terminology), ISO/IEC TR 24028:2020 (trustworthiness in AI). Integration standards: ISO/IEC 27001:2022 for the AIMS-on-top-of-ISMS pattern, ISO/IEC 27701:2025 for the PIMS integration. India-specific stack: India AI Governance Guidelines released by MeitY in November 2025 (seven sutras Trust / People-first / Innovation over restraint / Fairness and equity / Accountability / Understandability by design / Safety resilience sustainability, across six pillars Infrastructure / Capacity building / Policy and regulation / Risk mitigation / Accountability / Institutions, with Annexure 6 recommending ISO/IEC 42001), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 effective 20 February 2026 introducing Synthetically Generated Information as a due-diligence category with visual labelling audio disclosure metadata embedding and 2 to 3 hour takedown for deepfake harm, MeitY AI Advisory dated March 2024 on labelling AI-generated content operative until superseded on labelling by the 2026 Rules, SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 (Advisory on emerging advanced AI tools for vulnerability detection, Cyber-suraksha.ai task force, applies to every regulated entity in the Indian securities market), Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay released 13 August 2025 (seven sutras 26 recommendations six pillars Infrastructure Policy Capacity Governance Protection Assurance), DPDP Act 2023 and DPDP Rules 2025 notified November 2025 with phased commencement (no equivalent to GDPR Article 22, no right to explanation), BIS adoption as IS/ISO/IEC 42001:2023 identical to ISO text, IndiaAI Mission approved March 2024 with ₹10,371 crore outlay over five years across seven pillars including Safe & Trusted AI (13 projects funded as of July 2026 on deepfake and bias), IndiaAI Safety Institute announced January 2025. Global adjacent regulation for extraterritorial reach and crosswalk: EU AI Act Regulation (EU) 2024/1689 phased application 2 February 2025 prohibited practices and AI literacy live, 2 August 2025 GPAI transparency for new models, 2 August 2026 general application and Article 50 transparency, 2 December 2026 new prohibited practices on synthetic intimate content and CSAM, 2 December 2027 Annex III high-risk (pushed back from August 2026 by Digital Omnibus), 2 August 2028 Annex I product-embedded high-risk. NIST AI Risk Management Framework 1.0 (January 2023) four functions Govern Map Measure Manage with official crosswalk to ISO/IEC 42001 published by NIST AIRC. OECD AI Principles (2019 updated 2024). UNESCO Recommendation on the Ethics of AI (2021). Council of Europe AI Framework Convention (opened for signature September 2024). Certification body landscape referenced: A-LIGN, BSI India, Bureau Veritas India, DNV Business Assurance India, Schellman, SGS India, TÜV SÜD South Asia, TÜV Nord India, Intertek India (accredited under ANAB, UKAS, RvA pending NABCB scheme extension). Personal certification schemes referenced (not primary): PECB Lead Implementer and Lead Auditor for ISO 42001, BSI ISO 42001 Lead Implementer, operating under ISO/IEC 17024. India first-mover organisational certifications referenced: Mphasis (first Indian IT services company to certify, 2025) and KPMG India (certified by SGS December 2025). Items requiring ongoing verification and flagged inside the relevant lessons: NABCB scheme extension timeline for ISO 42001; any ISO/IEC 42001 amendment beyond first edition; Digital India Act draft status and eventual enactment; RBI conversion of FREE-AI Report recommendations into binding master directions; DPDP Board of India Chairperson appointment status; new India AI-specific legislation.

Now that you know what ISO 42001 is, what is in it, and how it sits against NIST AI RMF and the EU AI Act, let me walk you through what a certification project actually looks like on the calendar. I have deliberately not put this at the end of the course. I want you to see the whole path in outline early, so that as we walk each clause and each Annex A control in Modules 2 through 8, you know where each piece fits in the journey.

The three phases

Every ISO 42001 certification runs in three broad phases:

  1. Build phase — you build the AIMS. Typically six to twelve months for a first-time filer.
  2. Certification phase — the two-stage audit performed by an accredited certification body. Typically two to four months from CB engagement to certificate issuance.
  3. Sustain phase — the three-year certification cycle with annual surveillance in Years 1 and 2 and full recertification in Year 3.

Let me walk each phase.

Build phase, months 1 to 12

The build phase is where most of the actual work happens. This is what Modules 2 through 6 of this course teach you to do. In outline, you deliver these ten artefacts:

  1. AIMS Scope Statement (Clause 4.3). One page. Says which AI systems, which teams, which processes are inside the AIMS. Written carefully because it also defines what the auditor will and will not test.
  2. AI Policy (Clause 5.2 + Annex A.2.2). Two to four pages. Approved by top management. Sets the organisational stance on responsible AI. Aligned with the India AI Governance Guidelines seven sutras.
  3. Roles and Responsibilities (Clause 5.3 + Annex A.3.2 and A.3.3). A one-page RACI covering AI accountability, ethics, escalation of concerns.
  4. AI System Inventory. Every AI system in scope, with its lifecycle stage, its business purpose, its data sources and its risk tier. This becomes the master list from which every downstream artefact hangs.
  5. AI Risk Assessment Methodology (Clause 6.1.2, guided by ISO/IEC 23894:2023). Six to eight pages describing how you identify, analyse, evaluate, treat and monitor AI risk. This is the document your auditor tests most rigorously.
  6. AI Impact Assessment (Annex A.5.2, guided by ISO/IEC 42005:2025). One AIIA per AI system in scope. Covers fairness, safety, transparency, privacy, security, human oversight, environmental impact.
  7. AI Risk Register + Risk Treatment Plan (Clauses 6.1.3, 8.3). One consolidated risk register covering every AI system in scope, plus a treatment plan mapping each risk to Annex A controls or other treatment.
  8. Statement of Applicability (SoA) (Clause 6.1.3 output). All 38 Annex A controls listed, with Include or Exclude decision and clause-anchored justification. This is the single most-audited document in the AIMS.
  9. Internal Audit Programme (Clause 9.2). Three-year rolling programme covering all clauses and applicable Annex A controls.
  10. Management Review pack + minutes (Clause 9.3). Evidence of one full management review with mandatory agenda items and outputs. Auditors will not accept a certification without at least one completed cycle.

By the end of the build phase, you should have all ten documents populated with real content grounded in your organisation. Not templates. Not placeholders. Real content that describes the actual AI systems your organisation runs.

The timeline splits roughly like this. Months 1 to 2: scope, policy, roles, inventory. Months 3 to 6: risk methodology, first pass of AIIAs, risk register, initial SoA. Months 7 to 9: implement controls on the "Include" side of the SoA, gather evidence. Months 10 to 12: run at least one internal audit cycle, at least one management review, close nonconformities, run gap analysis against the standard. A team of two or three dedicated people plus wider organisational support can carry this through in nine to twelve months. If you are also implementing a full ISO 27001 for the first time in parallel, add three to six months.

Certification phase, months 13 to 16

Once the AIMS is built and has run for at least one internal audit and one management review cycle, you engage a certification body. Module 7 walks CB selection and audit preparation in detail. The certification audit itself has two stages.

Stage 1 — Documentation Review. Usually one to three audit days. The auditor reads your scope statement, your policy, your risk methodology, your AIIA outputs, your SoA. They ask questions to confirm that the AIMS is real and not paper. They identify areas of concern that they will test at Stage 2. Common Stage 1 findings I have seen: scope statement too broad, AI policy indistinguishable from a general IT policy, risk methodology does not distinguish AI-specific risk from ordinary IT risk, no evidence of at least one AIIA cycle, SoA justifications that copy standard text back to the auditor. If Stage 1 finds a major concern, you get a remediation window (usually 60 to 90 days) before Stage 2. If Stage 1 is clean, Stage 2 usually follows within 30 to 60 days.

Stage 2 — Operating Effectiveness. Usually three to eight audit days depending on the organisation size and AIMS scope. The auditor tests whether the AIMS actually operates as documented. They sample AI systems. They interview owners. They test the evidence for controls on the "Include" side of your SoA. They read management review minutes. They read internal audit reports. They observe the operating cadence. Common Stage 2 findings: internal audit programme paper-only, management review missed a mandatory agenda item, no evidence that AIIA was actually revisited when an AI system was updated, evidence for A.6 lifecycle controls missing for one or more sampled systems.

Nonconformities are classified as major or minor. A major means the process is not functioning, and it must be closed through CAPA (Corrective Action Preventive Action) before the certificate can issue. A minor is a gap that does not defeat the process, and it can be closed with a plan of action inside the certification cycle. Certificates issue when all majors are closed.

Sustain phase, three-year cycle

The certificate is valid for three years, but it is not static. You run:

  • Surveillance audit at end of Year 1 — typically 30 to 60 percent of the initial audit scope. The CB samples a subset of clauses and Annex A controls. Focus is continual operation and closure of prior findings.
  • Surveillance audit at end of Year 2 — similar to Year 1, with different sampling to progressively cover the whole system across the three-year cycle.
  • Recertification audit at end of Year 3 — full-scope audit similar to the initial Stage 2. This is when the certificate renews for another three years.

Between these events, the AIMS runs continuously. You conduct AIIAs whenever an AI system is added or materially changed. You update the risk register periodically. You conduct internal audits per your programme. You run management reviews annually. You handle nonconformities through CAPA. The certificate is not the end of the work — it is the beginning of the working cadence that keeps the certificate alive.

Approximate cost for an Indian organisation

For a mid-size Indian SaaS or IT services company with an AIMS covering a defined set of AI systems, the direct out-of-pocket cost typically splits across three categories. Certification body audit fees range from USD 15,000 to USD 30,000 for the initial Stage 1 + Stage 2 combined (accredited CBs charge USD 2,500 to USD 4,500 per audit day). Surveillance audits cost around 30 to 60 percent of that in each of Years 1 and 2, and full recertification cost in Year 3. Internal build cost — consultants if you use them, and the fully-loaded cost of your internal team — will typically run several times the CB fee. Vendor pricing for the standards themselves is a small line item (ISO 42001 + 23894 + 42005 + 22989 = about CHF 500 for the paper you must own).

Compare this to the market price for a personal PECB Lead Implementer training course sold in India today — Mindset Cyber sells it self-paced at Rs 56,999 and the classroom-led options through NovelVista and The Knowledge Academy run Rs 30,000 to Rs 40,000. Those are personal-certification schemes for individuals; they do not certify the organisation. This course, at Rs 9,999 founding, teaches you to build and run the organisational AIMS that leads to actual certification. Not the same thing at all.

Next lesson, I want to close Module 1 by placing the India AI Governance Guidelines against the ISO 42001 clause structure, so you can see exactly where the seven sutras and six pillars map on top of the standard. That will bridge us into Module 2 where we start reading the clauses in detail.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
ISO/IEC 42001:2023, Clause 4.3 Scope of the AIMS (AIMS scope statement) L4-C1
Clause 4.3 requires the organisation to determine the boundaries and applicability of the AIMS to establish its scope. The scope shall be documented and available. For AI, the scope statement must specifically identify the AI systems in scope which is significantly harder than an ISMS scope because AI capabilities are often embedded in wider products rather than run as separate systems.
ISO/IEC 42001:2023, Annex A A.2.2 AI Policy (AI policy documented) L4-C2
Annex A control A.2.2 requires the organisation to document, review, communicate and enforce an AI policy that expresses management commitment to responsible AI, aligns with the organisational context and other policies, and is available to relevant interested parties. This is not the same as Clause 5.2 which requires a policy in principle. A.2.2 controls what has to be inside that policy.
ISO/IEC 42001:2023, Annex A A.5.2 AI Impact Assessment (AIIA process required) L4-C3
Annex A control A.5.2 requires the organisation to establish a process for assessing the impact of AI systems on individuals, groups and societies. Impact must cover both intended and reasonably foreseeable unintended use. This is the AI Impact Assessment (AIIA). ISO/IEC 42005:2025 is the companion standard providing methodology.
ISO/IEC 23894:2023, ISO/IEC 23894:2023 AI risk management (Guidance on AI risk management) L4-C4
ISO/IEC 23894:2023 provides guidance on how organisations that develop, produce, deploy or use AI systems can manage AI-related risks. Non-certifiable companion to ISO 42001. Builds on ISO 31000:2018 risk management framework but adapts it for AI-specific risk sources: data quality, model bias, opacity, robustness, adversarial manipulation, autonomy and human oversight. Referenced by ISO 42001 Clause 6.1.2 as the guidance an auditor expects a risk methodology to follow.
ISO/IEC 42005:2025, ISO/IEC 42005:2025 AI impact assessment (AI system impact assessment) L4-C5
ISO/IEC 42005:2025 provides guidance on conducting an AI system impact assessment (AIIA). Companion to ISO 42001 Annex A control A.5.2. Methodology covers stakeholder identification, impact identification across fairness, safety, transparency, privacy, security, human oversight, environmental impact and society-level impact; scoring; documentation; and lifecycle re-assessment.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: What ISO/IEC 42001 actually is, and why it turned into a procurement gate in 2026
Module 2: Reading Clauses 4, 5 and 6: Context, Leadership and Planning
  • Clauses 4.1 and 4.2: understanding your context and identifying interested parties
  • Clause 4.3: writing an AIMS Scope Statement that a certification body will accept
  • Clause 5: Leadership, AI Policy and Roles — where an AIMS becomes real
  • Clause 6.1: the AI risk assessment methodology — the beating heart of the AIMS
  • Clauses 6.2 and 6.3: AI objectives and planning of changes
Module 3: Reading Clauses 7, 8, 9 and 10: Support, Operation, Performance evaluation, Improvement
  • Clauses 7.1 to 7.4: Resources, Competence, Awareness, Communication
  • Clause 7.5: Documented information — what must be in writing, and how it is controlled
  • Clause 8: Operation — executing the risk methodology and running the AIIA
  • Clause 9: Performance evaluation — monitoring, internal audit, management review
  • Clause 10: Continual improvement, nonconformity and the CAPA process
Module 4: Annex A controls Part 1: A.2 Policies, A.3 Internal organisation, A.4 Resources, A.5 Impact assessment
  • Annex A.2 — Policies related to AI: three controls that anchor the AIMS
  • Annex A.3 — Internal organisation: AI roles and the concerns-reporting channel
  • Annex A.4 Part 1 — Data and tooling resources (A.4.2 and A.4.3)
  • Annex A.4 Part 2 — Compute, human and financial resources (A.4.4 to A.4.6)
  • Annex A.5 — AI Impact Assessment: the four controls that decide whether an AIMS is real
Module 5: Annex A controls Part 2: A.6 AI lifecycle, A.7 Data, A.8 Information, A.9 Use, A.10 Third-party
  • Annex A.6 Part 1 — AI lifecycle: requirements, design and development
  • Annex A.6 Part 2 — Verification, deployment, operation, monitoring and event logs
  • Annex A.7 — Data for AI systems: five controls with the DPDP overlay
  • Annex A.8 — Information for interested parties: where the IT Rules 2026 SGI obligations land
  • Annex A.9 and A.10 — Responsible use of AI systems and third-party relationships
Module 6: Building the AIMS end-to-end: inventory, impact assessment, risk assessment, Statement of Applicability, tooling
  • Building the AI system inventory — the foundation everything else hangs on
  • Running an AI Impact Assessment per ISO/IEC 42005:2025 — the operational template
  • Running the AI risk assessment methodology per ISO/IEC 23894:2023
  • Building the Statement of Applicability — the single most-audited document
  • GRC tooling landscape — buy versus build for an AIMS
Module 7: Certification body selection, Stage 1 audit, Stage 2 audit, certificate issuance
  • The accreditation chain — why the certificate means anything, and where NABCB stands on ISO 42001
  • CB selection — the RFP process, scoring criteria and negotiation
  • Stage 1 — the documentation review: what the auditor tests and how to pass first time
  • Stage 2 — the operating-effectiveness audit: sampling, interviews, evidence
  • The three-year sustain cycle — surveillance, recertification and living with the certificate
Module 8: The India overlay + the next five years: AI Governance Guidelines, IT Rules 2026, SEBI, RBI FREE-AI, DPDP, EU AI Act, NIST AI RMF
  • The India AI Governance Guidelines in operational depth — the seven sutras and six pillars, clause by clause
  • IT Amendment Rules 2026 SGI obligations in operational depth — the first binding AI law in India
  • Sector-specific overlays — SEBI 5-May-2026, RBI FREE-AI, and the wider sectoral picture
  • DPDP intersection with AI, and EU AI Act extraterritorial reach on Indian exporters
  • NIST AI RMF crosswalk and the next five years — closing the course