Now that you know what ISO 42001 is, what is in it, and how it sits against NIST AI RMF and the EU AI Act, let me walk you through what a certification project actually looks like on the calendar. I have deliberately not put this at the end of the course. I want you to see the whole path in outline early, so that as we walk each clause and each Annex A control in Modules 2 through 8, you know where each piece fits in the journey.
The three phases
Every ISO 42001 certification runs in three broad phases:
- Build phase — you build the AIMS. Typically six to twelve months for a first-time filer.
- Certification phase — the two-stage audit performed by an accredited certification body. Typically two to four months from CB engagement to certificate issuance.
- Sustain phase — the three-year certification cycle with annual surveillance in Years 1 and 2 and full recertification in Year 3.
Let me walk each phase.
Build phase, months 1 to 12
The build phase is where most of the actual work happens. This is what Modules 2 through 6 of this course teach you to do. In outline, you deliver these ten artefacts:
- AIMS Scope Statement (Clause 4.3). One page. Says which AI systems, which teams, which processes are inside the AIMS. Written carefully because it also defines what the auditor will and will not test.
- AI Policy (Clause 5.2 + Annex A.2.2). Two to four pages. Approved by top management. Sets the organisational stance on responsible AI. Aligned with the India AI Governance Guidelines seven sutras.
- Roles and Responsibilities (Clause 5.3 + Annex A.3.2 and A.3.3). A one-page RACI covering AI accountability, ethics, escalation of concerns.
- AI System Inventory. Every AI system in scope, with its lifecycle stage, its business purpose, its data sources and its risk tier. This becomes the master list from which every downstream artefact hangs.
- AI Risk Assessment Methodology (Clause 6.1.2, guided by ISO/IEC 23894:2023). Six to eight pages describing how you identify, analyse, evaluate, treat and monitor AI risk. This is the document your auditor tests most rigorously.
- AI Impact Assessment (Annex A.5.2, guided by ISO/IEC 42005:2025). One AIIA per AI system in scope. Covers fairness, safety, transparency, privacy, security, human oversight, environmental impact.
- AI Risk Register + Risk Treatment Plan (Clauses 6.1.3, 8.3). One consolidated risk register covering every AI system in scope, plus a treatment plan mapping each risk to Annex A controls or other treatment.
- Statement of Applicability (SoA) (Clause 6.1.3 output). All 38 Annex A controls listed, with Include or Exclude decision and clause-anchored justification. This is the single most-audited document in the AIMS.
- Internal Audit Programme (Clause 9.2). Three-year rolling programme covering all clauses and applicable Annex A controls.
- Management Review pack + minutes (Clause 9.3). Evidence of one full management review with mandatory agenda items and outputs. Auditors will not accept a certification without at least one completed cycle.
By the end of the build phase, you should have all ten documents populated with real content grounded in your organisation. Not templates. Not placeholders. Real content that describes the actual AI systems your organisation runs.
The timeline splits roughly like this. Months 1 to 2: scope, policy, roles, inventory. Months 3 to 6: risk methodology, first pass of AIIAs, risk register, initial SoA. Months 7 to 9: implement controls on the "Include" side of the SoA, gather evidence. Months 10 to 12: run at least one internal audit cycle, at least one management review, close nonconformities, run gap analysis against the standard. A team of two or three dedicated people plus wider organisational support can carry this through in nine to twelve months. If you are also implementing a full ISO 27001 for the first time in parallel, add three to six months.
Certification phase, months 13 to 16
Once the AIMS is built and has run for at least one internal audit and one management review cycle, you engage a certification body. Module 7 walks CB selection and audit preparation in detail. The certification audit itself has two stages.
Stage 1 — Documentation Review. Usually one to three audit days. The auditor reads your scope statement, your policy, your risk methodology, your AIIA outputs, your SoA. They ask questions to confirm that the AIMS is real and not paper. They identify areas of concern that they will test at Stage 2. Common Stage 1 findings I have seen: scope statement too broad, AI policy indistinguishable from a general IT policy, risk methodology does not distinguish AI-specific risk from ordinary IT risk, no evidence of at least one AIIA cycle, SoA justifications that copy standard text back to the auditor. If Stage 1 finds a major concern, you get a remediation window (usually 60 to 90 days) before Stage 2. If Stage 1 is clean, Stage 2 usually follows within 30 to 60 days.
Stage 2 — Operating Effectiveness. Usually three to eight audit days depending on the organisation size and AIMS scope. The auditor tests whether the AIMS actually operates as documented. They sample AI systems. They interview owners. They test the evidence for controls on the "Include" side of your SoA. They read management review minutes. They read internal audit reports. They observe the operating cadence. Common Stage 2 findings: internal audit programme paper-only, management review missed a mandatory agenda item, no evidence that AIIA was actually revisited when an AI system was updated, evidence for A.6 lifecycle controls missing for one or more sampled systems.
Nonconformities are classified as major or minor. A major means the process is not functioning, and it must be closed through CAPA (Corrective Action Preventive Action) before the certificate can issue. A minor is a gap that does not defeat the process, and it can be closed with a plan of action inside the certification cycle. Certificates issue when all majors are closed.
Sustain phase, three-year cycle
The certificate is valid for three years, but it is not static. You run:
- Surveillance audit at end of Year 1 — typically 30 to 60 percent of the initial audit scope. The CB samples a subset of clauses and Annex A controls. Focus is continual operation and closure of prior findings.
- Surveillance audit at end of Year 2 — similar to Year 1, with different sampling to progressively cover the whole system across the three-year cycle.
- Recertification audit at end of Year 3 — full-scope audit similar to the initial Stage 2. This is when the certificate renews for another three years.
Between these events, the AIMS runs continuously. You conduct AIIAs whenever an AI system is added or materially changed. You update the risk register periodically. You conduct internal audits per your programme. You run management reviews annually. You handle nonconformities through CAPA. The certificate is not the end of the work — it is the beginning of the working cadence that keeps the certificate alive.
Approximate cost for an Indian organisation
For a mid-size Indian SaaS or IT services company with an AIMS covering a defined set of AI systems, the direct out-of-pocket cost typically splits across three categories. Certification body audit fees range from USD 15,000 to USD 30,000 for the initial Stage 1 + Stage 2 combined (accredited CBs charge USD 2,500 to USD 4,500 per audit day). Surveillance audits cost around 30 to 60 percent of that in each of Years 1 and 2, and full recertification cost in Year 3. Internal build cost — consultants if you use them, and the fully-loaded cost of your internal team — will typically run several times the CB fee. Vendor pricing for the standards themselves is a small line item (ISO 42001 + 23894 + 42005 + 22989 = about CHF 500 for the paper you must own).
Compare this to the market price for a personal PECB Lead Implementer training course sold in India today — Mindset Cyber sells it self-paced at Rs 56,999 and the classroom-led options through NovelVista and The Knowledge Academy run Rs 30,000 to Rs 40,000. Those are personal-certification schemes for individuals; they do not certify the organisation. This course, at Rs 9,999 founding, teaches you to build and run the organisational AIMS that leads to actual certification. Not the same thing at all.
Next lesson, I want to close Module 1 by placing the India AI Governance Guidelines against the ISO 42001 clause structure, so you can see exactly where the seven sutras and six pillars map on top of the standard. That will bridge us into Module 2 where we start reading the clauses in detail.