Services / ISO 42001 certification
ISO 42001 certification for your AI management system
Certification for organizations, not individuals: we audit how your company governs the AI systems it develops, provides or uses, from $800.
From $800Certified by EUROTECH

- Accredited by IAB and INTAQS
- Issuing certificates since 2004
- Online or on-site audits worldwide
- Verify any EUROTECH certificate
What ISO 42001 certification covers
ISO/IEC 42001:2023 is the first international standard for an artificial intelligence management system, often shortened to AIMS. Published in December 2023, it applies to any organization that develops, provides or uses AI products and services, whatever its size or sector.
Like other ISO management system standards, it asks for context, leadership, planning, support, operation, performance evaluation and improvement. What makes it different is the AI-specific content: an AI policy, defined roles and responsibilities for AI, AI risk assessment and treatment, AI system impact assessment, and controls over the AI system life cycle, data, third parties and the information you give to users.
An annex of the standard lists reference controls, and, as in ISO 27001, you decide which apply and justify your choice in a Statement of Applicability. The auditor checks that choice against how your AI systems are actually built, deployed and monitored.
Please note: many search results for ISO 42001 are courses for individuals, such as lead auditor training. This page is about certifying your organization's management system. For training, see MEGADEMI.
- Stage 1 review of AI policy, scope, risk and impact assessment methods and Statement of Applicability
- Stage 2 audit of AI system life cycle controls and evidence
- Certification decision and three-year certificate
- Listing on our verification portal
- Yearly surveillance audits and recertification
Developer, provider or user: the options for your scope
The scope depends on your role. An AI developer will be audited on design, data management, model development, testing and validation. A provider that offers AI-based services to customers will be audited on deployment, monitoring, incident handling and customer information. An organization that mainly uses AI from others will be audited on how it selects, approves, monitors and controls those systems and their suppliers.
Many organizations are more than one of these. A software company might build its own models, embed third-party models and use AI tools internally. The scope statement on your certificate should say which AI systems and roles it covers, in words your customers can understand.
If you already hold ISO/IEC 27001, the two standards fit together closely. Risk management, supplier control, incident management and document control can be shared, and an integrated audit saves time. Data protection and security controls from your ISMS often serve as evidence for AI data controls as well.
What the price depends on
ISO 42001 certification with EUROTECH starts at $800. Audit time grows with the number and risk of the AI systems in scope.
- Number of AI systems in scope and how critical they are
- Your role: developer, provider, user or a combination
- People involved in AI development, deployment and oversight
- Sites and teams, including remote teams
- Integration with ISO 27001 or other management systems
The written quote lists audit days and all fees. A clear inventory of AI systems with their owners and risk ratings is the single most useful document for keeping audit time under control.
Third-party AI components also count. If you rely on external models or AI services, the auditor checks how you assessed them, what contractual commitments you have, and how you monitor their behaviour and changes.
How ISO 42001 certification works with us

Step 1
Scope and AI inventory
We agree your role and the AI systems in scope, and quote the ISO 42001 audit in writing.

Step 2
Stage 1 review
We check your AI policy, risk and impact assessment methods and Statement of Applicability.

Step 3
Stage 2 audit
The auditor follows selected AI systems through their life cycle with live evidence.

Step 4
Certificate and surveillance
After the decision you receive the ISO 42001 certificate, with yearly surveillance audits.
AI regulation and customer expectations by region
We certify ISO 42001 for organizations in the USA, Europe, Asia and Africa. The regulatory context is moving quickly. In the European Union, the AI Act sets obligations based on the risk class of AI systems. In the USA, the NIST AI Risk Management Framework is widely used as voluntary guidance, alongside sector and state rules. Other countries are introducing their own frameworks.
ISO 42001 asks you to identify the legal and contractual requirements that apply to your AI systems and to meet them. Certification does not equal compliance with the EU AI Act or any other law, but a working AI management system gives you the structure to show how you manage those obligations.
Customers increasingly ask suppliers how they govern AI: which models are used, how data is handled, how outputs are checked. An ISO 42001 certificate, checkable online, answers the governance part of those questions.
What to expect during the audit
Expect the auditor to pick one or two AI systems from your inventory and follow them through the life cycle: why the system was approved, what data it uses and where that data came from, how it was tested before release, how its impact on people was assessed, how it is monitored in use and who can stop or change it.
Human oversight and transparency are common topics. The auditor will look at how users are told they are interacting with AI where relevant, how outputs are reviewed for higher-risk uses, and how complaints or incidents involving AI are recorded and handled.
Data is a frequent focus. Expect questions on how training and input data are sourced, whether its use is permitted, how quality and bias are checked, and how personal data is protected. Records of these checks are stronger evidence than a policy that says they should happen.
Findings are graded as major or minor, and the certification decision is based on the evidence. You receive a written report explaining each finding.
Keeping the certificate as your AI changes
AI systems change more often than most processes: models are retrained, new tools are adopted and new uses appear. Keep the AI system inventory current, run impact and risk assessments when systems change significantly, and record decisions to deploy or retire systems.
Surveillance audits will look at new AI systems added since the last audit, incidents and how they were handled, monitoring results and progress on objectives. Tell us about large changes in scope, such as launching a new AI product, so the audit plan covers it.
Training for staff on AI risks and responsible use supports the competence requirements of the standard. Training is available through MEGADEMI at megademi.com.
Keep impact assessments proportionate. A low-risk internal tool needs a short assessment; a system that affects decisions about people needs a deeper one, with clear human oversight. The auditor looks for that proportionality.
Questions buyers ask
How much does ISO 42001 certification cost?
With EUROTECH it starts at $800. The number and risk of AI systems, your role, people and integration with ISO 27001 set the final price.
Is ISO 42001 certification for people or companies?
This service certifies an organization's AI management system. Courses for individuals, such as lead auditor training, are a different thing.
Does ISO 42001 make us compliant with the EU AI Act?
Certification alone does not make you compliant. ISO 42001 gives you a management system to identify and meet your obligations, including those under the AI Act.
We only use AI tools from other companies. Can we certify?
Yes. The standard applies to organizations that use AI as well as those that develop or provide it. The audit then focuses on selection, approval, monitoring and supplier control.
Can ISO 42001 be combined with ISO 27001?
Yes. They share structure and many processes, and an integrated audit usually saves time.
When was ISO 42001 published?
ISO/IEC 42001 was published in December 2023.
Related services
- ISO 27001 certification
From $800
- ISO 37301 certification
From $800
- ISO 31000 assessment
From $800
Get a quote for ISO 42001 certification
Tell us your company, sites and the standard you need. We reply with a written quote and the audit plan.
Prefer to talk? Call +1 307 205 1833
Monday to Friday, 09:00 to 18:00 (US Mountain Time)
