ISO/IEC 42001:2023 · Artificial Intelligence
The proof that you use AI responsibly
Customers, procurement and regulators are increasingly asking how you handle artificial intelligence: which systems are running, who is responsible for them, what risks are known. ISO 42001:2023 provides a structured answer to this — and we issue the certificate without a consulting mandate doubling the price.
- AI system inventory, impact assessment and risk assessment with guided templates
- Annex A controls worked through systematically — with a reasoned decision for each control
- Fixed price from €179/month, audit and monitoring included
- Aligned with the EU AI Act: documented governance instead of individual questionnaire answers
Often bundled with ISO 27001 — information security and AI governance share half of the system requirements. We check beforehand, free of charge, whether Express works for you.
A management system for AI — not a quality seal for a model
The most common misconception: ISO 42001 checks whether an AI is good or safe. It doesn't. What is checked is whether your organization knows which AI systems it develops or uses, what risks and impacts are associated with them, who is responsible for them, and whether the measures taken are effective.
Record AI systems
An inventory of all AI systems you develop, offer or use — with purpose, role (provider, operator, user) and those responsible.
Assess impacts
An impact assessment for each system: Who is affected, what could go wrong, how serious is it? For individuals, groups and society.
Address risks
A risk assessment with reasoned decisions on which measures from Annex A you implement — and which not, and why.
Control data and lifecycle
Traceable rules for training data, development, testing, release, operation and decommissioning of AI systems.
Establish transparency
Those affected know when they are interacting with AI; decisions can be explained and challenged. Roles and responsibilities are documented.
Monitor and improve
The performance and behavior of the systems are continuously monitored. Incidents are handled, insights flow back into the system.
What companies want to know before certification
If you integrate AI systems into your services or use them for decisions about people, yes. ISO 42001 distinguishes between providers, operators and users; the requirements for a pure user are significantly lighter, but not zero.
No. The regulation is a legal requirement, the standard is a management system. But it covers a large part of the organizational obligations — risk management, documentation, human oversight, transparency — and makes the answers auditable.
We examine your system, not your code. Auditors ask how you select data, test models, monitor behavior and who decides. You need to be able to demonstrate this, not reinvent it.
Then you have already accomplished more than half. Context, leadership, risk approach, document control and internal audits are structured identically. We add the AI system inventory, the impact assessment and the Annex A measures of 42001.
Where proof determines the contract
ISO 42001 pays off where someone else wants to know how you use AI — and a questionnaire is no longer enough.
AI providers and software companies
Enterprise customers ask about governance before an AI product is allowed into procurement.
SaaS with AI features
Anyone who integrates language models or recommendation logic becomes a provider — with all the questions that come with it.
Finance and insurance
Scoring, fraud detection, underwriting: here regulators demand traceability.
Healthcare
Diagnostic support and triage are high-risk applications within the meaning of the AI Act.
HR and recruiting
Automated pre-selection of applicants is one of the regulated use cases.
Public sector clients
Authorities and public enterprises must justify their use of AI to citizens.
Industry and automation
Quality control, predictive maintenance and robotics with learning systems.
Consulting and agencies
Anyone building AI solutions for clients must show they have their own use of it under control.
Four steps — at the pace that suits you
After certification, a surveillance audit follows annually, and recertification after two years. Both are included in the price.
Register and clarify scope
You tell us how big your company is, where you work and what you do. We explain how extensive the audit will be.
1 to 2 daysOne registration meeting for all standards
Prepare
You use templates, task lists, and reminders about missing documents. You don't start with a blank page.
1 to 6 weeks, depending on paceOne shared documentation
Two-stage audit
First we review your documents and check if you're ready. Then we check whether the rules truly work in your everyday work.
1 to 4 daysOne combined audit plan, one appointment
Decision and certificate
An independent person makes the decision. Upon success, you receive your digital certificate, visible in the online register.
1 to 3 daysOne certificate document with multiple standards
Step 2 is the only step whose duration depends on the chosen pace: with Express it's skipped, because the system is already running. With Standard it takes one to three weeks, with Guided up to six.
You set the pace. We tell you which one is realistic.
We don't audit more superficially or briefly than others. Above all, we save waiting time. All three paces are audited according to the same rules.
48 hours
Express
Change of certification body or a very tight deadline
- What happens: Audit, decision and certificate
- Your system is already running, your documents are complete
- Internal audit and management review have been carried out
2–4 weeks
Standard
Most small and medium-sized enterprises
- What happens: Documents are organized and prepared with AI. The audit follows afterward.
- Your processes already work
- Documents are missing or not yet complete
2–8 weeks
Guided
Initial certification without preparation
- What happens: You build your system with an independent partner. The audit follows afterward.
- So far only a few rules, processes, or documents
- Independent consulting partners from our network
For ISO/IEC 42001, Express is less often realistic. AI system inventory, impact assessment, risk assessment, and the implementation of the selected Annex A measures must be in place and lived. This is often the case when switching from another certification body or with existing ISO 27001, but almost never when starting from scratch. Whether this applies to you, we clarify in advance in the free Express Check.
How extensive the audit will be depends on your number of employees, your locations, and the type of your work. Are you unsure which column applies to you? Write to us — we'll tell you in a brief conversation what's possible for you.
Scope of services
Included in the price — no fine print
Preparation platform with templates for all required documented information
Real-time gap analysis: you can see at any time what's missing for audit readiness
Certification audit Stage 1 and Stage 2 by our specially qualified and audited auditors
Certificate digital, multilingual, validated with entry in the public transparency register
Annual surveillance audits over the entire certificate term
Our AI auditors are specially trained in Digital Product Certification DPZ-1765
Personal point of contact — no ticketing system as the only door
Recertification after three years
Legal context
What ISO 42001 delivers in relation to the EU AI Act — and what it doesn't
We phrase this deliberately carefully, because a lot of nonsense is claimed in the market: an ISO 42001 certificate is not proof of conformity under the AI Act. An automatic presumption of conformity only arises through harmonized standards listed in the Official Journal of the EU; the corresponding European standardization is still ongoing.
Nevertheless, what ISO 42001 delivers is substantial: it forces you into exactly the structures the regulation requires — a register of systems, risk management, data governance, human oversight, transparency, logging, incident handling. Anyone who has implemented 42001 doesn't stand empty-handed before an authority or a major client, but with audited proof of organizational maturity.
- Yes — structured, externally audited proof of your AI governance
- Yes — covers a large part of the required management obligations
- Yes — strong starting position for when harmonized standards arrive
- No — does not replace conformity assessment for high-risk AI
- No — does not exempt you from your own classification of your systems
A standard is rarely the end
Anyone introducing 42001 builds half of what the ISO standards 27001 or 9001 additionally require. Combine now, instead of starting from scratch a second time in two years.
179 €/ month
- First standard €179/month, each additional standard €149 instead of €179. From four standards, an individual offer.
- From two standards onward, we run your system as an integrated management system (IMS): shared document control, one internal audit program, one management review, one combined audit program. You maintain things once instead of twice.
Prices excl. VAT
Prices you know before you start
Cancellable monthly. With annual payment, one month is free. For special requirements, we are happy to create an individual offer.
€179/month
1 standard
€1,969 per year
- One certification
- Preparation platform
- Audit stage 1 and stage 2
- Certificate and register entry
- Surveillance audits
- Support
€328/month
2 standards
€3,608 per year — second standard €149 instead of €179
- Everything from 1 standard
- Second standard
- Integrated management system
- Dedicated contact person
€477/month
3 standards
€5,247 per year — each additional standard €149
- Everything from 2 standards
- Third standard
- Dedicated project support
- Combined audit program
On request
Dedicated
- Multiple locations
- Group structures
- API integration
- Individual audit planning
Prices excl. VAT. The audit scope depends on the number of employees, locations and field of activity; for very large or multi-site organisations, we create an individual offer. The cost calculator shows what this means for your business.
Frequently asked questions about ISO 42001
€179 per month for the first standard, €149 for each additional one — platform, audit, certificate and surveillance audits included. The audit scope depends on the number of employees, locations and the number and criticality of your AI systems.
With running processes and AI support, typically 2 to 8 weeks. If your system is already in operation — for example when switching certification bodies — Express is possible in 48 hours.
No. The EU AI Act is mandatory. ISO 42001 is the recognized way to systematically implement and demonstrate its organizational requirements.
No. You must assess each measure and justify why you implement it or not. What is audited is the justification and the effectiveness of the chosen measures.
No. We audit your management system: whether you know what you use, what risks exist, who is responsible, and whether your measures are effective. The technical quality of your models remains your responsibility.
External models also belong in the AI system inventory. You assess risks and impacts from your role — as operator or user — and regulate selection, use, and monitoring.
This is the most common combination. Both standards have the same structure and share the risk-based approach. One integrated system, one combined audit, two certificates — the second standard for €149 instead of €179.
We are an independent, non-accredited certification body. No accreditation is required for ISO 42001. We ensure our quality through qualified and specially trained AI auditors, our own management system according to ISO 9001, and a public certificate register.
Yes. Your system lives on in the platform; the IMS Radar captures new AI systems, model changes, and role changes and reminds you what needs to be updated before the next surveillance audit.
The platform and AI guide you through preparation. If you need additional help, we connect you with independent consulting partners. They advise — Eucerta audits later.
Know what ISO 42001 costs you in two minutes
No call, no mandatory forms, with disclosed assumptions.
