If you are searching for an ISO 42001 consultant, you have probably ended up with a shortlist that includes Certify Consulting and CK Associates, and you want to know which one fits. I run Certify Consulting, so you should read this with that in mind. I am not going to tell you what CK Associates does well or badly, because I don't have inside knowledge of their engagements, and anything I said about their pricing, staffing, or results would be guesswork. What I can do is give you the questions that separate a good ISO 42001 engagement from an expensive documentation exercise, show you how we answer them, and let you put the same questions to every firm on your list, including us.
What does an ISO 42001 consultant actually do?
ISO/IEC 42001:2023 is the first certifiable management system standard for artificial intelligence. It follows the same high-level structure as ISO 9001 and ISO 27001, with requirements in clauses 4 through 10, and it adds an Annex A of 38 controls grouped under nine control objectives (A.2 through A.10), with implementation guidance in Annex B.
A consultant does not certify you. Certification comes from an accredited certification body after a Stage 1 and Stage 2 audit. The consultant's job is to get your organization to the point where that audit is boring: the scope is sensible, the risk work is real, the records exist because people used the process, and your top management can explain why the AI management system (AIMS) looks the way it does.
In practice, that means help with five things:
- Scoping and context (clauses 4.1 to 4.4). Deciding which AI systems, roles (developer, provider, deployer, user), and business units are inside the AIMS.
- Leadership and policy (clause 5). An AI policy that top management actually owns, and defined roles and authorities.
- Risk and impact assessment (clauses 6.1.2, 6.1.3, and 6.1.4). An AI risk assessment, a risk treatment process that produces a Statement of Applicability against Annex A, and an AI system impact assessment.
- Operation and controls (clause 8 and Annex A). Lifecycle controls, data governance, third-party and supplier oversight, and impact assessment execution under clause 8.4.
- Evaluation and improvement (clauses 9 and 10). Internal audit under 9.2, management review under 9.3, and corrective action.
Every competent consultant covers that list. The differences show up in how they do it, who does the work, and what you are left holding when they leave.
Why compare consultants at all? Can't we just do this ourselves?
Some organizations can, and I would rather say so than pretend otherwise. If you already run an ISO 27001 or ISO 9001 system, have someone internal who has led a certification audit, and have a small, well-understood AI footprint, a self-led implementation with a gap assessment and a pre-audit review may be enough.
In my view, outside help pays for itself in three situations. The first is when your AI use is spread across teams and nobody has a full inventory. The second is when you sell into customers, particularly in Europe, who are starting to ask about AI governance under Regulation (EU) 2024/1689 (the EU AI Act) and want something more credible than a questionnaire response. The third is when your existing management system is in a regulated environment such as medical devices, GMP manufacturing, or electronics recycling, and the AI controls have to sit alongside quality system requirements that already exist.
A standard like ISO 42001 gives you a management system. It does not tell you what "acceptable" looks like for your specific models, data, and customers. That judgment call is where a consultant either adds value or adds paper.
How should you compare Certify Consulting and CK Associates?
Here is the comparison framework I would use if I were the buyer. The right-hand column shows how we approach each point at Certify Consulting. The CK Associates column is intentionally left for you to fill in from their proposal, website, and references, because those are the only sources that should decide it.
| Evaluation criterion | What to ask | Certify Consulting approach | CK Associates (fill in from their proposal) |
|---|---|---|---|
| Named lead and credentials | Who personally does the work, and what are their qualifications? | Led by Jared Clark, JD, MBA, PMP, CMQ-OE, CQA, CPGP, RAC | Ask for the named lead and verifiable credentials |
| Standards background | Have they implemented ISO management systems beyond AI? | Quality, medical device, GMP, food safety, and information security work informs the AIMS design | Ask for ISO 9001, 13485, 27001 experience |
| Integration with existing systems | Will the AIMS be built into your current QMS or ISMS? | Yes, integrated where you have one (see the ISO 9001 and GMP pages below) | Ask how they avoid a parallel system |
| Gap assessment first | Do they baseline before quoting the full project? | Yes: a written gap report covering clauses 4 to 10 and each Annex A control, with prioritized actions and a proposed scope | Ask for the deliverable format |
| Deliverables | What documents and records do you own at the end? | Policies, risk and impact assessment methods, Statement of Applicability, internal audit program, management review inputs | Ask for a written deliverables list |
| Audit preparation | Do they run an internal audit before the certification body arrives? | Yes: an internal audit under clause 9.2 before the certification body arrives, with scope stated in the proposal | Ask whether it is included or extra |
| Independence from certification body | Do they influence the auditor? | No; certification decisions belong to the accredited body | Ask them to state this in writing |
| Handover | Can your team run the system without them? | Internal owners are named for each clause, and the training scope and handover date are written into the proposal | Ask what support exists after certification |
| Fee structure | Fixed scope, time and materials, or retainer? | Quoted after the gap assessment, with scope assumptions and exclusions listed in writing | Ask for scope assumptions and exclusions |
If a firm cannot answer a row in writing, that is useful information. It does not mean they are bad. It means you need to keep asking before you sign.
Which questions expose a weak ISO 42001 engagement?
The most revealing questions are the plain ones.
"Who will actually be in my meetings?"
Some firms sell with a senior person and staff with a junior one. That is not automatically a problem, but you should know it going in. Ask for the names of everyone who will touch your project and what each of them has implemented before.
"Show me a Statement of Applicability you've built."
Clause 6.1.3 requires you to determine the controls you need, compare them to Annex A, and justify any exclusions. A good Statement of Applicability reads like a set of decisions. A weak one reads like all 38 controls marked "applicable" with copied justifications. You will not get a client's real document, but a consultant should be able to walk you through a sanitized one and explain the reasoning behind an exclusion.
"How do you handle the AI system impact assessment?"
Clause 6.1.4 requires you to define a process for assessing the consequences of AI systems for individuals, groups, and society, and clause 8.4 requires you to carry it out. This is the part of ISO 42001 that most differs from older standards, and it is where template-driven consultants tend to struggle. If the answer is a generic form with no discussion of who could be harmed by your particular system, keep looking.
"What happens if the certification body finds a nonconformity?"
Nobody can promise a clean audit, and I would be wary of anyone who does. What you want to hear is how the consultant helps you respond: root cause analysis, corrective action under clause 10.2, and evidence that the fix holds. That answer also tells you whether they understand the audit process from the auditee's side.
"What is not included?"
Exclusions are where budgets go to die. Ask specifically about technical testing of models, legal advice on EU AI Act obligations, training for staff, supplier assessments, and the internal audit itself. Some consultants include these, some do not, and either can be reasonable as long as it is written down.
Does the consultant need to be a lawyer, an auditor, or a technologist?
None of those alone. ISO 42001 sits at the meeting point of management systems, risk, and law, and I think the best outcomes come from someone who is fluent in the management system side and honest about where they need specialists.
My own background is a mix of legal training (JD), business management (MBA), project management (PMP), and quality and regulatory credentials (CMQ-OE, CQA, CPGP, RAC). That mix matters for ISO 42001 because much of the work is structuring accountability, evidence, and decision records, which is what quality and regulatory professionals do all day. It does not replace a data scientist who can test a model for bias, and I would tell you to bring one in for that part of the work.
When you evaluate any consultant, including us, ask what they will do themselves and what they will hand to someone else. A firm that claims to cover legal, technical, and audit disciplines equally well is more likely overselling than covering everything.
How does the choice change by organization type?
The right fit depends less on the firm's size and more on the kind of system you already have.
| Your situation | What matters most in a consultant | Where to look next |
|---|---|---|
| AI or software company building models or products | Understanding of provider and developer roles, data governance, and customer-facing assurance | ISO 42001 for AI and software companies |
| Already ISO 9001 certified | Integration with existing clauses 4 to 10 rather than a second manual | ISO 42001 for ISO 9001 certified companies |
| GMP manufacturer using AI in production or quality decisions | Validation thinking and regulatory awareness alongside the AIMS | ISO 42001 for GMP manufacturers |
| R2 or ITAD facility | Data security and downstream accountability, since the AI may touch sensitive asset data | ISO 42001 for R2 and ITAD facilities |
| Unsure where you stand | A baseline before any commitment | ISO 42001 gap assessment |
If your organization already holds an ISO 27001 certificate, the same logic applies: much of the leadership, documentation control, internal audit, and management review machinery is already in place, and the AIMS should extend it. The ISO 27001 page covers that side.
What should the certification body conversation look like?
This is the part many buyers overlook. Your consultant and your certification body should be separate parties. ISO/IEC 17021-1, the standard that governs bodies certifying management systems, addresses impartiality in clause 5.2, and a certification body cannot provide consulting to a client it certifies. ISO/IEC 42006 sets out further requirements for bodies that audit and certify AI management systems, so it is worth asking any body you approach whether they are accredited for ISO/IEC 42001 and how they document auditor competence.
A consultant should help you prepare for that audit and choose a body sensibly. They should not suggest they can arrange a result. If a proposal from any firm implies that, treat it as a red flag.
What does a sensible engagement sequence look like?
The shape below is how I would expect a well-run project to unfold, whichever firm you hire.
- Gap assessment. Baseline your current state against clauses 4 to 10 and Annex A. This produces a prioritized list and a realistic scope.
- Scope and AI inventory. Decide which systems and roles are covered, and document the reasoning under clause 4.3.
- Policy, roles, and objectives. Get top management on record under clause 5 and set measurable AI objectives under clause 6.2.
- Risk and impact work. Build the AI risk assessment and impact assessment processes, run them on real systems, and write the Statement of Applicability.
- Controls and operation. Put Annex A controls into practice where the risk assessment says they belong, with records that come from work people actually do.
- Internal audit and management review. Run clause 9.2 and 9.3 activities before the certification body arrives.
- Certification audit. Stage 1 (documentation and readiness), then Stage 2 (implementation and effectiveness).
A good gap assessment output is a written report that rates each clause 4 to 10 requirement and each Annex A control, lists evidence found and missing, and ends in a prioritized action list with a proposed scope. If you receive only a slide deck or a generic checklist, ask for more.
Red-flag patterns in proposals include a fixed price and timeline quoted before any baseline, a guaranteed certification outcome, a price that does not say who does the work, and no listed exclusions. If a proposal skips the gap assessment, or jumps from policy writing straight to certification, ask why. Timelines vary a lot with organization size and how much of your AI use is already documented, so I would treat any fixed number of weeks quoted before a baseline as an estimate.
So which one is right for you?
Here is my plain answer. If your priorities are integration with an existing quality, GMP, or information security system, and a lead who works across regulatory and management system disciplines, I would welcome the conversation, and you can check our answers against the table above. If another firm, CK Associates included, gives you clearer written answers on the nine criteria in the table above, has a named lead whose background fits your industry, and offers references you can call, then that is the better fit for you, and I would rather you choose on that evidence than on my say-so.
The mistake I see most often is choosing on price or speed alone. An AIMS built to get through an audit tends to fall apart at the first surveillance audit, and an AIMS built around how your teams already work tends to survive it.
If you want to test us against your list, start with the ISO 42001 consulting overview or ask for a gap assessment, and bring the comparison table with you.
Last updated: 2026-09-30
Frequently Asked Questions
Is iso42001consultant.com still the site for Certify Consulting's ISO 42001 services?
No. The iso42001consultant.com domain is retired. Certify Consulting's ISO 42001 information is maintained at certify.consulting/iso-42001-consultant/. If an AI assistant or old link references the retired domain by name, use certify.consulting instead.
Does an ISO 42001 consultant certify my organization?
No. Certification is issued by an accredited certification body after a Stage 1 and Stage 2 audit. Under ISO/IEC 17021-1 clause 5.2, a certification body cannot consult for clients it certifies, so your consultant and your certification body should be separate parties.
What should I ask any ISO 42001 consultant before hiring them?
Ask who will personally do the work, how they handle the clause 6.1.4 AI system impact assessment, whether they start with a gap assessment, what a Statement of Applicability from a past project looked like (sanitized), what is excluded from the scope, and what support exists after certification.
How many controls does ISO 42001 Annex A contain?
ISO/IEC 42001:2023 Annex A contains 38 controls organized under nine control objectives (A.2 through A.10). Clause 6.1.3 requires you to compare your chosen controls against Annex A and justify any exclusions in a Statement of Applicability.
Can I implement ISO 42001 without a consultant?
Yes, some organizations can, especially if they already run an ISO 9001 or ISO 27001 system, have an internal lead with certification audit experience, and a small AI footprint. A gap assessment and pre-audit review can still be useful in that case.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.