If you are deciding how to get to an ISO 42001 certificate, here is the short version. Doing it in-house works when someone on your team has already run a certified management system and has a real share of their week to give this one. A scoped consulting engagement (a gap assessment, a readiness review, an internal audit) is the right buy for most companies, because it puts outside judgment where judgment is actually needed and leaves the routine work with you. A fractional or retained arrangement earns its cost when you have no management-system experience at all and a date you cannot miss.
What you are buying in each case
Start with what the standard asks for, because the three approaches differ mostly in who supplies it. ISO/IEC 42001:2023 is an Annex SL management-system standard, so clauses 4 to 10 mirror ISO 9001 and ISO 27001, and the AI-specific content sits in Annex A, nine control areas running from AI policy and roles through impact assessment, the AI system life cycle, data, and third-party relationships.
Two pieces of judgment carry most of the weight at audit: which of those controls apply to your AI systems and why (the Statement of Applicability), and how you assess the effect of an AI system on individuals and society (the impact assessment under clauses 6.1.4 and 8.4). Everything else is mechanics a competent quality or security person can do: procedures, records, internal audits, management review. So the real question behind "DIY, consultant, or fractional" is where the judgment will come from, and how much of the mechanics you want to pay someone else to do.
| In-house with a toolkit or platform | Consultant, scoped engagement | Fractional or retained | |
|---|---|---|---|
| Who does the work | Your team | Consultant does the scoped pieces, your team does the rest | Your team, with the consultant directing |
| Typical outside cost | Toolkit a few hundred to a few thousand dollars; platform roughly low five figures a year | $1,500 to $2,500 for a small two-day gap assessment; $5,000 to $20,000 for a larger readiness review | Retainer by the month; total usually between a readiness review and the low end of a first-year budget |
| Time to certificate | Long end of 4 to 12 months, often longer without a prior certified system | 4 to 12 months | 6 to 12 months |
| Where it breaks | Documents without judgment; evidence without applicability decisions | Handover, and owning what you did not write | Dependency; the retainer becomes your AI governance function |
Doing it in-house with a toolkit or compliance platform
Two different products get lumped together as "DIY", and they break in different places.
What a toolkit gives you, and what it cannot
A toolkit is a document pack: a policy, a set of procedures, a risk register template, an SoA spreadsheet, sometimes an internal audit checklist. It costs a few hundred to a few thousand dollars, and for a team that already runs ISO 9001 or ISO 27001 it can save several weeks of drafting.
What it cannot do is tell you what is true about your organisation. The templates are written for everyone, so they include AI system categories you do not use and committees you do not have, and an auditor will find the gap between the paper and the practice within the first hour. In my experience the failure looks much the same everywhere: the documents are complete, the AI risk assessment is a table of generic risks lifted from the template, and nobody can explain why the life-cycle controls were marked applicable for a chatbot a vendor hosts and the company never developed. The toolkit produced documents. The judgment, which is the part being audited, never got produced.
What a platform gives you, and what it cannot
Compliance platforms grew up around SOC 2 and ISO 27001, and most now sell a 42001 module. What they do well is evidence: they connect to your cloud accounts and your HR and ticketing tools, pull evidence on a schedule, and map it to controls on a dashboard of green and red. For the clauses that overlap with 27001 that is real work saved, and if you already run one of these platforms, adding the 42001 module is the cheapest possible starting point.
Where a platform breaks is at the decision it cannot make. It cannot decide which Annex A controls apply to a given AI system, because that depends on whether you develop, deploy or merely use the system, on who is affected by its output, and on what your interested parties expect. It cannot write an impact assessment, because that is a reasoned judgment about people rather than a log export. And it cannot tell an auditor why a control was excluded; it can only show that someone ticked a box. Evidence is the last step. Applicability, scope and impact come first, and a person still does those. Our article on the Statement of Applicability walks through them control by control.
When in-house is the right call
Three conditions, and you want all three:
- You hold a current ISO 9001, 27001 or similar certificate, and the same people will run this system.
- Someone with that experience has roughly a quarter to a third of their week available for six months, scheduled rather than promised.
- Your AI use is narrow: a handful of tools, mostly vendor-hosted, none making consequential decisions about people without human review.
If you meet all three, buy the toolkit or the platform module and spend a small amount of outside money at the two judgment points rather than on the whole project. If you miss any one of them, the in-house route usually costs more than a consultant would have, paid in months instead of dollars.
Hiring a consultant for a scoped engagement
A scoped engagement means you buy defined pieces of work at a defined price, and your team does everything in between. The pieces bought most often, in the order a project usually needs them:
- Gap assessment. A structured review of where you stand against clauses 4 to 10 and Annex A, with a prioritised list of what to close. In 2026 a two-day version for a small organisation using one or two AI tools runs about $1,500 to $2,500, and a scoped readiness review for a larger organisation runs $5,000 to $20,000. Ours is a fixed fee, the ISO 42001 gap assessment at $9,750, priced that way so you know the number before the first call.
- SoA workshop and first impact assessment. A day or two working through each Annex A control against your actual AI systems, then running the first impact assessment with your team so the method is sound and the team can repeat it without help.
- Internal audit. Clause 9.2 requires one before certification. For a first cycle an outside auditor is cheaper than training an internal one and more likely to find what the certification body will find.
- Pre-audit readiness review. A short check a few weeks before Stage 1.
For regulated manufacturers there is a narrower buy that often comes first: a review of the AI-generated records, specifications and procedures already sitting inside the quality system. In April 2026 FDA issued a warning letter to Purolea citing "inappropriate use of artificial intelligence" under 21 CFR 211.22(c), for AI-written specifications, procedures and master records released without qualified review, the first time AI-generated quality records drew an FDA citation. Our AI-in-the-quality-system review is a $5,000 fixed fee for exactly that question, and a GMP site will usually want it answered whether or not it goes on to certification.
Where the scoped engagement breaks
Two places. The first is handover. If the consultant writes the procedures, trains your people and leaves, you have inherited a set of documents in place of a working system, and it shows at the surveillance audit a year later, where the auditor tests whether your people can explain the system without the consultant in the room. The fix is to keep the writing in-house and buy judgment, review and audit from outside.
The second is scope creep in both directions: a gap assessment that quietly becomes a full implementation at hourly rates, or a fixed fee whose scope was never written down. Read what is in and out before signing; our guide to choosing an ISO 42001 consultant has the questions to ask.
A fractional or retained arrangement
A fractional arrangement retains a consultant part-time for the length of the project, commonly a fixed number of days a month on a monthly fee, and sometimes continuing after certification as the standing AI governance lead. The consultant chairs the working group, coaches whoever is drafting, runs the first management review, and sits in on the audit. Your team still writes the system.
Pricing is by time, so the total depends on months and days rather than deliverables. In our experience a retained arrangement over a nine-to-twelve-month implementation lands somewhere between the cost of a scoped readiness review and the low end of the $85,000 to $150,000 first-year figure for a 50-to-200-person company. The line-by-line breakdown behind that figure is in our full budget guide.
It is the only one of the three that supplies judgment continuously instead of at two or three points, so it fits a company that has never run a management system, has a customer date it cannot miss, or has an AI portfolio complicated enough that applicability questions come up every week.
Where the retained arrangement breaks
Dependency. The arrangement builds internal capability when the consultant coaches and the team writes. It fails when the team is busy and the consultant, who is paid for the days anyway, starts writing; six months later the consultant is your AI governance function, the surveillance audit exposes it, and the retainer cannot end. Name the internal owner in the contract, and put a planned taper in the schedule (fewer days per month after Stage 2) so the end is agreed before the start.
The softer failure is drift. A monthly fee has no natural finish, so tie the retainer to milestones (gap closed, SoA signed, internal audit complete, Stage 1, Stage 2) and review the arrangement at each one.
What the calendar does to the choice
The timeline from gap assessment to certificate is typically four to twelve months, and organisations with a working ISO 27001 or ISO 9001 system are usually at the short end. The certification body runs a separate clock: bodies are reporting auditor backlogs, and some Stage 2 audits have waited six months or more. A company that picks the in-house route to save money and then waits half a year for an audit slot has saved nothing if a customer contract turned on the date. Our realistic timeline article lays out both clocks.
So book the certification body early, in parallel with the gap assessment, whichever approach you take. And with a hard date under twelve months away and no existing certified system, the in-house route is not really open; you are choosing between a scoped engagement backed by a lot of your own hours and a retained arrangement.
Regulatory dates deserve a careful word, because sellers of all three approaches trade on urgency. EN ISO/IEC 42001:2026 was adopted as a European standard on 18 March 2026, but no harmonised standard for the EU AI Act has been cited in the Official Journal, so a 42001 certificate does not give a presumption of conformity with the Act; the standard being written for that job is prEN 18286, targeted for late 2026, and under the 2026 revisions the Act's high-risk obligations now fall in December 2027 and August 2028. In the US, Texas's TRAIGA took effect on 1 January 2026 and Colorado's narrower replacement law (SB 26-189) takes effect 1 January 2027, and neither requires a 42001 certificate. If a vendor's deadline slide is doing most of the selling, ask which law it refers to and read that law. We cover the EU side for US companies in ISO 42001 vs the EU AI Act.
A decision guide by company size and existing certifications
Under 50 people, no existing certificate. Fewer than 100 organisations held a 42001 certificate in January 2026 and roughly 350 did by spring, so at this size the first question is whether you need the certificate at all, or whether a documented AI policy and a real impact assessment would satisfy the customer asking. If you do need it, a small gap assessment at the $1,500 to $2,500 end, then in-house work with a toolkit and a scoped internal audit at the finish, is the cheapest credible route. Budget more of your own time than you think.
Under 50 people, with ISO 27001 or 9001. In-house, reusing your existing procedures for nearly everything in clauses 4 to 10, and a platform module if you already run one. Spend outside money only on an SoA workshop and the first impact assessment. This is the group that reaches the short end of the timeline.
50 to 200 people, no existing certificate. This is the group the $85,000-to-$150,000 first-year figure describes. A scoped engagement front-loaded on the gap assessment and SoA, with your own quality or security lead running the middle, is the default. Go fractional if that lead does not exist yet, or if the AI portfolio includes systems you develop rather than buy.
50 to 200 people, with ISO 27001 or 9001. A scoped engagement, and a smaller one. The gap assessment will find that most of clauses 4 to 10 are already met and the real work is Annex A. Our page on what 42001 adds to an ISO 9001 system covers what to expect.
Over 200 people or multiple sites. The readiness review sits at the $5,000 to $20,000 end, and a retained arrangement is more often justified because applicability questions arrive continuously from different business units. Scope narrowly under clause 4.3: certify the highest-exposure AI systems first and extend at the next cycle.
GMP manufacturers of any size. Start with the AI records review, whichever route you pick afterward. An FDA investigator who reads a specification and asks who wrote it and who reviewed it is asking a 211.22(c) question, and a 42001 certificate does not answer it on its own. The GMP manufacturers page walks through how 42001 plugs into a quality system you already run.
Where to start
Every route begins with the same step, which is finding out where you stand. A gap assessment is cheap relative to everything after it, it tells you which of the three routes you can afford in time as well as money, and it produces the list everyone downstream will work from. If you want a fixed number for that step, ours is $9,750 for the gap assessment. If a two-day review is more your size, the $1,500 to $2,500 market rate is fair, and our implementation guide describes what a good one should hand back. Either way, get the assessment before you buy the toolkit, the platform, or the retainer, because it is the one purchase that tells you whether you need the others.
Frequently Asked Questions
Can we implement ISO 42001 ourselves with a toolkit or compliance platform?
Yes, if someone on your team has run a certified management system before and has real time set aside for this one. A toolkit supplies documents and a platform collects evidence, but neither decides which Annex A controls apply to your AI systems or how to assess AI impact, and that judgment is what the auditor tests.
How much does an ISO 42001 consultant cost?
In 2026 a two-day gap assessment for a small organisation runs about $1,500 to $2,500, a scoped readiness review for a larger one $5,000 to $20,000, and a full first year for a 50-to-200-person company is commonly quoted at $85,000 to $150,000 including internal time, tooling and the certification body. Fixed-fee options exist; ours is a $9,750 gap assessment.
What is a fractional ISO 42001 consultant?
A consultant retained part-time for the length of the implementation, usually on a monthly fee for a set number of days, who acts as your AI governance lead while your own team writes and runs the system. It suits companies with no prior management-system experience that cannot justify a full-time hire.
Can we start ISO 42001 in-house and bring in a consultant later?
Yes, and it is common. The cleanest handoff point is right after a gap assessment and before procedures are written; switching in the middle of documentation means the consultant spends paid time reconciling what is already there.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.