AI Governance 13 min read

How Long Does ISO 42001 Certification Take? A Realistic Timeline

J

September 13, 2026

Most organizations get from an ISO 42001 gap assessment to a certificate in four to twelve months. A company that already runs an ISO 27001 or ISO 9001 system, uses a small number of AI tools, and has an executive who shows up for the decisions tends to land at the short end. A company that has never listed its AI systems, relies on vendor AI with nothing in the contract about it, and has not yet talked to a certification body tends to land at the long end, or past it. And there is one variable that no amount of internal effort moves: some certification bodies have had waits of six months or more for a Stage 2 audit, so the date you book matters as much as the work you do.

This article lays out the phases, a month-by-month plan for a typical mid-size company, what we have seen shorten and lengthen the timeline, and when to book the certification body so the audit date does not become the thing you are waiting on.

Why the range is so wide

ISO/IEC 42001:2023 was published in December 2023, and the market for certification is still young. Fewer than 100 organizations held a certificate in January 2026 and roughly 350 did by spring 2026, counting from public announcements because there is no official register. Certification bodies are still building auditor capacity, and that is most of where the queue comes from.

The standard itself is an Annex SL management system, so clauses 4 through 10 mirror ISO 9001 and ISO 27001: context, leadership, planning, support, operation, performance evaluation, improvement. The work that is genuinely new sits in a few AI-specific pieces: an inventory of the AI systems in scope, an AI risk assessment and an AI system impact assessment for each of them, a Statement of Applicability against the Annex A controls, and records showing the whole thing has run. How much of the shared part you already have, and how many AI systems you have to assess, decide most of the difference between four months and twelve.

The phases and how long each one takes

Here is how the work breaks down. The durations are what we see in practice, and the later phases overlap once the system is running.

Phase Typical duration What has to be true before you move on
1. Gap assessment and scoping 2 to 4 weeks You know which AI systems are in scope, what you already have, and what is missing
2. AI inventory, policy, roles and assessment method 4 to 8 weeks Every in-scope AI system is listed with an owner; the AI policy is signed; the risk and impact assessment method is written
3. Building the system 6 to 12 weeks Risk and impact assessments are done for each in-scope system; the Statement of Applicability is drafted; procedures for the AI lifecycle, suppliers, incidents and monitoring exist
4. Running it and collecting records 8 to 16 weeks (overlaps with 3) People are trained, controls are being followed, and records exist to prove it
5. Internal audit and management review 2 to 4 weeks Findings are closed or have corrective action plans; management review minutes exist
6. Stage 1 audit 1 to 2 audit days, then 2 to 8 weeks to Stage 2 The auditor has confirmed the documented system is complete and you are ready for Stage 2
7. Stage 2 audit and certificate decision 2 to 5 audit days, then 2 to 6 weeks No open major nonconformities; the certification body's technical review is complete

Add up the middle of each range, allowing for the overlap, and you get roughly eight to nine months. Overlap phases 3 and 4 aggressively, start from a management system that already exists, and you can get to four or five. Discover twenty AI tools nobody told you about in month three, and you are looking at twelve.

A month-by-month plan for a mid-size company

This is the shape of a nine-month project for a company of roughly 50 to 200 people with a handful of AI systems in scope and no prior ISO certificate. Shift everything earlier if you have one.

Month 1. Gap assessment. Define the scope: which business units, which AI systems, which sites. Start the AI inventory the same week, because the gap assessment is only as good as the list it works from. Name the person who owns the project and the executive who will sign the policy. Request quotes from two or three certification bodies; they will ask for headcount, sites and the number of AI systems, which is another reason to have the inventory started.

Month 2. Write the AI policy and get it signed. Document context, interested parties and roles. Finish the inventory. Write the method for AI risk assessment and AI system impact assessment. Choose the certification body and reserve Stage 1 and Stage 2 dates. Send a supplier questionnaire to every AI vendor on the inventory, because their answers will take longer than you expect.

Month 3. Run the risk and impact assessments on each in-scope system. Draft the Statement of Applicability. Write the operating procedures: how AI systems are approved, developed or bought, tested, monitored, changed and retired; how incidents are handled; how suppliers are managed. If you already have a document control system, use it rather than building a second one.

Month 4. Go live. Train the people who touch AI systems and the people who approve them. Start keeping the records the procedures call for: approvals, monitoring logs, change records, incident reports. Chase the vendors who have not answered.

Month 5. Operate. This is the month that feels slow and is the one auditors care most about. Fix the procedures that turn out not to match how people actually work. Log the first corrective actions; an auditor reads a closed corrective action as evidence that the system is alive.

Month 6. Internal audit against both the standard and your own procedures (our internal audit checklist covers what to look at), followed by management review. Close the findings or write corrective action plans with dates. Confirm the Stage 1 date with the certification body.

Month 7. Stage 1 audit. The auditor reviews the documented system and tells you what has to change before Stage 2.

Month 8. Close the Stage 1 findings. Stage 2 audit: interviews, records, walkthroughs of the AI lifecycle for the in-scope systems.

Month 9. Certificate decision after the certification body's technical review, assuming no open major nonconformities.

What shortens the timeline

An ISO 27001 or ISO 9001 system that already runs

This shortens the timeline more than anything else. If you hold ISO 9001 or ISO 27001, you already have document control, an internal audit program with a schedule, a management review with minutes, a corrective action process, competence records and a way of evaluating suppliers. ISO 42001 asks for the same things, and an integrated system reuses them. What you are adding is the AI inventory, the AI policy, the AI risk and impact assessments, the Statement of Applicability and the lifecycle procedures. That is a four-to-six-month project for most companies, and the Stage 1 auditor will spend far less time on the shared clauses. We wrote up exactly what 42001 adds to a 9001 system separately.

A small AI footprint

The number of AI systems in scope drives phases 2 and 3 almost linearly. Each system needs an owner, a risk assessment, an impact assessment, a place in the Statement of Applicability and lifecycle records. Two tools in one process is a few weeks of assessment work. Fifteen tools across four business units is a quarter. Scoping the first certificate narrowly, to the AI that matters most to customers or regulators, and bringing the rest in at a later surveillance audit is a legitimate path and often a faster one.

A decision-maker who shows up

Clause 5 puts top management on the hook for the AI policy, for resources, and for management review. In my experience, the executive's calendar is the single most common reason a six-month plan becomes a nine-month plan. Policy sign-off waits three weeks, management review gets moved twice, and the decision about whether a vendor's AI is in scope sits in an inbox. None of these takes more than an hour of the executive's time, and every one of them stops the project while it waits. Pick a sponsor who will attend the kickoff, sign the policy in month 2 and sit through management review in month 6, and the plan holds.

What lengthens the timeline

No AI inventory

You cannot scope what you have not listed. In our experience most companies underestimate their AI footprint, usually because the tools arrived through individual subscriptions, features switched on inside software they already used, or a vendor that added a model to a product without announcing it. Every AI system discovered after scoping re-opens the scope, the risk assessment and the Statement of Applicability. A two-week inventory sprint before or during the gap assessment, asking each department head what tools make or inform decisions, saves a month later.

Vendor AI with no contract terms

Most organizations seeking ISO 42001 are deployers of AI rather than developers of it, and the standard expects you to manage the AI you buy as well as the AI you build. That means knowing what the vendor does with your data, how you will learn about model changes, who is responsible for what when an output is wrong, and what evidence you can ask for when an auditor wants it. If none of that is in writing, getting it in writing from a large vendor can take a full quarter on its own, and the quarter runs on the vendor's clock. Send the questions in month 2. If a vendor will not answer, that is itself a finding for your risk assessment, and it is better to know in month 2 than in month 7.

Certification-body auditor backlogs

This is the one you cannot shorten by working harder. Certification bodies report backlogs for ISO 42001, and some Stage 2 audits have waited six months or more. A company that finishes its internal audit and then goes looking for an auditor can be certification-ready in month 6 and certified in month 12. The cure is in the section on booking, below.

AI-generated records inside a regulated quality system

One more for manufacturers. In April 2026 FDA issued a warning letter to Purolea citing "inappropriate use of artificial intelligence" under 21 CFR 211.22(c), for AI-written specifications, procedures and master records that had been released without qualified review. If your company has been using AI to draft quality documents, part of the 42001 work is finding those records and reviewing them, and that is a task with its own timeline. We offer a fixed-fee AI-in-the-quality-system review for exactly this, and there is more on what an FDA investigator will ask about AI on our page for GMP manufacturers.

When to book the certification body

Book early, and book before you feel ready. The steps:

  1. Request quotes in month 1, during the gap assessment. The certification body will ask for scope, headcount, number of sites and number of AI systems, and will quote audit days from that.
  2. Ask each candidate five questions. Is your ISO 42001 certification accredited, and by which accreditation body? How many ISO 42001 audits have your auditors completed? What is your current lead time for a Stage 2 audit? What is your policy if we need to move a date? Do you require a minimum period of operating records before Stage 2?
  3. Reserve Stage 1 and Stage 2 dates by month 2 or 3, roughly six months before the Stage 2 date you want. A reserved date can be moved. A place in the queue cannot be bought later.
  4. Do not let the audit date drive the internal audit. Stage 1 should follow your internal audit and management review, not precede them. If the reserved date arrives before the internal audit is done, move the date rather than skip the step. An open internal audit finding at Stage 1 is one of the most common reasons a Stage 2 gets pushed.
  5. Plan on some operating history. Certification bodies generally want to see records showing the system has run for a period, commonly around three months, before Stage 2. Ask yours for its expectation, and count back from the Stage 2 date to find the latest date the system can go live.

A note on accreditation: the certificate is only as good as the accreditation behind it. Some certification bodies offer ISO 42001 under accreditation, some are still in the process, and the difference matters to a customer or regulator who later asks. Ask, and get the answer in writing.

What the timeline costs

The timeline and the budget move together, so here is the short version. Market pricing seen in 2026 puts a two-day gap assessment for a small organization using one or two AI tools at about $1,500 to $2,500, a scoped readiness review for a larger organization at $5,000 to $20,000, and the total first-year cost for a 50-to-200-person company, including internal time, tooling and the certification body, commonly at $85,000 to $150,000. Treat all of those as ranges. Our own ISO 42001 gap assessment is a fixed fee of $9,750 and is built to give you the scope, the gap list and the plan that month 1 above calls for. The full budget breakdown is in our implementation cost guide.

Where to start

If you want a date, start with the two things that decide it: the AI inventory and the certification body's calendar. The inventory tells you how big the project is, and the calendar tells you the earliest the certificate can be issued regardless of how fast you work. Everything in between is ordinary management-system work that a company with a quality system has done before.

A gap assessment gives you both in the first month, along with the list of what is missing. If you would rather talk it through first, our ISO 42001 consulting page explains how we work, and our guide to choosing an ISO 42001 consultant covers what to ask anyone you are considering, including us.

Frequently Asked Questions

How long does ISO 42001 certification take for a small company?

A small company using one or two AI tools, with an existing ISO 9001 or ISO 27001 system, can usually get from gap assessment to certificate in four to six months. Without an existing management system, plan on seven to ten months, plus whatever the certification body's current queue for Stage 2 audits adds.

Can ISO 42001 certification be done in under six months?

Yes, but only when three things line up: a management system that already runs, a small and well-defined AI scope, and a certification body audit date reserved in the first month or two. Working harder does not shorten the auditor's queue, so the booking is the part most fast timelines get wrong.

When should we book the ISO 42001 certification body?

Request quotes during the gap assessment and reserve Stage 1 and Stage 2 dates by month two or three, roughly six months before the Stage 2 date you want. Some certification bodies have reported waits of six months or more for ISO 42001 Stage 2 audits, and a reserved date can be moved far more easily than a new one can be found.

Do we need ISO 27001 before ISO 42001?

No. ISO 42001 stands on its own and can be your first certification. An existing ISO 27001 or ISO 9001 system shortens the work because the shared clauses (context, leadership, planning, support, internal audit, management review) are already in place, but it is not a prerequisite.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.