AI Governance 11 min read

How to Choose an ISO 42001 Consultant: What to Check Before You Hire

J

September 21, 2026

The most useful question to ask an ISO 42001 consultant is not how many ISO 42001 certificates they have. Very few firms anywhere have a long record in this standard, because it was only published in December 2023 and roughly 350 organizations held a certificate by spring 2026. What predicts a good engagement is a record of taking organizations through management-system certification audits, a working command of the parts of ISO 42001 that are genuinely new, and knowledge of the regulations your AI actually sits under. This guide covers how to check each of those, the questions to ask before you sign, the red flags, and what consulting costs in 2026.

Why this choice is harder than it is for ISO 9001

ISO 42001 uses the same Annex SL structure as ISO 9001 and ISO 27001, so clauses 4 to 10 (context, leadership, planning, support, operation, performance evaluation and improvement) will look familiar to anyone who has run a management system. The difficulty sits in three places those standards never asked about: an AI risk assessment, a Statement of Applicability built against the AI controls in Annex A, and an AI system impact assessment that looks at how a system could affect people outside your organization. A consultant can be excellent at the familiar part and never have done the new one.

The market is also young. There is no official register of ISO 42001 certificates, and the counts that exist are assembled from announcements, so almost nobody can point to dozens of completed ISO 42001 projects. That makes the usual shortcut, asking for a long list of certifications in the exact standard, less useful than it is for older standards. You have to look at the evidence underneath.

The kinds of firms you will be choosing between

Type of provider Where they are strong Where they are thin Usually fits
Management-system consultancies Audit preparation, document control, getting through Stage 1 and Stage 2 AI-specific risk and impact work, unless they have built it Organizations that already hold ISO 9001, 13485 or 27001
AI governance and ethics specialists AI risk, model oversight, responsible-AI policy Certification audits and document control Organizations with complex in-house AI and no management system
Large consulting and accounting firms Brand, large teams, breadth Cost, junior staff doing the work, heavy templates Large enterprises running a global program
Solo practitioners Price, flexibility, a senior person doing the work Capacity, and continuity if they get busy Small organizations with a narrow scope
Software vendors with consulting attached Tooling for inventories and evidence Advice tends to lead back to the tool Organizations that have already chosen a platform

None of these types is right for everyone, and the criteria below matter more than the category.

Six things that predict a good engagement

1. A record of management-system certification audits

Ask how many organizations the consultant has taken through Stage 1 and Stage 2 certification audits on any Annex SL standard, and what happened at those audits. Most of the work in an ISO 42001 project is management-system work: scope, document control, internal audit, management review and corrective action. A consultant who has done that many times will get you through clauses 4 to 10 without drama. Ask for references from those engagements, and ask about any ISO 42001 work they have done, but do not expect a long list of the latter from anyone.

2. Command of the AI-specific requirements

This is where you test rather than ask. Pick one AI system your organization uses, whether it is a vendor's model inside your quality system or a model you ship to customers, and ask the consultant to walk you through three things for it:

  1. How they would run the AI risk assessment under clause 6.1.2, and what risk criteria they would set.
  2. How they would decide which Annex A controls apply and justify the ones that do not, which is the Statement of Applicability under clause 6.1.3.
  3. How they would perform the AI system impact assessment under clauses 6.1.4 and 8.4, including who outside your organization could be affected.

A qualified consultant will answer in specifics about your system within a few minutes. Someone who has only read summaries of the standard will talk about responsible AI in general terms. Our Statement of Applicability guide and clause by clause breakdown show the level of detail to expect.

3. Formal study of the standard

Lead Implementer and Lead Auditor courses for ISO 42001 are offered by training bodies such as PECB and BSI, and it is fair to ask whether a consultant has taken one. It shows they have worked through the text of the standard rather than someone's summary of it. It is a short course, though, and it tells you less than the walk-through in point 2 does, so weigh it alongside the other five points instead of using it as a gate on its own.

4. Knowledge of the rules your AI sits under

ISO 42001 is voluntary, and the pressure to adopt it comes from somewhere specific: a customer's security questionnaire, an FDA investigator, an auditor for another standard, or the EU AI Act. Your consultant should know that context for your industry. For an FDA-regulated manufacturer, that means knowing that in April 2026 FDA cited "inappropriate use of artificial intelligence" under 21 CFR 211.22(c) for AI-written specifications and procedures released without qualified review. For a company selling into Europe, it means knowing that ISO 42001 certification does not give a presumption of conformity with the EU AI Act, and that the standard being written for that purpose is prEN 18286. A consultant who tells you ISO 42001 makes you compliant with the AI Act is wrong on a point that matters. Our comparison of ISO 42001, the NIST AI RMF and the EU AI Act sets out where each one applies.

5. A plan that builds on the system you already run

If you hold ISO 9001, ISO 13485 or ISO 27001, most of your management system already exists, and ISO 42001 should extend it instead of sitting beside it as a second set of procedures. Ask how the consultant would bring the AI requirements into your existing document control, internal audit and management review. An answer that starts with a fresh template library for everything is a sign you will pay to rebuild what you have. We cover what carries over in ISO 42001 for ISO 9001 certified companies.

6. Independence from the certification body

A certification body is not allowed to consult on a management system it will then certify, and ISO/IEC 17021-1, the accreditation standard certification bodies work under, treats that as a threat to impartiality. Your consultant should be separate from your auditor, and should be able to tell you how the certification bodies offering ISO 42001 differ in availability and approach. Some have reported auditor backlogs, with Stage 2 audits waiting six months or more, so advice on when to book is part of the job.

Red flags

  • Years of ISO 42001 experience before 2024. The standard was published in December 2023. Experience with AI governance or with other management systems can be real and valuable, and it is still a different thing from ISO 42001 experience. A consultant who blurs the two in a proposal will blur other things.
  • A guarantee of certification. A consultant can commit to getting you ready for the audit. The certification decision belongs to the certification body.
  • Claims that ISO 42001 is legally required, or that it satisfies the EU AI Act. Neither is true today.
  • Templates with your name typed in. The auditor will ask how your AI policy, risk criteria and impact assessments reflect your actual systems, and generic documents fail that question.
  • Everything in scope by default. Not every AI tool you use needs to sit inside the certification scope. A consultant who never raises the question may be sizing the engagement to suit themselves.
  • No clear answer on price. If you cannot get a fixed fee or a clearly bounded estimate for the first phase, expect the rest to drift.

What a sound engagement looks like

Phase What happens Typical duration
Gap assessment Your current state against clauses 4 to 10 and Annex A, a draft scope, and a costed plan 2 to 4 weeks
Scope and context AI system inventory, interested parties, the boundary of the management system 2 to 4 weeks
Risk and impact AI risk assessment, Statement of Applicability, impact assessments for the systems in scope 4 to 8 weeks
Controls and documents AI policy, roles, procedures, and the Annex A controls you selected 6 to 10 weeks
Operation and internal audit Running the system, training, an internal audit and a management review 4 to 8 weeks
Certification audits Stage 1, then Stage 2, and responses to any nonconformities Depends on the certification body

Phases overlap in practice, and the whole path from gap assessment to certificate usually takes four to twelve months. Organizations with a working ISO 9001 or ISO 27001 system tend to finish at the short end. Our timeline guide goes month by month, and the most common gaps article shows where the time usually goes.

Questions to ask before you sign

  1. Which management-system certification audits have you taken clients through, and can I speak to two of those clients?
  2. What ISO 42001 work have you done so far, and what did it involve?
  3. Walk me through the AI risk assessment, Statement of Applicability and impact assessment for one of our AI systems.
  4. How would you fit ISO 42001 into the management system we already run?
  5. Which parts of our AI use would you leave out of scope, and why?
  6. Which regulations and customer requirements do you see driving this for a company like ours?
  7. Which certification bodies would you suggest, and how long are their waits right now?
  8. What is fixed in your fee, what is not, and what happens if the audit finds a major nonconformity?
  9. Who will actually do the work, and how much of it will be you?

How someone answers matters as much as what they say. Specific, unhurried answers about your own systems are the best sign you will get.

What ISO 42001 consulting costs in 2026

Prices vary with the size of the organization and how much AI sits in scope, but the market in 2026 looks roughly like this:

Item Typical range
Two-day gap assessment, small organization using one or two AI tools $1,500 to $2,500
Scoped readiness review, larger organization $5,000 to $20,000
Total first-year cost for a 50 to 200 person company, including internal time, tooling and the certification body $85,000 to $150,000

The last line is the one to plan around, because most of it is not consulting fees. Internal time is usually the largest cost, and it never arrives as an invoice. Our cost guide breaks the budget down line by line with three worked examples.

Very low quotes deserve a second look, because a price that could only cover templates usually means templates. Our own offers are fixed: an ISO 42001 gap assessment at $9,750 and, for FDA- and ISO-regulated manufacturers, an AI in the quality system review at $5,000.

How we answer these questions ourselves

We would rather be held to this list than exempted from it. Certify Consulting Group comes to ISO 42001 from quality systems and regulatory affairs for FDA-regulated manufacturers. Jared Clark, who leads the practice, holds a JD and an MBA, the CMQ-OE, CQA, CPGP, RAC and PMP credentials, and validation credentials in computer system validation, computer software assurance and pharmaceutical validation management. That background shapes how we approach ISO 42001: as a management system added to the quality system you already run, tested against what an FDA investigator or an ISO auditor will ask about your AI.

If you are comparing consultants, start with a conversation and put these questions to us. You can read more about Jared's background and our ISO 42001 services.

Frequently Asked Questions

What credentials should an ISO 42001 consultant have?

Look for a record of taking organizations through management-system certification audits, formal study of ISO 42001 itself such as a Lead Implementer or Lead Auditor course, and working knowledge of the regulations in your industry. A course certificate shows the consultant has studied the standard, and a walk-through of how they would run your AI system impact assessment shows whether they can apply it.

How much does an ISO 42001 consultant cost?

In 2026 a two-day gap assessment for a small organization runs roughly $1,500 to $2,500, and a scoped readiness review for a larger one $5,000 to $20,000. Total first-year cost for a 50 to 200 person company, including internal time, tooling and the certification body, is commonly quoted at $85,000 to $150,000.

Can our certification body also be our ISO 42001 consultant?

No. ISO/IEC 17021-1, the accreditation standard certification bodies work under, treats consulting on a management system the body then certifies as a threat to impartiality. Hire the consultant and the certification body separately.

Can an ISO 9001 or ISO 27001 consultant handle ISO 42001?

Often, for clauses 4 to 10, which share the same Annex SL structure. The test is the AI-specific work: the AI risk assessment, the Statement of Applicability against Annex A, and the AI system impact assessment. Ask them to walk you through those for one of your own AI systems.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.