TL;DR: ISO/IEC 42001:2023 is the first international standard for AI management systems, covering risk assessment, data governance, and monitoring across 39 controls, with certification typically taking 6 to 12 months and costing $5,000 to $30,000+ for the initial audit, according to Openlayer. ISO 42001 creates a governance backbone for AI programmes, but it does not satisfy EU AI Act obligations on its own.
NHIMG editorial — based on content published by Openlayer: ISO 42001: A Complete Guide to AI Management Systems in June 2026
By the numbers:
- ISO 42001 certification takes 6 to 12 months and costs $5,000 to $30,000+ for the initial audit.
- Research shows that ISO 27001-certified organizations can achieve ISO 42001 compliance up to 40% faster than those starting from scratch.
Questions worth separating out
Q: How should organisations prepare AI programmes for ISO 42001 readiness?
A: Start by defining ownership, evidence, and review workflows before chasing certification.
Q: Why do AI programmes need more than policy documents to satisfy ISO 42001?
A: Because the standard expects management systems to operate, not just exist on paper.
Q: What do organisations get wrong about ISO 42001 readiness?
A: They often treat it as a documentation exercise instead of a lifecycle control model.
Practitioner guidance
- Map AI systems to a defensible scope Inventory every AI use case, owner, data source, and supplier dependency before drafting the Statement of Applicability.
- Tie AI policy to runtime evidence Require CI/CD tests, monitoring logs, and approval records that show AI controls are operating as described.
- Review privileged access behind AI workflows Identify service accounts, API keys, tokens, and delegated permissions used by AI pipelines and agents.
What's in the full article
Openlayer's full guide covers the operational detail this post intentionally leaves for the source:
- Detailed cost breakdowns for gap assessment, auditor fees, training, and surveillance audits.
- Provider and delivery-format comparisons for ISO 42001 lead auditor training.
- Stage-by-stage certification workflow, including Stage 1 and Stage 2 audit expectations.
- Practical mapping of ISO 42001 requirements to runtime enforcement and compliance evidence.
👉 Read Openlayer's guide to ISO 42001 certification, costs, and audit steps →
ISO 42001 certification and AI governance: are controls keeping up?
Explore further
ISO 42001 is becoming the governance wrapper for AI, not the control plane. The standard is useful because it forces AI programmes to define scope, ownership, and evidence. But it does not itself constrain model behaviour or privilege use, which means organisations still need IAM, NHI, and platform controls underneath the certification layer. The practitioner conclusion is simple: certification without operational control mapping will not survive scrutiny.
A question worth separating out:
Q: When does AI governance become an IAM and NHI problem?
A: It becomes an IAM and NHI problem as soon as autonomous systems use credentials, APIs, or delegated access to perform actions. At that point, the quality of identity assignment, privilege scope, logging, and lifecycle control determines whether the system can be governed and audited responsibly.
👉 Read our full editorial: ISO 42001 certification is reshaping AI governance and audit work