← All articles
ISO/IEC 42001AIMSCertification

The ISO/IEC 42001 Certification Journey: What the First 90 Days Actually Look Like

Most organisations treat 42001 as a documentation exercise. The ones that certify on the first attempt treat it as an operating-model change — and start with the inventory, not the policy.

22 Jul 2026·8 min read

Certification bodies do not audit your intentions. They audit evidence — records, decisions, and the traceable line between a stated control and the artefact that proves it operated. That distinction decides whether your first Stage 2 audit is a formality or a rework cycle.

An AI Management System under ISO/IEC 42001 is a management system before it is anything about AI. The clause structure will feel familiar to anyone who has been through 27001 or 9001: context, leadership, planning, support, operation, evaluation, improvement. What changes is the object being managed — a portfolio of systems whose behaviour is probabilistic, whose training data has provenance questions, and whose failure modes are not always visible in a log file.

Weeks 1–3 · Inventory before policy

The single most common failure we see is a beautifully drafted AI policy sitting above an organisation that cannot say how many AI systems it operates. Start with discovery: every model, every vendor API, every embedded feature in a SaaS product your teams already pay for. Shadow AI is the norm, not the exception.

  • System name, owner, business purpose and lifecycle stage
  • Data categories consumed, including any personal or special-category data
  • Degree of autonomy and the human decision it informs or replaces
  • Third-party dependency chain — who trained it, who hosts it, who can change it
If you cannot name the owner of a system, you do not have a control over it. You have a hope.

Weeks 4–8 · Impact assessment and control selection

Annex A gives you the control set; Annex B tells you how to implement it. Neither tells you which controls matter for your risk profile — that comes from the AI system impact assessment, which is the closest thing 42001 has to a load-bearing wall. Done properly it feeds your Statement of Applicability, your risk treatment plan, and, if you operate in the EU, a large share of your AI Act technical documentation.

38Annex A controls
9–14Months, typical journey
~60%Overlap with EU AI Act evidence

Weeks 9–13 · Operate it, then evidence it

Auditors look for a system that has been running, not one that was assembled the week before. Three months of live records — review meeting minutes, incident logs, change approvals, competence records — is worth more than three hundred pages of policy. Run internal audit early enough that findings can be closed before Stage 1.

The organisations that struggle are the ones that outsourced the management system to a consultant and kept operating exactly as before. The ones that certify cleanly used the standard as a reason to fix governance they already knew was thin.

Ready to build AI systems the world can trust?

Book a complimentary 45-minute AI Governance Readiness Assessment with our Senior Lead Auditor team.

contact@gnaan.ai +91 6282 552 995