ISO/IEC 42001 was published in December 2023 as the first international management system standard for artificial intelligence. It is certifiable, which is the whole point of it and the reason you are probably reading about it: somebody has asked whether you have it, or a certification body has told you that you should.
Almost everything written about this standard is published by organisations that sell certification or readiness services. That content is often accurate and never disinterested, and there is one question it structurally cannot answer for you: whether you need this at all. That is the question this page is about.
What the standard actually contains
It follows the familiar ISO management system shape, so if you have been through ISO 27001 the structure will be recognisable.
Clauses 4 to 10 are the management system: understanding your context, leadership commitment, planning, support, operation, performance evaluation, and improvement. This is the part that says an AI management system must exist, be owned, be resourced and be reviewed.
Annex A carries 38 controls grouped under 9 objectives, covering AI policy, internal organisation, resources, impact assessment, the AI system life cycle, data, information for interested parties, responsible use, and third-party relationships. The controls are deliberately principle-based rather than prescriptive technical requirements, which makes them adaptable and also means two certified organisations can look very different.
You are not required to implement all 38. You select the ones applicable to your risks and record those choices in a Statement of Applicability. Annex B provides implementation guidance rather than further requirements.
Who actually needs it
The honest answer has nothing to do with your AI maturity and everything to do with who is asking.
You probably need it if customers are asking for it in procurement, you sell AI-enabled software to enterprises or the public sector, you operate in a regulated sector where your regulator has started asking about AI governance, or an insurer or investor has raised it. In every one of those cases the certificate is the deliverable. Nothing else you do produces the same artefact.
You probably do not need it if nobody has asked, you use AI tools rather than building AI systems, and your actual concern is staff pasting client data into a chatbot. That is a real problem and certification is a disproportionate response to it. The proportionate response is a policy people sign and a quarterly review, which costs you a week rather than a year.
The distinction that matters most: this standard was written primarily for organisations that develop, deploy or provide AI systems. If you are a company that uses AI tools the way you use email, much of Annex A is about a life cycle you do not have. You can still certify, and consultancies will happily help, but you will spend a lot of effort documenting the absence of things.
ISO 42001 or the NIST framework
These get compared constantly and they are not really alternatives.
The NIST AI RMF is voluntary, free, has no certification, and exists to help you reason about AI risk. ISO 42001 is a certifiable standard with an audit and a certificate at the end. If your need is to think clearly, NIST is faster and costs nothing. If your need is to prove something to a third party, only ISO produces the evidence.
Plenty of organisations use the NIST framework to do the thinking and ISO 42001 to certify the result. That sequence is cheaper than starting with the auditor.
What it realistically costs
Nobody publishes prices, so treat any specific number you see with suspicion, including from certification bodies who will quote after scoping. What is predictable is the shape of the cost.
There are three components: internal effort to build and run the management system, which is by far the largest and lands on your people; the certification body's audit fees across a two-stage initial audit and then surveillance; and usually consultancy to prepare, which is optional and heavily sold.
The variable that moves the total most is scope. Certifying one AI-enabled product is a different exercise from certifying the whole organisation. Scope it as narrowly as the person asking will accept, because scope drives the effort in every one of the three components.
What to do before calling a certification body
Three things, in order, and the third often makes the first two unnecessary.
First, get the actual requirement in writing from whoever is asking. "ISO 42001 certified" and "demonstrate AI governance" are very different asks, and the second is frequently satisfied by a policy, a risk assessment and a review cadence. Ask before you assume.
Second, do the governance work regardless, because it is required either way and it is useful on its own. A signed AI acceptable use policy, a named owner, an AI risk assessment, and a review that happens. That is a meaningful proportion of what the standard's early clauses ask for, and it is work you would want done even if certification never happens.
Third, then decide. Having done the governance work you will know how large the gap actually is, and you will be negotiating with certification bodies from a position of understanding rather than anxiety. That is a materially cheaper conversation.
FAQ
ISO/IEC 42001, published in December 2023, is the first international management system standard for artificial intelligence. It specifies requirements for establishing and running an AI management system across clauses 4 to 10, supported by Annex A's 38 controls grouped under 9 objectives and Annex B's implementation guidance. It is certifiable, and organisations select which Annex A controls apply to them and record those choices in a Statement of Applicability.
Usually only if someone is asking for it. Certification is the right answer when customers require it in procurement, when selling AI-enabled software to enterprise or public sector buyers, or when a regulator or insurer has raised it, because the certificate is the deliverable and nothing else produces it. If the actual concern is staff putting client data into chatbots, a signed policy and a quarterly review addresses that at a fraction of the cost.
No, and they are not really alternatives. The NIST AI Risk Management Framework is voluntary, free and carries no certification, existing to help an organisation reason about AI risk. ISO 42001 is a certifiable standard with a two-stage audit and a certificate. Many organisations use NIST to do the thinking and ISO to certify the outcome, which is cheaper than starting with an auditor.
Annex A contains 38 controls across 9 control objectives: AI policy, internal organisation, resources, impact assessment, AI system life cycle, data, information for interested parties, responsible use, and third-party relationships. Implementing all of them is not mandatory. An organisation selects those applicable to its identified risks and documents the selection and rationale in a Statement of Applicability.
No credible published price exists, because cost is driven by scope and certification bodies quote after scoping. The predictable structure is three components: internal effort to build and run the management system, which is the largest and falls on your own people; audit fees across a two-stage initial certification and ongoing surveillance; and optional preparation consultancy. Scope moves the total more than any other variable, so certifying a single AI-enabled product costs far less than certifying an entire organisation.