Read this first
We cannot currently offer accredited certification against ISO/IEC 42001.
EIAC publishes the list of standards it accredits certification bodies against. ISO/IEC 42001 does not appear on it. There is a defined route by which an accreditation body can establish a new scheme, and whether that happens is a question for EIAC rather than for us.
What this means for you, concretely: a certificate we issue against ISO/IEC 42001 would be unaccredited certification, even after UMA’s accreditation for other standards is granted. If your customer, tender or regulator requires accredited certification, this standard cannot yet meet that requirement from us or, as far as we can establish, from anyone accredited by EIAC.
We would rather tell you that on this page than discover it with you at contract stage. If unaccredited certification is still useful to you — and for many organisations getting the management system right is the actual objective — talk to us. If it is not, we will say so.
What the standard actually requires
ISO/IEC 42001 is the first management system standard for artificial intelligence. Published in 2023, it applies to organisations that develop AI systems, provide them, or use them — the last category being much larger than most organisations realise.
The clause structure will be familiar to anyone who has been through ISO 9001 or ISO/IEC 27001: context, leadership, planning, support, operation, performance evaluation, improvement. Annex A carries 38 controls grouped under nine objectives, covering AI policy, internal organisation, resources for AI systems, impact assessment, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships.
What makes it different from every other standard on this site is clause 6.1.4, the AI system impact assessment. Other management system standards ask you to assess risk to the organisation. This one requires you to assess the consequences for individuals and for society — the people affected by a decision your system makes, who are usually not your customer and have not agreed to anything.
That single requirement is where most of the real work sits, and it is where an auditor will look hardest.
Do you actually need it?
It is worth considering when you build or sell AI-enabled products and your customers have started asking governance questions you cannot answer consistently; you operate in a sector where AI regulation is arriving and you would rather have the arrangements before the deadline; or AI has spread through your organisation faster than anyone’s ability to say who approved what.
It is not the right answer when what you actually need is compliance with a specific AI regulation. This standard is a management system, not a legal compliance framework. It will help you demonstrate governance; it will not make you compliant with any particular law.
What a UMA certificate against ISO/IEC 42001 does and does not assert
It asserts that we audited your AI management system against ISO/IEC 42001:2023, for the scope stated on the certificate, and that on the evidence we saw it conforms.
It does not assert that your AI systems are accurate, fair, unbiased, safe, or fit for any particular purpose. It does not certify a model. It does not mean an automated decision your system makes is correct or lawful. What it certifies is that you have arrangements for governing these systems and that you follow them.
Anyone marketing a certificate against this standard as proof that their AI is trustworthy has misunderstood it, or is hoping you will.
How audit time is worked out for this standard
Audit duration for ISO/IEC 42001 is determined under ISO/IEC 42006, the standard for bodies certifying AI management systems. It is a recent document and the basis it sets out is not the same as the tables used for ISO 9001, ISO 14001 and ISO 45001.
The inputs include the effective number of personnel in scope, the number and complexity of AI systems, whether you develop them or only use them, the domains they operate in, and the extent of third-party AI you rely on. We show you the calculation with the quotation.
The cycle
Stage 1, then stage 2, then a certification decision taken by someone who had no part in the audit. Three years, with surveillance in each of the two intervening years — the first due within twelve months of the decision — and recertification before the three years are up.