Acuity AI Advisory
← Insights
·7 min read

Is ISO 42001 certification worth it for your business?

G

Ger Perdisatt

ISO/IEC 42001 Lead Auditor | Founder, Acuity AI Advisory

ISO 42001 can support customer confidence and better AI governance. Is certification worth pursuing now, or should your business prepare first?

ISO 42001 raises a useful question for businesses working with AI: could pursuing certification now help us establish credibility and run AI more confidently? That question applies to organisations using AI in everyday operations as well as companies developing or supplying it.

Certification can be worthwhile when it answers an assurance need or supports a management system the business has a reason to maintain. It may also help distinguish your approach to AI. The value of being early depends on whether customers and other stakeholders understand and care about the assurance. Being early, by itself, is not a business case.

Ger Perdisatt, founder of Acuity AI Advisory, holds the ISO/IEC 42001 Lead Auditor qualification. This article considers the business judgement behind certification. It does not assume the answer will be to certify.

What would the certificate tell a customer?

ISO/IEC 42001 concerns an organisation's AI management system within a defined scope. It can apply to companies developing AI, supplying AI-enabled services or using AI in their operations. ISO's overview explains that applicability.

The scope matters. A professional-services business using AI to support client work might consider the management of that activity. A manufacturer might focus on AI used in a particular operation. An AI supplier might cover development and delivery of its service. These are illustrative possibilities: the scope needs to be properly defined with the business and certification body.

A customer should be able to understand whether the certificate covers the activity they care about. A certificate covering a different part of the organisation may answer little about the work under consideration.

Certification has limits. It does not promise that every generated answer is correct or establish that every legal obligation has been satisfied. Customers may still need evidence about a particular use of AI and its effect on the work you do for them.

Ask what external assessment would help resolve. A procurement team may have a specific requirement. A board may want assurance that agreed governance is operating. A business might want a more disciplined way to manage growing AI use. Each reason deserves examination before committing to certification.

Decide between certifying, preparing and waiting

When to pursue ISO 42001 certification

Pursue now

There is a clear assurance or business need, the proposed scope addresses it, and the organisation can maintain the management system.

Prepare first

The potential value is clear, but responsibilities or operating evidence still need work. Establish those before fixing an audit date.

Defer

The value of external certification is unclear, or more immediate operational improvements deserve the available budget and attention.

These are decision prompts, not a readiness assessment. A business can have a strong reason to certify and still need substantial preparation.

Could being an early adopter help credibility?

It could. A business able to explain how it manages AI and offer independent assurance may give customers something concrete to assess. That can be relevant even when AI is used behind the scenes to support an established service, rather than sold as the product.

The useful test is what the intended audience makes of that assurance. If an important customer already asks for ISO 42001, clarify the acceptable scope and whether certification is mandatory. If customers have not asked for it, discuss whether it would help answer their concerns. Do not assume that they will recognise the certificate or give it weight in a buying decision.

Being among the earlier organisations in your particular market to certify could contribute to differentiation. That is a possibility to investigate, not a claim that the market is empty or that certification will win work. We would look for evidence in customer conversations and procurement requirements before attaching a commercial value to it.

There can also be a reason to act before an external deadline appears. If AI use is expanding across departments, establishing responsibilities and review processes now may be useful in its own right. External certification adds a further decision about assurance and cost. The organisation can improve governance before making that commitment.

What would make it useful inside the business?

A growing collection of AI tools can leave management unsure who owns each use, which uses have been assessed and whether agreed controls are followed. A management system gives those questions a regular place in how the organisation operates.

The benefit needs to show up in the work. Can someone identify the person responsible when an AI-assisted process produces a problem? Are material changes reviewed? Does management see unresolved issues and act on them? Those are practical outcomes to examine when deciding whether an ISO 42001 approach would help.

Certification should assess a system that is operating. If the main activity would be writing documents solely for the audit, the organisation should first reconsider how those documents relate to decisions people actually make.

When I would advise waiting

Where the business has limited AI use and proportionate controls, the extra value of external certification may be modest. If the main problem is poor information quality or unreliable outputs, work on that problem still needs to happen. A certificate will not repair it.

I would also be cautious when responsibility for the entire programme is assigned to someone with no time or authority to do it. The relevant question is whether the organisation can sustain the management system after the audit, including when tools and uses change.

Deferring certification should not leave material AI risks unmanaged. Agree who owns the systems already in use and how problems are handled. Set a reason to revisit the decision, such as a customer requirement or a substantial expansion of AI use. You can then reconsider it with better evidence.

What effort and cost should you budget for?

Ask for a scoped quotation from a certification body. Headcount alone will not tell you the cost. NSAI describes how AI lifecycle staff, system complexity, sensitive uses and third-party dependencies affect audit effort. Its process includes readiness assessment, an implementation audit and ongoing surveillance, with recertification every three years. NSAI's certification process

Your internal effort matters too. Someone needs to maintain the records, review changes and follow through on problems. Where you need outside preparation support, include that separately from the certification body's fees. A quote for the audit is not the full cost of operating the system.

If you already operate an ISO 27001 management system, examine what can be shared. Existing responsibilities, document controls and review routines may provide a starting point. AI-specific issues still need to be assessed. An information-security certificate does not automatically establish conformity with ISO 42001.

Can we prepare without committing to certification?

Yes. You can use the standard to guide improvements before seeking independent certification. Be accurate in how you describe that work: "preparing for certification" and "certified" make different claims.

Start by defining the activities the management system should cover and comparing current practice with the applicable requirements. Then decide whether the remaining work is proportionate to the likely benefit. Our AI Register guide to audit preparation explains the types of evidence involved. The ISO 42001 reference guide explains how a register contributes to the wider system.

Keep legal compliance as a separate assessment. ISO 42001 certification is not a substitute for checking the EU AI Act obligations that apply to your role and systems. Our comparison of ISO 42001 and the EU AI Act explains that distinction.

A useful first conversation

Start with how your organisation uses or supplies AI and what you would want certification to achieve. A customer requirement is helpful if one exists; it is not a prerequisite for the conversation. We can discuss whether certification merits attention now, what preparation would help, or whether to defer it. That conversation sits within our AI governance advisory work.

Acuity advises on preparation. The certification decision belongs to an independent certification body; ISO itself does not issue certificates. ISO's explanation of certification

iso 42001ai governanceai strategyireland