What the certificate actually covers
ISO/IEC 42001:2023 sets requirements for an artificial intelligence management system. The certificate says that management system met the standard, on the audit dates, inside a stated scope. It says nothing about whether a given model is accurate, or whether an agent behaved itself last Tuesday. Settle that internally before you start, because an executive who hears certified and understands our AI is safe will be disappointed by the actual document. The scope statement printed on the certificate is the part customers and regulators read, so it deserves more argument than most teams give it. Too wide and you are audited on systems nobody meant to include. Too narrow and the certificate answers nothing your buyers asked.
Step 1. Set the scope, then measure how far you are from it
Scope means which parts of the organisation, which AI systems, and which roles you hold for them. Write it down before the gap assessment, because the assessment is only meaningful against a boundary. Then run the gap assessment against the standard's clauses and its Annex A controls. The output that matters is not a maturity score. It is a list of gaps with an owner and a date against each one, because that list becomes the plan you are audited on later.
- The scope statement as it would appear on the certificate, in the words you would defend to an auditor
- A gap per clause and per Annex A control, marked as absent, partial or in place
- The named owner for each gap, and the date they have accepted
- The evidence each closed gap will produce once the control is running
- The decisions you are deliberately not making yet, with the reason recorded
Step 2. Build controls so the evidence falls out of operating them
The common mistake is to build controls, then start a separate evidence exercise a month before the audit. Records assembled retrospectively are exactly what a Stage 2 auditor is trained to notice, and the interviews will surface it faster than the documents will. Design each control so that running it produces the record by itself. That is a design constraint on tooling, not a documentation task.
- An AI system inventory with a risk classification and a review date per entry
- Impact assessments for the systems that affect people, kept current rather than filed once
- Records of data provenance and data quality for the systems that depend on them
- Human oversight records: which decisions were escalated to a person, what they decided, and when
- Supplier assessment covering model providers and tool vendors, with the review cadence stated
- Change control over model versions, prompt text and agent configuration, with the approval attached
- Incident handling that captures AI-specific failures, rather than availability incidents alone
Step 3. Operate it, then run an internal audit and a management review
Certification needs operating history. An auditor sampling records wants a meaningful period of normal operation, not a fortnight of tidying up, and there is no way to shortcut that with documentation. Once the system has been running, run an internal audit against the standard using someone independent of the work being audited. Hold a management review that produces recorded decisions rather than attendance. Then close your corrective actions with evidence, because an open nonconformity you found yourself and fixed is a much better story at Stage 2 than one the auditor finds.
Step 4. Choose an accredited certification body
Anyone can print a certificate. A certificate that survives a customer's due diligence comes from a body accredited to ISO/IEC 17021-1, supplemented by the AI-specific requirements in ISO/IEC 42006, by a recognised national accreditation body. UKAS, ANAB, JAS-ANZ or DAkkS are the sort of accreditation bodies you will see named. Ask for the accreditation certificate itself and check that its scope names ISO/IEC 42001, because a body accredited for a different standard is not accredited for this one.
- Which accreditation body accredits you, and does its scope name ISO/IEC 42001 specifically
- How many ISO/IEC 42001 audits has the assigned auditor personally led
- What does your Stage 1 output look like, and how long do we get to close findings before Stage 2
- How do you sample evidence for AI systems, and what will you want to see on the day
- What triggers a special audit inside the three-year cycle
Step 5. The two-stage audit, and the three years after it
Stage 1 reviews your documentation and the design of the management system. It usually produces findings you are expected to close before Stage 2, and treating it as a rehearsal rather than a hurdle is the right posture. Stage 2 tests whether the system operates as described, by sampling records and interviewing the people who do the work. Findings are graded, and a major nonconformity blocks the certificate until it is resolved. After that, the certificate is valid for three years. A surveillance audit each year covers changes and continual improvement, and is narrower than the initial audit. A full recertification audit opens the next cycle.
Where Difinity.ai fits, and where it stops
A Stage 2 auditor asks for evidence that the system operates as described, and that is the part an append-only run trail is built to produce. The run trail, which Hub calls the AI Trail, is the evidence of one governed run: the message, each guardrail verdict, each model turn, each proposed action, the tool gateway's decision, approvals asked for and answered, each executed action, the redactions applied, and the outcome. It cannot be edited. The application role holds no update grant, the table carries no policy that would allow one, and a repeated write is rejected rather than stored twice. That covers the human oversight and change control records above for the agents you run through the platform, and nothing beyond them. Governed run records can contribute operational evidence to wider EU AI Act, ISO/IEC 42001, risk and audit processes. Difinity does not determine that an organisation or AI system is compliant, and it does not provide ISO/IEC 42001 certification. Legal, risk, information security and compliance owners stay responsible for deciding which obligations apply and how the evidence is used.
What this guide cannot tell you
Three limits worth stating. The process detail here is triangulated from certification-industry sources, including an accredited certification body's own guidance, because ISO does not publish the audit process itself as free text. Clause-level and Annex A control detail should be read from the purchased standard rather than any summary, including this one. And there is no cost or duration figure on this page on purpose: the honest range depends on your scope, the certifications you already hold and the body you choose, so a number quoted without those three would be worth nothing to you.
Frequently asked questions
How long does ISO/IEC 42001 certification take?
There is no standard answer, and the binding constraint is usually operating history rather than paperwork. You need the management system running long enough to produce records, plus an internal audit and a management review, before a Stage 2 auditor has anything to sample.
How long is an ISO/IEC 42001 certificate valid?
Three years. A surveillance audit each year checks changes and continual improvement, and a full recertification audit opens the next three-year cycle.
What is the difference between Stage 1 and Stage 2?
Stage 1 reviews whether the AI management system is documented and coherent. Stage 2 tests whether the organisation operates it, by sampling records and interviewing the people who run the controls.
Can a vendor certify us, or can we inherit a vendor's certificate?
No. Certification applies to the organisation's own management system inside its own scope. A supplier's certificate is useful input to your supplier assessment, and it is not a substitute for your own.
Does ISO/IEC 42001 certification make us EU AI Act compliant?
No. They are different instruments. A management system certificate is evidence of process discipline, and the Act's obligations still depend on your role for each system and its risk category.
Does Difinity provide ISO/IEC 42001 certification?
No. Certification is performed by an independent, accredited certification body. Difinity contributes operational evidence from governed agent runs that an organisation can use inside its own management system and audit preparation.
Sources and further reading
- Cloud Security Alliance: what to expect in the ISO 42001 certification process (2026) (opens in a new tab)
- Schellman, an accredited certification body: guide to ISO 42001 certification (2026) (opens in a new tab)
- Trustible: how ISO 42001 certification works, the two-stage audit (2026) (opens in a new tab)
- ISO: ISO/IEC 42001:2023, artificial intelligence management system (published 2023) (opens in a new tab)