ISO 42001 certification costs €11,900 with us for a single standard, and €21,900 if you take it together with ISO 27001 and Spain's ENS framework, twelve months of platform included and the certification body's audit contracted separately. Those are published, fixed prices, excluding VAT. What almost nobody quotes is the other half of the bill. This standard is not won with documents. It is won by showing that you govern your AI while you work.
Updated August 2026. The EU AI Act dates come from the European Commission's own page. Kiwop prices are the ones published on our website, excluding VAT.
What ISO 42001 actually certifies
ISO/IEC 42001:2023 certifies your AI management system: how you decide which AI you build or use, on what data, what impact it has on people, and who answers when something goes wrong. It is the first certifiable international standard for this, published in December 2023. It is audited like any other management standard, by a body accredited under ISO/IEC 17021-1, on a three-year cycle with annual surveillance.
Its Annex A carries 38 controls grouped into nine objectives, A.2 through A.10: AI policy, internal organisation, resources, impact assessment, system life cycle, data, information for interested parties, use, and third-party relationships. You do not implement all 38 blindly. You select the applicable ones in your statement of applicability, driven by your risk and impact assessments, and you justify in writing everything you leave out. That justification is the first thing the auditor reads.
Who it is really for
Three profiles, and all three for the same reason: someone outside is asking how they govern their AI, and they need an answer that is not a marketing PDF.
- Companies that build or run AI for others. Software with an LLM inside, agents, models trained on customer data. The question arrives in the enterprise buyer's security questionnaire, before signature.
- Companies that bid for public contracts. Tenders are adding AI governance requirements at the same speed governments are buying AI. Once it is on the table, there is no time left to improvise it.
- Companies exposed to the EU AI Act. The standard does not replace the Regulation, but it builds most of the machinery the Regulation will demand from you anyway.
What it costs: four line items, not one
The price is implementation, platform, certification audit and maintenance. The first three land in year one. The fourth starts in year two and never stops, because the certificate lives three years with annual surveillance.
Prices exclude VAT. We deliberately give no figure for the audit, and it is worth saying why.
Why we will not quote you an ISO 42001 audit fee
Because we have not found a public source we would stand behind. The cost guides circulating online quote anything from a few thousand dollars to six figures, and almost all of them are published by US compliance software vendors selling their own tooling. With that spread, any number we gave you would be decoration.
What we do know is how the fee is built. An independent third party invoices it, it is priced in auditor days, and those days depend on your headcount, your scope and how many AI systems fall inside it. It sits in the same order of magnitude as other management system audits. Ask for it in writing with your scope defined, and compare auditor days rather than headlines. One rule has no exception: whoever implements your system cannot audit it afterwards. If someone sells you a single price that "includes certification", ask what share of it reaches the accredited body.
The expensive mistake: treating it as paperwork
The classic mistake is to build ISO 42001 as a body of documents and turn up to the audit with a folder. With older standards that still buys you a few hours. Not with this one, because almost everything it asks for is operational and carries a date. Three things the auditor opens, and where most projects fall:
- The register of AI systems and models. What you run, which version, from which vendor, on what data, who owns it internally and how long it has been in production. An inventory frozen on the day it was written shows on the first question.
- Impact assessments. Assessing the impact on people before the system goes live, not after. The document date against the deployment date tells the whole truth.
- The decision trail. Who approved which model, what happened with that incident, what changed afterwards. This cannot be reconstructed the week before the audit.
Our own conclusion after going through it was unglamorous. The paperwork was not the hard part. The hard part is dated evidence, and it only exists if the system produces it while people work.
How it fits with ISO 27001
It fits well, and that is the best financial news in this article. Both standards share the harmonised high-level structure, so clauses 4 to 10 are the same: context, leadership, risk, internal audit, management review. What changes is the object. ISO 27001 governs information, ISO 42001 governs AI, and plenty of controls cross over.
In practice you audit them with the same accredited body in the same visit, shared governance evidence (minutes, training, incident handling) serves both, and adding ISO 42001 to a system that already exists costs far less than building it on its own. In our pricing, going from one standard to three moves from €11,900 to €21,900.
What it gives you against the EU AI Act, and what it does not
ISO 42001 is not mandatory, and certifying does not grant you presumption of conformity with the EU AI Act. That presumption comes only from harmonised standards whose references are published in the Official Journal of the European Union, and the committee writing them, CEN-CENELEC JTC 21, is drafting its own European standards rather than adopting ISO 42001 as it stands.
The Regulation's calendar, per the European Commission's official page, consulted in August 2026:
The last two dates moved with the digital omnibus regulation, in force since 27 July 2026, which postponed the high-risk obligations originally set for August 2026. Everything else held.
With that on the table, ISO 42001 makes more sense. It puts the house in order and builds the risk analysis, data governance, documentation, human oversight and incident log the Regulation will require regardless. What it does not hand you is a regulatory free pass.
How long it takes: twelve to sixteen weeks
With the platform running and the document kit ready, the plan runs twelve to sixteen weeks depending on where you start. The floor is set by maturity, not by documentation: you need weeks of real operation before there are dated records worth showing.
Add two waits you do not control: the certification body's calendar, which books weeks ahead, and the committee decision after the auditor's report. In our case that was communicated as up to fifteen working days.
What we did ourselves
From 17 to 27 August 2026, OCA Global audited Kiwop against three standards at once: Spain's ENS at MEDIUM category, ISO/IEC 27001 and ISO/IEC 42001. All three closed with zero non-conformities, with the management system run end to end on our own platform.
We say audit passed rather than "we are certified", on purpose. The certificates are issued later, once the body's committee resolves, and until they are in our hands this is the honest claim. When they arrive we will publish their numbers and scope.
We managed 204 measures and controls at once (73 ENS Annex II measures, 93 ISO 27001 Annex A controls and the 38 from ISO 42001), and we did it with no external consultancy. ISO 42001 was the one that forced the most change in how we work, because it touches product decisions and not just systems.
Frequently asked questions
Is ISO 42001 mandatory?
No. It is voluntary and no European law imposes it. The EU AI Act binds on its own terms, and presumption of conformity will come from harmonised standards. Companies certify because buyers ask, not because a regulator does.
Can I certify ISO 42001 without holding ISO 27001?
Yes, they are independent standards. You will have to build from scratch the management scaffolding ISO 27001 would have given you, so it costs more than taking both together. If you plan to do both within two years, do them in one project.
Does it apply if I only use third-party AI?
Yes. The standard covers developing, providing and using AI systems, and a good share of its controls deal with suppliers, responsible use and the information you give to affected people. If you put someone else's AI into processes that touch customers or employees, you have plenty to certify.
Where to start
Before asking anyone for a quote, write your scope: which AI systems are in, who owns them, and what decisions they touch. With that page in hand, every conversation with a certification body takes half the time.
The prices for Nexo SGSI are published on its page, with no form in the way, and they are the same ones behind our own management system. If you would rather talk it through with a team that has just passed the audit for three standards using this tool, get in touch and we will look at it in half an hour.