ISO 42001 certification in Australia and New Zealand.
The steps from a standing start to a certificate, the two audits, how long it takes, what drives the cost and how to check the body that certifies you. Written by a team going through it.
The short answer
ISO/IEC 42001 certification is issued by an accredited certification body after two audits: Stage 1 reviews your documentation and readiness, Stage 2 checks the AI management system is genuinely operating. Before either, you set the scope, build the system (policy, AI inventory, risk and impact assessments, Statement of Applicability, controls), run it long enough to keep records, and complete an internal audit and a management review. Expect four to nine months, less if you hold ISO 27001. The certificate lasts three years with surveillance audits. In Australia and New Zealand, check the body is accredited for 42001 by JAS-ANZ or another IAF signatory.
The seven steps to a certificate
The audits are the last two steps and the shortest. Most of the time goes on steps two and three, because Stage 2 inspects what happened, not what was written down.
Set the scope
Which parts of the business, which AI systems and which roles: developer, provider or user. A narrow first scope certifies faster, but it must include the AI people actually use.
Build the management system
AI policy, named accountability, the AI inventory, risk assessments, AI system impact assessments, the Statement of Applicability against Annex A, and the controls it commits you to.
Run it and keep the records
Operate the controls for long enough to show they are followed: approvals, reviews, monitoring and supplier checks, dated and retrievable.
Internal audit and management review
Audit your own system against the standard and hold a management review of the results (Clauses 9.2 and 9.3). A certification body expects to see both before Stage 2.
Stage 1 audit
The certification body reviews your documentation and readiness: is the scope sound, is the system designed to meet the standard, is it ready to be assessed in operation.
Stage 2 audit
The body assesses whether the system is genuinely operating: it samples records, interviews the people named in it, and raises nonconformities where practice and documents part ways.
Certificate, then surveillance
Close the nonconformities and the certificate is issued for three years, with surveillance audits, usually annual, and recertification at the end.
How long it takes, and where the time goes
Four to nine months is typical from a standing start. The range is set less by the size of the business than by how much evidence already exists. An organisation that cannot yet say which AI tools its people use spends the first weeks finding out, and that inventory is the foundation every later clause stands on.
The step organisations underestimate is the third. A policy can be written in a week; a Stage 2 auditor wants to see that approvals were given, reviews held and AI use monitored over time. That is why we start the monitoring early: the usage records that show who uses which AI are evidence for Clause 9.1 from the day they switch on.
How to choose a certification body
A certificate is only as useful as the trust your customer places in whoever issued it. Four checks before you sign.
Accredited for ISO/IEC 42001, not only for ISO 27001
Accreditation is granted standard by standard. Ask which accreditation body accredits them for 42001 and check it on that body's own register. In Australia and New Zealand that is JAS-ANZ; bodies accredited by another signatory to the IAF multilateral recognition arrangement are also widely accepted.
Independent of whoever prepared you
The body that audits you cannot be the one that built your system. If a firm offers to do both, the certificate is worth less to the customer who asked for it.
Auditors who understand the AI you run
ISO/IEC 42006 sets out what competence a body needs to audit an AI management system. Ask who will audit you and what AI systems they have assessed before.
Can audit 27001 alongside it
If you hold or are pursuing ISO 27001, an integrated audit saves days and keeps one set of management-system records.
What drives the cost
There are two costs and they are often confused: the certification body's audit days, which it quotes per organisation, and the internal work of building and running the system, which is usually larger. These are what move both.
| Driver | Why it matters |
|---|---|
| Headcount and sites in scope | More people and locations mean more audit days. |
| How many AI systems are in scope | Each one needs its own risk and impact assessment and its own evidence. |
| Developer, provider or user | Building AI brings in the full lifecycle controls; using it narrows the work. |
| ISO 27001 already in place | Document control, internal audit and management review already exist. |
| How much evidence already exists | Usage records, approvals and an inventory that already run shorten the build. |
Where we stand
We prepare; an accredited body certifies
Sentry AI is not a certification body and never will be. We build and run the thing the audit inspects: the AI inventory, the risk and impact assessments, the approval trail and the monitoring that produces the evidence. Our own ISO 42001 programme is underway, so we are writing from the same path you are on, and we will say we are certified when a certificate is issued and not before. Our trust centre carries the current status.
Frequently asked questions
How do you get ISO 42001 certified?
Define the scope, build the AI management system (policy, AI inventory, risk and impact assessments, Statement of Applicability, controls), run it long enough to produce records, complete an internal audit and a management review, then engage an accredited certification body for a Stage 1 audit (documentation and readiness) and a Stage 2 audit (is the system genuinely operating). Close any nonconformities and the certificate is issued for three years, with surveillance audits in between.
How long does ISO 42001 certification take in Australia or New Zealand?
Typically four to nine months from a standing start, and shorter if you already hold ISO 27001. The audits are short. What takes the time is building the management system and accumulating enough operating evidence, including a completed internal audit and management review, that Stage 2 has something real to assess.
Who can certify us against ISO 42001?
Only a certification body, and the certificate carries the most weight when that body is accredited for ISO/IEC 42001 specifically. In Australia and New Zealand the accreditation body is JAS-ANZ; certificates issued under another accreditation body that is a signatory to the IAF multilateral recognition arrangement are also widely accepted. ISO/IEC 42006 sets the requirements for bodies that audit and certify AI management systems.
Can the firm that prepares us also certify us?
No. The body that audits you must be independent of the body that helped you build the system. A firm offering both is a reason to look elsewhere. Sentry AI builds and runs the management system; an accredited certification body certifies it.
What makes ISO 42001 certification cost more or less?
Headcount in scope, the number of sites, how many AI systems the scope covers, whether you build AI or only use it, and whether ISO 27001 is already in place. The certification body quotes its own audit days. The larger cost is usually internal: the time to build the system and produce evidence before anyone audits it.
Can we certify only part of the business?
Yes. The scope can be a business unit, a product or a set of AI systems, provided the boundary is defined and defensible. A narrow first scope certifies faster; a scope that excludes the AI people actually use will not survive Stage 2 questioning.
Can ISO 42001 and ISO 27001 be audited together?
Yes. Both use the same management-system structure, so many certification bodies offer an integrated audit, and much of the 27001 scaffolding (document control, internal audit, management review) carries straight across.
What happens after the certificate is issued?
Surveillance audits, usually annually, check the system is still operating, and recertification falls due at the end of the three years. The evidence has to keep accumulating, which is why the monitoring and the register need to run as part of the work rather than be rebuilt before each audit.
Want to know how far you are from Stage 2?
Take the free readiness checker first. If the gaps are real, a short call will show you what building the management system involves for a business your size.
Ask an AI about this page
Opens the assistant with this page loaded: read it, summarise it, cite it.