Skip to content
ISO 42001 certification cost and timeline

ISO 42001 Certification Cost and Timeline UK (2026)

Marius van Aswegen
Marius van Aswegen

In short: for a UK organisation, ISO 42001 consultancy with Cybercontrols costs from £10,200 if you already hold ISO 27001, and from £12,750 if you are starting from scratch, as a fixed price agreed before work begins. An independent internal audit costs from £3,400. Certification body fees are separate. The biggest variables are the number of AI systems in scope and whether you can build on an existing ISO 27001 system.

ISO 42001 costs at a glance

Cost elementTypical UK costWhat drives it
Consultancy, existing ISO 27001 holderFrom £10,200, fixedAI systems in scope, how mature your ISMS is
Consultancy, starting from scratchFrom £12,750, fixedOrganisation size, AI footprint, complexity
Independent internal auditFrom £3,400, fixedScope and whether it is combined with ISO 27001
Certification body (Stage 1 and Stage 2)Quoted by the certification bodyHeadcount, sites and AI system complexity
Internal timeYour team's effortAvailability of AI system owners and evidence

All Cybercontrols prices exclude VAT. See our fixed-price ISO 42001 packages for what each one includes.

Why holding ISO 27001 lowers the cost

ISO 42001 and ISO 27001 share the same management system structure: context, leadership, planning, support, operation, performance evaluation and improvement. If you already run a certified information security management system, your management review, internal audit, document control and corrective action processes can serve both standards. The work then concentrates on what is genuinely new: your AI policy, an inventory of AI systems, AI risk and impact assessments, and the Annex A controls for responsible AI. That is why our package for ISO 27001 holders starts lower than a full build.

What drives the price up or down

  • Number and type of AI systems. A business using two third-party AI tools needs far less work than one developing its own models.
  • Your role. AI developers and providers carry more obligations than organisations that only use AI.
  • Existing management systems. ISO 27001, ISO 27701 or ISO 9001 already in place reduce the effort.
  • Organisation size and sites. More people and locations mean more interviews, evidence and audit time.
  • Supply chain. Heavy reliance on AI suppliers adds third-party assessment work.

Typical timeline

Most ISO 42001 projects move through five phases. We agree the actual timeline at scoping, around your team's availability and your target certification date.

  1. Scope and gap analysis. Define the AI management system boundary and compare current practice with the standard.
  2. Foundations. AI policy, roles and responsibilities, and an inventory of AI systems.
  3. Risk and impact. AI risk assessments, AI system impact assessments and selection of Annex A controls.
  4. Operate and evidence. Run the controls, train owners and collect records.
  5. Audit and certify. Internal audit, management review, then Stage 1 and Stage 2 with your certification body.

How ISO 42001 maps to the EU AI Act

ISO 42001 does not make you compliant with the EU AI Act on its own, but it gives you the management system to evidence many of the Act's requirements for high-risk AI systems.

EU AI Act requirementWhere ISO 42001 helps
Risk management system (Article 9)AI risk assessment and treatment (clauses 6.1 and 8)
Data and data governance (Article 10)Data for AI systems (Annex A.7)
Technical documentation and record-keeping (Articles 11 and 12)AI system life cycle and documented information (Annex A.6, clause 7.5)
Transparency and information for users (Article 13)Information for interested parties (Annex A.8)
Human oversight (Article 14)Responsible use of AI systems (Annex A.9)
Quality management system (Article 17)The AI management system as a whole (clauses 4 to 10)

For more on where the Act applies to UK companies, read ISO 42001 and the EU AI Act.

Frequently asked questions

How much does ISO 42001 certification cost in the UK?

With Cybercontrols, consultancy starts at £10,200 for ISO 27001 holders and £12,750 for organisations starting from scratch, as a fixed price. Certification body fees are additional and quoted directly by the certification body.

Why fixed price instead of a day rate?

A fixed price means you know the full cost before you commit, and we carry the risk if the work takes longer than planned.

Do we need an internal audit before certification?

Yes. ISO 42001 clause 9.2 requires internal audits at planned intervals, and certification bodies expect to see at least one completed before Stage 2. Our independent internal audit starts at £3,400.

Can we combine ISO 42001 with ISO 27001?

Yes, and it is usually the most efficient route. One integrated management system means shared audits, shared reviews and one evidence library.

Want a fixed price for your organisation? Email hello@cybercontrols.io or book a free scoping call with a senior lead auditor.

Share this post