The ISO 42001 certification process
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 42001
If you have certified to ISO 27001, ISO 42001 certification will feel familiar — the same two-stage audit, applied to your AI management system.
The same path as 27001
ISO 42001 certification follows the harmonised management-system path you may know from ISO 27001. You build the AI Management System, exercise its machinery (internal audit, management review), then a certification body audits you in two stages. The familiarity is deliberate — it is the same structure applied to AI.
Build and self-check
First you stand up the AIMS: scope, AI risk assessment, the AI-specific controls (selected via an applicability statement), AI policy, and the processes for lifecycle, data, transparency, and oversight. Then you run at least one internal audit and management review — the AIMS must operate before it can be certified.
The two-stage audit
Stage 1 reviews your AIMS documentation for adequacy; Stage 2 tests whether it actually operates — sampling evidence, interviewing people, checking the audits and reviews happened. Major nonconformities must be closed before the certificate issues, exactly as in ISO 27001.
Maintain it
Certification runs on a multi-year cycle with surveillance audits in between and recertification at the end. Because the structure mirrors ISO 27001, the maintenance rhythm is the same. SentinelPanda keeps the AIMS evidence and audit cadence flowing across the cycle.