Skip to main content
ISO 42001

How to Choose an ISO 42001 Consultant in the UK

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

12 min read

Contents

    ISO/IEC 42001 was published on 18 December 2023 as the first international standard for Artificial Intelligence Management Systems. Through 2026 it has moved from a standard people read about to one that buyers ask for by name, and a market of consultants has appeared to meet that demand faster than any way of judging them has.

    There is no licensing body for ISO 42001 consultancy. Anyone may use the title. Accreditation for the certification bodies themselves only began arriving during 2026. So the buyer is making a significant purchase with no register to check and, in most cases, no prior experience of the standard to check it against.

    This guide sets out six things worth checking, in the order they matter. The fourth one is the one almost nobody raises, and it is the one that can invalidate the work after it is finished.

    First, be honest about whether you need it at all

    ISO 42001 is appropriate for organisations that build AI systems, deploy AI in their products or operations, or procure AI from third parties in ways that create material organisational risk. It is less appropriate for organisations whose only AI exposure is using off-the-shelf tools such as email, productivity software or general-purpose assistants without building or deploying AI in their own services.

    A consultant who reaches the scoping conclusion before hearing the answer is not scoping. This decision belongs at the start of an engagement, not after a contract is signed, and a good adviser will sometimes talk you out of the standard and into a narrower piece of work.

    Where it does apply, the standard follows the same Annex SL high-level structure as ISO 27001 and ISO 9001, which is why organisations already holding ISO 27001 can extend into ISO 42001 with materially less effort, and why the certification process follows the familiar Stage 1 and Stage 2 model.

    The six checks

    1. Certification-audit experience, named

    Ask directly: have you taken an AI management system through a Stage 2 certification audit, and which certification body ran it?

    This is a harder question in 2026 than it looks, because the accredited certification population is small and new. It is still the right question, and a specific answer naming a body and a scope is worth more than a general claim of experience. Where the answer is that the consultant has taken management systems through Stage 2 under other standards and is applying that to a newer one, that is a reasonable and checkable position. It is only a problem when it is dressed up as something else.

    2. Who actually does the work

    Ask who delivers day to day, by name, and what they hold.

    The pattern worth watching for is a credentialed practitioner who wins the work and a less experienced team who deliver it. There is nothing wrong with a team, but you should know which model you are buying and what proportion of the engagement the named person is present for.

    3. Credentials, which are necessary and not sufficient

    The implementer-level credentials in the UK market are ISO 42001 Lead Implementer and ISO 42001 Lead Auditor. They are different qualifications: the auditor credential demonstrates competence to audit an implementation, not to design one. ISO 27001 credentials alone do not qualify a practitioner to implement ISO 42001, though they are genuinely useful adjacent knowledge, and the strongest implementations tend to come from practitioners who also understand information security management and data protection.

    Ask for the certification reference and verify it with the issuing body rather than taking the logo on the website. This takes two minutes and it is the cheapest check on this list.

    But treat credentials as a floor. A certificate demonstrates that somebody passed an examination about a standard. It does not demonstrate that they have built a management system that survived contact with an auditor.

    4. Independence, and this is the one that can invalidate the work

    A consultant who will not tell you in writing which of implementation and internal audit they are excluded from doing for you afterwards has not understood the standard they are selling.

    Here is why it matters, and the rule is not a matter of opinion.

    ISO/IEC 42006:2025 was published in its first edition in July 2025. It sets out the requirements for bodies providing audit and certification of AI management systems, and it is the document accreditation bodies use when they assess a certification body's competence to certify against ISO 42001. It sits alongside ISO/IEC 17021-1:2015, the general requirements for bodies providing audit and certification of management systems.

    Clause 5.2 of ISO/IEC 17021-1 is the impartiality clause, and its substance is reproduced in the published impartiality policies certification bodies are required to make available. It provides, among other things, that a certification body shall not provide management system consultancy; that it shall not provide internal audits to its certified clients, and shall not certify a management system on which it supplied internal audits within two years of the end of that work; that it shall not outsource audits to a management system consultancy organisation; and that it shall not state or imply that certification would be simpler, easier, faster or less expensive if a specified consultancy organisation were used.

    Read that list from the buyer's side. The rules exist because a body cannot credibly assess a system it designed. The same logic runs down to the consultant: the party that builds your AI management system cannot be the party that performs the clause 9.2 internal audit on it, because the internal audit is one of the things the Stage 2 auditor will examine, and an internal audit conducted by its own author is not an audit.

    Three practical consequences for your shortlist.

    • A firm offering to implement your AIMS and certify it is offering something the framework does not permit. Goldline is not a certification body and cannot issue a certificate, and nor can any consultancy.
    • A firm offering to implement your AIMS and then run your internal audit is offering something that will not stand up. Plan for two parties from the beginning: it is cheaper than discovering it at Stage 1.
    • If your chosen consultant does both kinds of work, ask which one they are taking on for you, and get the exclusion in writing. A practitioner who holds both implementer and auditor credentials is more useful, not less, provided the line is drawn in the engagement letter rather than in conversation.

    Internal audit competence is itself defined. ISO 19011:2018 has been withdrawn; the current text is ISO 19011:2026, fourth edition, published 27 May 2026. Anyone quoting the 2018 edition at you in the second half of 2026 has not looked recently.

    5. Whether the price is published

    This is a simple test with more signal in it than its cost suggests.

    An independent comparison directory of ISO 27001 and adjacent consultancies maintained at soc2auditors.org carries a published-price field in every firm record. In its August 2026 snapshot, only ten of the thirty-three firms compared had filled it in. Twenty-three showed pricing as not published. That is a fair reflection of the market.

    A firm that will state its engagement model, day rate or fixed-fee structure before a call is easier to plan around and easier to compare. It is not a claim about quality, and there are good firms that scope everything individually for defensible reasons. It does tell you how much work you will have to do to find out what something costs.

    The directory deserves credit for scoring it at all. Making the field exist is what turns an unanswerable question into a comparable one.

    6. What happens after the certificate

    Certification is the beginning of an obligation, not the end of one. Surveillance audits follow, the management system has to keep running, and the internal audit has to happen again.

    Ask what retained or managed support looks like after the certificate is issued, and what it costs. A programme that ends the week the certificate arrives leaves you carrying a system nobody has been resourced to operate.

    The accreditation position, stated with the conflict left in

    Buyers reasonably want to know whether a certificate will be accepted. The honest answer in 2026 is that the accredited population is small and growing, and that the public record does not agree with itself on when it started.

    UKAS announced on 15 January 2026 that it had granted BSI the first UKAS accreditation for ISO/IEC 42001. BSI announced the same accreditation on 17 November 2025. Neither statement gives the date the accreditation was actually granted, so the two announcements cannot be reconciled from the public record. Both are worth reading and neither establishes the date.

    The UKAS AI management systems page was last modified on 25 August 2026 and states that the pilot accreditation programme has concluded and applications are open. The practical reading is that the accredited population is expanding through 2026 and that you should confirm the accreditation status and scope of any certification body at the point you approach it rather than relying on a list, including this one.

    What a competent implementation actually produces

    Whoever you engage, the outputs should be recognisable. A senior practitioner-led implementation should leave you with:

    • A documented AI system inventory, with an impact assessment completed for each system in scope
    • A Statement of Applicability with evidence for the Annex A controls included and a stated reason for those excluded
    • An AI risk register with treatments documented and monitored, calibrated to AI-specific risk including bias, opacity, data quality and unintended consequences
    • A policy framework covering the Annex A control objectives
    • Governance structures that match how decisions are actually made in your organisation
    • An evidence pack assembled to certification body submission standard

    Timelines run roughly 12 to 20 weeks from no AI governance baseline, and 8 to 14 weeks where current ISO 27001 certification allows evidence reuse across the shared Annex SL structure. Those are ranges, and the number of AI systems in scope moves them more than anything else.

    The failures that produce findings at Stage 2

    The most common ISO 42001 failure is treating it as a documentation exercise rather than a governance implementation. Stage 2 auditors test whether the management system is operating, not whether the documents exist.

    Specifically:

    • Impact assessments completed as templates rather than as genuine assessments of each system
    • Risk registers populated with generic AI risks rather than the risks your systems actually carry
    • Statements of Applicability that cannot be evidenced, with controls marked as implemented and nothing behind them
    • Governance structures on paper that do not reflect who really decides
    • Internal audits conducted without genuine independence, which is the failure this guide has spent the most words on because it is the one that cannot be fixed by working harder

    Why this is worth getting right in 2026

    Three things are making the timing real rather than theoretical.

    The EU AI Act. Article 50 transparency obligations apply from 2 August 2026. High-risk obligations apply from 2 December 2027 for Annex III standalone systems and 2 August 2028 for Annex I systems embedded in regulated products. UK organisations placing AI systems on the EU market, or serving EU customers, are in scope regardless of where they are headquartered. ISO 42001 addresses substantial parts of the Act's risk management, data governance and documentation requirements without being a compliance route to it.

    Procurement. UK enterprise and public sector buyers are adding AI governance questions to supplier assessments, and a certified management system is the cleanest available answer to a question that otherwise takes a bespoke response every time.

    Board accountability. Expectations of board oversight of AI risk are hardening in the same direction information security expectations moved under GDPR. A management system is the documented answer to a question boards are increasingly being asked.

    If it is useful

    Goldline implements ISO 42001 and ISO 27001 management systems and separately carries out clause 9.2 internal audits, and does not do both for the same organisation and scope. The scope and prices for every service are published at goldlineconsultancy.co.uk/pricing. For a scoping conversation, book a call.


    Sources, and the date each was read

    • ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, published 18 December 2023. Read at iso.org, 1 September 2026.
    • ISO/IEC 42006:2025, Requirements for bodies providing audit and certification of artificial intelligence management systems, first edition, July 2025, 31 pages. Read at iso.org, 1 September 2026.
    • ISO/IEC 17021-1:2015, Requirements for bodies providing audit and certification of management systems, Part 1. Clause 5.2 impartiality requirements read via a certification body's published impartiality policy reproducing the clause, 1 September 2026. The ISO text itself is behind purchase and the summary above reflects the reproduced clause rather than the standard as published.
    • ISO 19011:2026, Guidelines for auditing management systems, fourth edition, published 27 May 2026, 46 pages, superseding ISO 19011:2018 which is withdrawn. Read at iso.org, 1 September 2026.
    • UKAS, ISO/IEC 42001 accreditation announcement, 15 January 2026, and AI management systems accreditation page, last modified 25 August 2026. Read at ukas.com, 1 September 2026.
    • BSI announcement of UKAS accreditation for ISO/IEC 42001, 17 November 2025. Read 1 September 2026.
    • soc2auditors.org, ISO 27001 consultants comparison, August 2026 snapshot, published-price field populated for 10 of 33 firms compared. Read 1 September 2026.
    • EU AI Act application dates as recorded in Goldline's verified claims register, read 1 September 2026.

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.