What ISO 42001 Costs in the UK
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
7 min read
Contents
The question has no single answer, and not because anybody is being evasive. It is four different costs, with four different owners, and only two of them are usually published by anyone.
Getting a number that survives a budget meeting means separating them first.
The four costs
1. Building the management system. The consultancy or internal effort that produces the AIMS. One-off, and the largest single figure.
2. Running it. Everything that recurs once the system exists: evidence, reviews, the internal audit, the annual visit. This is the one organisations underestimate, because the project has an end date and the function does not.
3. The certification body's fees. Paid directly to the body that issues the certificate, over a three-year cycle: initial certification, then surveillance, then recertification.
4. The platform licence, if you use one. Held in your own name, annual.
Almost every argument about what ISO 42001 costs turns out to be two people comparing different items from that list.
What is actually published
Goldline publishes 1 and 2 on its pricing page, along with the tiers and what moves an organisation between them. The AI governance readiness assessment that establishes your position is published there too, and it credits in full against a subsequent Sprint.
Some of the market publishes 2, and it is worth crediting the ones that do, because published pricing in this sector is rare and it makes buying easier for everyone. Atoro, for example, publishes UK sterling managed compliance pricing at £1,300, £2,600 and £3,900 a month for companies up to 50 people, with additional frameworks at £425 a month, on a twelve month term with a free exit in the first ninety days, prices last reviewed 5 August 2026. They also state that a standalone internal audit, which they include, would otherwise cost €3,000 to €5,000.
Nobody publishes 3. No UKAS-accredited certification body publishes its day rate, and the number of audit days your scope attracts for an AIMS is determined under ISO/IEC 42006:2025, which ISO sells rather than publishes. So there is no honest public figure for certification body fees, only a written quote. Anyone who gives you one has estimated it.
Platform licences are published by the platforms, and are commonly in the region of several thousand pounds a year for an organisation of this size.
The two numbers that actually move your total
Scope. The number of AI systems, entities and business units inside the boundary. It is the largest lever by a distance, and it is routinely set wider than any buyer asked for. Narrowing it is judgement work, which is why it is the first thing a readiness assessment should produce and the last thing a template will give you.
Whether you already hold ISO 27001. Two independent published sources point the same way here. Goldline states on its pricing page that where ISO 27001 is already certified, the ISO 42001 Sprint runs materially cheaper because the management system spine exists and the engagement is an overlay rather than a build. Atoro prices an additional framework on an existing programme at £425 a month rather than a second full plan. Different businesses, different models, same conclusion.
If you are choosing what to do first and you need both, ISO 27001 and ISO 42001 govern different things and the order matters commercially as well as technically.
Why ISO 42001 prices above ISO 27001 for comparable scope
Three reasons, and they are worth understanding rather than resenting.
The standard is young. It was published in December 2023, so there is no mature template library, and work that would be configuration on an ISMS is design work on an AIMS.
The controls require judgement rather than adaptation. Model risk, training data lineage, bias assessment, explainability and human oversight do not map onto information security controls, and an implementation that grafts AI language onto an ISO 27001 template will not survive Stage 2.
The practitioner pool is small. There are relatively few credentialled ISO 42001 lead implementers and lead auditors, and scarcity shows up in price.
For sanity checking any quote you receive
UK contract information security consultants had a median advertised day rate of £700 in the six months to 3 September 2026, with the 90th percentile at £840, from a sample of nine daily rates across ten matching adverts, according to ITJobsWatch. Credentialled lead implementer and audit work is quoted above that band.
That figure is not a price for ISO 42001 work. It is a floor for what senior time costs, which is useful when a quote looks either implausibly low or unexplained.
The more useful question than "is this expensive" is "what model is this priced on". A day rate rewards a slow engagement. A fixed scope rewards a finished one. Ask any consultancy which they use before you compare two numbers, because otherwise you are not comparing the same thing.
What the cheap end leaves out
The price floor in this market is very low, because the work can be done well or badly with almost no visible difference at the point of delivery. Both arrive as documents.
The difference surfaces at Stage 2, when the auditor asks how a control operates in practice and the answer is not in the document. A failed Stage 2 carries re-audit fees from the certification body and a delay measured in months, and that combined figure is larger than the difference between any two implementation quotes you are weighing up.
The recurring costs are the ones most often missed entirely. Certification is a three-year cycle, the internal audit is an annual obligation rather than a one-off, and in years two and three the certification body examines a full year of the programme running rather than the push that produced the certificate.
A number you can take to a budget meeting
Ask for four lines rather than one: build, run, certification body, platform. Ask which of the four each quoted figure covers. Ask what scope the figure assumes, and what happens to it if the scope changes.
A supplier who cannot answer those four questions has not scoped the work, whatever the number at the bottom.
Sources
- Goldline published prices, tiers, credit rules and the ITJobsWatch day rate figures, goldlineconsultancy.co.uk/pricing, read 1 September 2026.
- ITJobsWatch, UK contract information security consultant median advertised day rate £700 and 90th percentile £840 for the six months to 3 September 2026, from a sample of nine daily rates across ten matching adverts, as cited on the Goldline pricing page.
- Atoro published TrustOps pricing, atoro.io/pricing, read 1 September 2026. Page states prices last reviewed 5 August 2026. Cited because they publish, which is uncommon and useful to buyers.
- ISO catalogue entry for ISO/IEC 42006:2025, requirements for bodies providing audit and certification of artificial intelligence management systems, first edition, July 2025. Read 1 September 2026. ISO sells this standard rather than publishing it, so audit duration requirements are not publicly readable.
- ISO/IEC 42001:2023 was published in December 2023.
- No figure is given here for certification body fees, because no UKAS-accredited certification body publishes one.
Alfred Obeng
Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.
Related reading
7 min read
Who Can Issue an ISO 42001 Certificate in the UK?
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Anyone can issue a certificate. Accredited certification is a different thing, it was unavailable for twenty five months, and no published list stays current. How to check the register yourself.
- ISO 42001
- Certification
- UKAS
- AI Governance
8 min read
Can the Consultancy That Built Your AIMS Also Audit It?
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.
- ISO 42001
- Internal Audit
- Certification
- AI Governance
6 min read
Readiness Assessment, Internal Audit, Certification Audit: Three Different Things
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.
- Certification
- Internal Audit
- ISO 27001
- ISO 42001
11 min read
ISO 27001 vs ISO 42001: What Each Standard Actually Governs
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The practical difference between an information security management system and an AI management system, where the controls overlap, and which one to implement first.
- ISO 42001
- ISO 27001
- AI Governance
