ISO/IEC 42001 certification is voluntary in India. For most organisations it takes three to eight months to reach audit readiness. Implementation costs about INR 5 lakh to INR 18 lakh, and certification bodies charge about INR 1.5 lakh to INR 10 lakh for the first year. Where an organisation falls in those ranges depends on three things: how many AI systems are in scope, whether it builds AI or deploys tools built by others, and whether records of those systems’ life cycle and data already exist.
The question now more often arrives from outside the organisation than from within it. An enterprise customer’s due diligence questionnaire asks how AI is governed. A client in Europe asks what assurance you can give ahead of the EU AI Act. A board member reads about an AI failure at a competitor and asks what would happen here. ISO/IEC 42001, published in December 2023, is the first international standard for AI management systems against which an organisation can be independently certified. That is why it has become the default answer to all three.
This guide sets out what certification involves, how long it takes, what it costs and why, and when we would advise you not to pursue it yet.
Part One: Two different things called “ISO 42001 certification”
Searches for ISO 42001 certification in Mumbai, Delhi or Chennai mix two quite different needs.
The first is certification of an organisation. An accredited certification body audits your AI management system and, if it conforms, issues a certificate for a defined scope. This is what customers mean when they ask whether you are ISO 42001 certified.
The second is certification of a person. An individual completes a lead implementer or lead auditor course and passes an examination. The certificate belongs to that person, not their employer, and it proves competence to build or audit a management system, not that any organisation has one.
Both are useful, but they are not interchangeable. An organisation that sends two staff on a lead implementer course has not begun its own certification. The rest of this guide is about the first kind. If you are looking for the second, our ISO 42001 training page sets out the course options.
Part Two: What the standard asks for, and why it is counted per system
ISO/IEC 42001 follows the same management system structure as ISO 27001. Its framework requirements apply to the whole organisation: an AI policy, defined roles, a method for assessing AI risk, internal audit and management review. Existing procedures for incident management, supplier management, change management and risk assessment can usually be extended rather than rewritten. An organisation with a working ISO 27001 system starts this part well ahead.
The larger part of the work, however, is done system by system. For each AI system in scope, the standard expects its own set of records:
- an intake record, made when the system is proposed or acquired;
- an AI risk assessment and an AI system impact assessment;
- a system card describing what the system does, its limits, and who is accountable for it;
- an entry in the AI resource register, including the data the system uses;
- verification and validation records from before release;
- data quality and data provenance records.
Ten AI systems mean ten sets. This one fact explains most of the variation in timeline and cost described below.

Part Three: Six types of AI system, and why the type matters
Not every set of records is equally heavy. We sort AI systems into six types, because the type decides where the effort concentrates.
| Type | What it is | Where the effort concentrates |
|---|---|---|
| 1. Assistants that answer | Retrieval grounded systems that answer questions within a domain, such as an HR policy or contracts assistant | Controlling the sources the system draws on, and testing that its answers are accurate and stay within the domain |
| 2. Agents that take action | Systems that carry out steps in live workflows or infrastructure within set thresholds | Verification before release, the thresholds and human override, and logs of what the agent actually did |
| 3. Judgements about people | Outputs that affect the rights or standing of identifiable people or parties, such as screening or evaluation | The heaviest impact assessment, testing for unfair outcomes, and human review of decisions |
| 4. Forecasts for leadership | Predictive analytics whose numbers steer significant decisions | Model validation, monitoring for drift, and making the limits clear to the people who rely on the numbers |
| 5. Embedded, consumer facing | AI inside a product used by people who may not know AI is involved | Telling users what they are dealing with, and handling complaints and incidents from outside the organisation |
| 6. Platform and enablement | You provide the infrastructure, and the customer builds and runs the model | Drawing the line of responsibility with customers, and the controls on your side of that line |
Where several systems share a type and work the same way, for example the same assistant deployed in several departments, some records can be prepared once for the group. The assessments must still reflect how each system is actually used.
Part Four: How long ISO 42001 certification takes
Between three and eight months to reach audit readiness. The difference is almost entirely about evidence rather than effort. The framework can be built in weeks. What cannot be built quickly is the record of how your AI systems have actually been developed and run.
Two groups of records decide the timeline:
- The AI system life cycle: evidence that each system was verified and validated before release and is monitored in operation, with the technical documentation to show it.
- Data governance: records of where training and operational data came from, the quality checks applied to it, and how it was prepared.
Where these records exist, the rest of the management system can be built on top of them, and three months is realistic. Where they do not, they have to be created and then allowed to accumulate before an auditor will rely on them. That is what carries a programme towards eight months.
For organisations that use AI rather than build it, the question changes shape. The development records sit with the vendor. Your evidence is the due diligence you performed on the supplier, the validation you did before putting the tool into your own processes, and the monitoring you do in use. How much the vendor is willing to disclose then becomes the main variable. In one professional services firm we worked with, the core system was a sector-specific SaaS tool, and alongside it staff were using the free edition of a mainstream productivity assistant. Neither vendor’s model could be examined, so the work lay in supplier due diligence, and in configuring the free assistant properly before it could sit within scope.
| Where you start | Typical time to audit readiness |
|---|---|
| Life cycle and data records already exist and are current | About 3 months |
| Records exist in part, scattered across teams and tools | 4 to 6 months |
| Little documented evidence, so records must be created and allowed to run | 6 to 8 months |
The two-stage certification audit follows, and its dates depend on the certification body’s calendar.
Part Five: What ISO 42001 certification costs
Two costs make up the first year: implementation, and the certification body’s audit. In our experience, implementation runs from about INR 5 lakh to about INR 18 lakh. Certification bodies charge from about INR 1.5 lakh to INR 10 lakh for the first year, depending on the tier of the body. Smaller surveillance audits follow in the second and third years.
The implementation fee is driven, more than anything else, by the number of AI systems in scope, because each one needs its own set of records. The second driver is whether you build AI or deploy it. An organisation deploying one or two third-party or SaaS tools, with its records already in order, sits at the lower end. An organisation designing and training its own models across several functions, with records still to be created, sits at the upper end.
| What drives the fee | Towards INR 5 lakh | Towards INR 18 lakh |
|---|---|---|
| AI systems in scope | One or two | Many, across functions |
| How you use AI | Deploying third-party or SaaS tools | Designing and building your own models |
| Types of system | Mostly assistants that answer | Agents, judgements about people, consumer facing |
| Life cycle and data records | Already exist | Have to be created |
| Certification body, first year | From about INR 1.5 lakh | Up to about INR 10 lakh |
Part Six: When we advise a client not to certify yet
When nobody is asking for it. If no customer, regulator or investor wants to see a certificate, an AI policy, an inventory of AI systems and a risk assessment for each give most of the protection at a fraction of the cost. Certification can follow when the demand does.
When you cannot yet list your AI systems. The inventory comes first. Certifying an incomplete scope pays for an audit that tells you little.
When your only AI systems are vendor tools and the vendors will not share documentation. The programme will stall on evidence, so fix the supplier contracts first.
Two cases from our practice
Two systems, built before the paperwork
A multinational consulting firm had two AI systems in scope. The first was a retrieval based assistant, connected to Microsoft Teams, that answered policy questions and raised IT tickets. The second was an internal platform on which staff could bring and deploy their own code. Development had begun well before any AI governance existed, so much of the documentation had to be written after the fact. Because the underlying test and operating data existed, and there were only two systems, the programme was ready within two to three months.
Sixty use cases, and no single list
A mining and manufacturing group asked us to assess its AI portfolio against its own group AI policy. Across eight functions it had close to sixty use cases, from predictive maintenance models to agents in procurement, finance and HR, and different trackers gave different counts of what was live. AI embedded in licensed enterprise software had not been inventoried at all. Of the systems examined in depth, one recommended payments to individual workers and had been tested on three cases, with no check that it treated different groups consistently. Another, a legal research assistant, had produced fabricated answers in use but had never been formally tested for it.
None of this is unusual. It is what a first assessment of an AI portfolio typically finds, and it is why the inventory, not the certificate, is the first step.
Closing
ISO 42001 rewards organisations that already know what AI they run and keep records of how it behaves. For them, certification is a matter of months and a moderate fee. For everyone else, the first and most valuable step is the inventory, and it is worth taking whether or not a certificate follows. How we run an implementation is set out on our ISO 42001 consulting page.
Not sure whether you need certification or a policy? Book a 30 minute ISO 42001 readiness call. We will tell you which, and roughly what it would take.
Frequently asked questions
No. No Indian law currently requires it. Organisations pursue it because customers, overseas clients or boards ask for independent assurance on how AI is governed.
Three to eight months to reach audit readiness for most organisations, followed by the two-stage certification audit. The main variable is whether life cycle and data records already exist for each AI system.
Implementation costs from about INR 5 lakh to about INR 18 lakh, plus certification body fees of about INR 1.5 lakh to INR 10 lakh for the first year. The number of AI systems in scope is the biggest driver.
Yes. The scope covers how you use AI. Your evidence is supplier due diligence, validation before deployment and monitoring in use. Organisations in this position usually sit at the lower end of the cost range.
Yes, for the framework: the management system structure is shared, and procedures such as incident, supplier and change management can be extended. It does not supply the records for individual AI systems, which is where most of the work sits.
No. A lead implementer certificate shows that a person is competent to build an AI management system. ISO 42001 certification shows that an organisation has one, and has been audited against the standard.
Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that implements AI management systems. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. Indicative cost figures reflect our consulting experience and market observation, and will vary with scope and readiness. This article is general commentary on ISO/IEC 42001:2023 and is not legal advice. Last reviewed 22 September 2026.