Pricoris

ISO 42001 Certification in India: Cost, Timeline and Whether You Actually Need It

ISO/IEC 42001 certification is voluntary in India. For most organisations it takes three to eight months to reach audit readiness. Implementation costs about INR 5 lakh to INR 18 lakh, and certification bodies charge about INR 1.5 lakh to INR 10 lakh for the first year. Where an organisation falls in those ranges depends on three things: how many AI systems are in scope, whether it builds AI or deploys tools built by others, and whether records of those systems’ life cycle and data already exist.

The question now more often arrives from outside the organisation than from within it. An enterprise customer’s due diligence questionnaire asks how AI is governed. A client in Europe asks what assurance you can give ahead of the EU AI Act. A board member reads about an AI failure at a competitor and asks what would happen here. ISO/IEC 42001, published in December 2023, is the first international standard for AI management systems against which an organisation can be independently certified. That is why it has become the default answer to all three.

This guide sets out what certification involves, how long it takes, what it costs and why, and when we would advise you not to pursue it yet.

Part One: Two different things called “ISO 42001 certification”

Searches for ISO 42001 certification in Mumbai, Delhi or Chennai mix two quite different needs.

The first is certification of an organisation. An accredited certification body audits your AI management system and, if it conforms, issues a certificate for a defined scope. This is what customers mean when they ask whether you are ISO 42001 certified.

The second is certification of a person. An individual completes a lead implementer or lead auditor course and passes an examination. The certificate belongs to that person, not their employer, and it proves competence to build or audit a management system, not that any organisation has one.

Both are useful, but they are not interchangeable. An organisation that sends two staff on a lead implementer course has not begun its own certification. The rest of this guide is about the first kind. If you are looking for the second, our ISO 42001 training page sets out the course options.

Part Two: What the standard asks for, and why it is counted per system

ISO/IEC 42001 follows the same management system structure as ISO 27001. Its framework requirements apply to the whole organisation: an AI policy, defined roles, a method for assessing AI risk, internal audit and management review. Existing procedures for incident management, supplier management, change management and risk assessment can usually be extended rather than rewritten. An organisation with a working ISO 27001 system starts this part well ahead.

The larger part of the work, however, is done system by system. For each AI system in scope, the standard expects its own set of records:

  • an intake record, made when the system is proposed or acquired;
  • an AI risk assessment and an AI system impact assessment;
  • a system card describing what the system does, its limits, and who is accountable for it;
  • an entry in the AI resource register, including the data the system uses;
  • verification and validation records from before release;
  • data quality and data provenance records.

Ten AI systems mean ten sets. This one fact explains most of the variation in timeline and cost described below.

ISO 42001 framework built once for the organisation, and a set of seven records built again for every AI system in scope
The framework is built once. The records are built again for every AI system, and the type of system decides how heavy each set is.

Part Three: Six types of AI system, and why the type matters

Not every set of records is equally heavy. We sort AI systems into six types, because the type decides where the effort concentrates.

TypeWhat it isWhere the effort concentrates
1. Assistants that answerRetrieval grounded systems that answer questions within a domain, such as an HR policy or contracts assistantControlling the sources the system draws on, and testing that its answers are accurate and stay within the domain
2. Agents that take actionSystems that carry out steps in live workflows or infrastructure within set thresholdsVerification before release, the thresholds and human override, and logs of what the agent actually did
3. Judgements about peopleOutputs that affect the rights or standing of identifiable people or parties, such as screening or evaluationThe heaviest impact assessment, testing for unfair outcomes, and human review of decisions
4. Forecasts for leadershipPredictive analytics whose numbers steer significant decisionsModel validation, monitoring for drift, and making the limits clear to the people who rely on the numbers
5. Embedded, consumer facingAI inside a product used by people who may not know AI is involvedTelling users what they are dealing with, and handling complaints and incidents from outside the organisation
6. Platform and enablementYou provide the infrastructure, and the customer builds and runs the modelDrawing the line of responsibility with customers, and the controls on your side of that line

Where several systems share a type and work the same way, for example the same assistant deployed in several departments, some records can be prepared once for the group. The assessments must still reflect how each system is actually used.

Part Four: How long ISO 42001 certification takes

Between three and eight months to reach audit readiness. The difference is almost entirely about evidence rather than effort. The framework can be built in weeks. What cannot be built quickly is the record of how your AI systems have actually been developed and run.

Two groups of records decide the timeline:

  • The AI system life cycle: evidence that each system was verified and validated before release and is monitored in operation, with the technical documentation to show it.
  • Data governance: records of where training and operational data came from, the quality checks applied to it, and how it was prepared.

Where these records exist, the rest of the management system can be built on top of them, and three months is realistic. Where they do not, they have to be created and then allowed to accumulate before an auditor will rely on them. That is what carries a programme towards eight months.

For organisations that use AI rather than build it, the question changes shape. The development records sit with the vendor. Your evidence is the due diligence you performed on the supplier, the validation you did before putting the tool into your own processes, and the monitoring you do in use. How much the vendor is willing to disclose then becomes the main variable. In one professional services firm we worked with, the core system was a sector-specific SaaS tool, and alongside it staff were using the free edition of a mainstream productivity assistant. Neither vendor’s model could be examined, so the work lay in supplier due diligence, and in configuring the free assistant properly before it could sit within scope.

Where you startTypical time to audit readiness
Life cycle and data records already exist and are currentAbout 3 months
Records exist in part, scattered across teams and tools4 to 6 months
Little documented evidence, so records must be created and allowed to run6 to 8 months

The two-stage certification audit follows, and its dates depend on the certification body’s calendar.

Part Five: What ISO 42001 certification costs

Two costs make up the first year: implementation, and the certification body’s audit. In our experience, implementation runs from about INR 5 lakh to about INR 18 lakh. Certification bodies charge from about INR 1.5 lakh to INR 10 lakh for the first year, depending on the tier of the body. Smaller surveillance audits follow in the second and third years.

The implementation fee is driven, more than anything else, by the number of AI systems in scope, because each one needs its own set of records. The second driver is whether you build AI or deploy it. An organisation deploying one or two third-party or SaaS tools, with its records already in order, sits at the lower end. An organisation designing and training its own models across several functions, with records still to be created, sits at the upper end.

What drives the feeTowards INR 5 lakhTowards INR 18 lakh
AI systems in scopeOne or twoMany, across functions
How you use AIDeploying third-party or SaaS toolsDesigning and building your own models
Types of systemMostly assistants that answerAgents, judgements about people, consumer facing
Life cycle and data recordsAlready existHave to be created
Certification body, first yearFrom about INR 1.5 lakhUp to about INR 10 lakh

Part Six: When we advise a client not to certify yet

When nobody is asking for it. If no customer, regulator or investor wants to see a certificate, an AI policy, an inventory of AI systems and a risk assessment for each give most of the protection at a fraction of the cost. Certification can follow when the demand does.

When you cannot yet list your AI systems. The inventory comes first. Certifying an incomplete scope pays for an audit that tells you little.

When your only AI systems are vendor tools and the vendors will not share documentation. The programme will stall on evidence, so fix the supplier contracts first.

Two cases from our practice

Two systems, built before the paperwork

A multinational consulting firm had two AI systems in scope. The first was a retrieval based assistant, connected to Microsoft Teams, that answered policy questions and raised IT tickets. The second was an internal platform on which staff could bring and deploy their own code. Development had begun well before any AI governance existed, so much of the documentation had to be written after the fact. Because the underlying test and operating data existed, and there were only two systems, the programme was ready within two to three months.

Sixty use cases, and no single list

A mining and manufacturing group asked us to assess its AI portfolio against its own group AI policy. Across eight functions it had close to sixty use cases, from predictive maintenance models to agents in procurement, finance and HR, and different trackers gave different counts of what was live. AI embedded in licensed enterprise software had not been inventoried at all. Of the systems examined in depth, one recommended payments to individual workers and had been tested on three cases, with no check that it treated different groups consistently. Another, a legal research assistant, had produced fabricated answers in use but had never been formally tested for it.

None of this is unusual. It is what a first assessment of an AI portfolio typically finds, and it is why the inventory, not the certificate, is the first step.

Closing

ISO 42001 rewards organisations that already know what AI they run and keep records of how it behaves. For them, certification is a matter of months and a moderate fee. For everyone else, the first and most valuable step is the inventory, and it is worth taking whether or not a certificate follows. How we run an implementation is set out on our ISO 42001 consulting page.

Not sure whether you need certification or a policy? Book a 30 minute ISO 42001 readiness call. We will tell you which, and roughly what it would take.

Frequently asked questions

Is ISO 42001 certification mandatory in India?

No. No Indian law currently requires it. Organisations pursue it because customers, overseas clients or boards ask for independent assurance on how AI is governed.

How long does ISO 42001 certification take?

Three to eight months to reach audit readiness for most organisations, followed by the two-stage certification audit. The main variable is whether life cycle and data records already exist for each AI system.

How much does ISO 42001 certification cost in India?

Implementation costs from about INR 5 lakh to about INR 18 lakh, plus certification body fees of about INR 1.5 lakh to INR 10 lakh for the first year. The number of AI systems in scope is the biggest driver.

Can we get ISO 42001 certification if we only use third-party AI tools?

Yes. The scope covers how you use AI. Your evidence is supplier due diligence, validation before deployment and monitoring in use. Organisations in this position usually sit at the lower end of the cost range.

Does an existing ISO 27001 certificate help?

Yes, for the framework: the management system structure is shared, and procedures such as incident, supplier and change management can be extended. It does not supply the records for individual AI systems, which is where most of the work sits.

Is a lead implementer certificate the same as ISO 42001 certification?

No. A lead implementer certificate shows that a person is competent to build an AI management system. ISO 42001 certification shows that an organisation has one, and has been audited against the standard.


Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that implements AI management systems. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. Indicative cost figures reflect our consulting experience and market observation, and will vary with scope and readiness. This article is general commentary on ISO/IEC 42001:2023 and is not legal advice. Last reviewed 22 September 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top