Why most small NGOs and foundations should not pursue ISO/IEC 42001 certification, and which parts of the AI management system standard are worth borrowing as a structural checklist.
A few pieces ago, this series argued that an organisation should never call its own governance file "certified" unless an actual accreditation body issued that certification. This piece looks at the one place a genuine, internationally recognised certification for AI governance does exist: ISO/IEC 42001, the international standard for AI management systems, published in 2023. Most organisations this series is written for will never actually pursue that certification. Third-party audits and formal accreditation carry a real cost, proportionate for a large regulated company or a vendor whose enterprise clients demand it contractually, disproportionate for a small NGO or foundation.
None of that makes the standard itself useless. Even entirely unadopted, ISO/IEC 42001 is a genuinely useful document to borrow structure from, and this piece sets out what is worth taking and what is not, for an organisation with no intention of ever sitting through an external audit.
It is an international standard setting out requirements for an AI management system, built on the same high-level structure other ISO management-system standards share, the same family that produced ISO 27001 for information security. In practical terms, it asks an organisation to define an AI policy, assign clear roles and responsibilities, run risk and impact assessments specific to its AI systems, govern the data feeding those systems, document its decisions, and review the whole system on a regular cycle. Anyone following this series will recognise that structure immediately, because it maps closely onto the policy, tool inventory, and review cycle this series has already built piece by piece. This is a general description rather than a substitute for the published standard itself, and any organisation seriously weighing certification should work from the current official text.
Formal certification means external auditors, a recurring audit cycle, and a genuine financial cost that only makes sense when someone specific is actually asking for the certificate. An earlier piece in this series mapped what an auditor, a board and a funder each actually ask for, and none of the three typically demands an ISO certificate by name. A board wants risk and accountability. A funder wants reassurance that practice matches what was represented. An auditor wants a paper trail. A certification badge answers a question nobody in that list was actually asking, which is exactly why the cost rarely earns its place for an organisation this size.
Certification asks whether an external auditor agrees with the file. Borrowing the structure asks whether the organisation's own governance actually holds up. For an organisation this size, the second question is the one that matters.
The calculus changes the moment a real external party starts asking for it by name. If a major institutional funder or a UN agency partner begins contractually requiring ISO/IEC 42001 certification as a condition of a grant or partnership, in the way some funders already require ISO 27001 or an equivalent for data security, formal certification stops being a nice-to-have and becomes a genuine, cost-justified decision. Until that specific ask arrives, borrowing the structure delivers most of the value the standard offers, at a fraction of the cost.
Treat ISO/IEC 42001 as a structural checklist to borrow from, roles, risk assessment, documentation, review cycle, rather than a certification to pursue, and revisit that decision only if a specific funder or partner begins requiring the certificate by name.
No external statistic cited; this article presents a general, high-level description of ISO/IEC 42001's structure rather than a substitute for the published standard. Organisations weighing certification should confirm current requirements against the official ISO text or a qualified adviser.
Why an internally maintained AI governance file should be called documentation, not certification: the precise label survives follow-up questions from boards, funders and auditors, and matches what the law asks.
AI Use Policy · 4 minAnalysis · 28 September 2026Auditors, boards and funders ask to see your AI governance file for different reasons; keep one evidence file but prepare a short cover framing for each audience.
AI Use Policy · 4 minFramework · 27 September 2026A practical trigger test for when an AI use case needs a data protection impact assessment, so a DPO does a few properly instead of running one on everything or none at all.
AI Use Policy · 4 minIf this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.