M.A.I. Consulting
BriefingAdvanced29 September 20264 min read

ISO/IEC 42001 for organisations that will never certify

Why most small NGOs and foundations should not pursue ISO/IEC 42001 certification, and which parts of the AI management system standard are worth borrowing as a structural checklist.

A few pieces ago, this series argued that an organisation should never call its own governance file "certified" unless an actual accreditation body issued that certification. This piece looks at the one place a genuine, internationally recognised certification for AI governance does exist: ISO/IEC 42001, the international standard for AI management systems, published in 2023. Most organisations this series is written for will never actually pursue that certification. Third-party audits and formal accreditation carry a real cost, proportionate for a large regulated company or a vendor whose enterprise clients demand it contractually, disproportionate for a small NGO or foundation.

None of that makes the standard itself useless. Even entirely unadopted, ISO/IEC 42001 is a genuinely useful document to borrow structure from, and this piece sets out what is worth taking and what is not, for an organisation with no intention of ever sitting through an external audit.

What ISO/IEC 42001 actually is

It is an international standard setting out requirements for an AI management system, built on the same high-level structure other ISO management-system standards share, the same family that produced ISO 27001 for information security. In practical terms, it asks an organisation to define an AI policy, assign clear roles and responsibilities, run risk and impact assessments specific to its AI systems, govern the data feeding those systems, document its decisions, and review the whole system on a regular cycle. Anyone following this series will recognise that structure immediately, because it maps closely onto the policy, tool inventory, and review cycle this series has already built piece by piece. This is a general description rather than a substitute for the published standard itself, and any organisation seriously weighing certification should work from the current official text.

Why certification itself is rarely worth it at this size

Formal certification means external auditors, a recurring audit cycle, and a genuine financial cost that only makes sense when someone specific is actually asking for the certificate. An earlier piece in this series mapped what an auditor, a board and a funder each actually ask for, and none of the three typically demands an ISO certificate by name. A board wants risk and accountability. A funder wants reassurance that practice matches what was represented. An auditor wants a paper trail. A certification badge answers a question nobody in that list was actually asking, which is exactly why the cost rarely earns its place for an organisation this size.

What is worth borrowing without certifying

Certification asks whether an external auditor agrees with the file. Borrowing the structure asks whether the organisation's own governance actually holds up. For an organisation this size, the second question is the one that matters.

When certification might actually become worth it

The calculus changes the moment a real external party starts asking for it by name. If a major institutional funder or a UN agency partner begins contractually requiring ISO/IEC 42001 certification as a condition of a grant or partnership, in the way some funders already require ISO 27001 or an equivalent for data security, formal certification stops being a nice-to-have and becomes a genuine, cost-justified decision. Until that specific ask arrives, borrowing the structure delivers most of the value the standard offers, at a fraction of the cost.

The practical takeaway

Treat ISO/IEC 42001 as a structural checklist to borrow from, roles, risk assessment, documentation, review cycle, rather than a certification to pursue, and revisit that decision only if a specific funder or partner begins requiring the certificate by name.

No external statistic cited; this article presents a general, high-level description of ISO/IEC 42001's structure rather than a substitute for the published standard. Organisations weighing certification should confirm current requirements against the official ISO text or a qualified adviser.

Series · Standards you can use without certifying · part 1 of 3
Keep reading
01 ยท AI Readiness Assessment

Where do we stand, and what do we fix first?

If this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.