
The most expensive part of ISO 42001 is not the audit. It is the internal working time that nobody budgeted for. The cost of ISO 42001 falls into three blocks, and the best known of them, the certificate, is the least urgent one. That is the short answer to a question that is coming up in many management meetings right now, usually right after someone has asked whether the company needs an AI certificate.
Hardly any Swiss SME is asked by a customer for an ISO 42001 certificate today. The standard has been published since December 2023, and the first certificates are held by the large tech providers, not by Swiss mid-sized companies. What you need today is the substance behind it: an inventory of your AI usage, a policy, a risk assessment. That costs far less than a certification project. And you need it regardless of whether an auditor ever shows up.
The three cost blocks of ISO 42001
Before you talk about amounts, you have to know what you are paying for in the first place. With ISO 42001 there are three blocks, the same mechanics as with every certifiable management system standard.
Block 1: the build. The AI management system itself. Concretely: an inventory of all AI systems in the company, a policy for working with AI, a risk assessment per system, defined processes for introducing new tools, responsibilities and training. The largest part of this is internal working time, not an external invoice. Someone has to talk to the departments to find out which tools are in use, including the ones that were never officially introduced. Someone has to decide which data may go into which tool, and defend that decision in front of the executive team. Someone has to tailor the policy to your operation. That is exactly why this block gets underestimated in budget discussions again and again: it appears on no quote.
Block 2: the support. External help with the build, from selective advice to full guidance. Optional, but in practice the difference between a system that fits the company and a folder of templates that nobody lives. Your own share of the work decides the price here. A rule of thumb from our ISMS projects: What your people work out and decide themselves costs less and also survives the consultant leaving.
Block 3: the audit. A certification audit in two stages, then annual surveillance audits and recertification after three years. This is the block most people think of first. It is recurring, but it is not the largest. And it is the only one of the three that you can safely postpone.
On top of that comes a fourth item that appears on no cost overview: operations. An AI inventory goes stale faster than any classic asset inventory, because new tools keep appearing in the departments, and each of them needs to be assessed before it sees company data. A management system that goes into the cupboard after the audit was therefore the most expensive option of all: you paid for the build and still have to repeat it for the next audit.
The biggest saving lever: do not build a second management system
The most expensive decision around ISO 42001 is made right at the start, and it has nothing to do with the auditor. It is the decision to build a separate, second management system for AI governance next to the ISMS.
ISO 42001 follows the same harmonized structure as ISO 27001. Context, leadership, planning, support, operation, evaluation, improvement: the chapters are built identically. If you run an ISMS, you already have document control, a risk methodology, internal audits and the management review. ISO 42001 as an extension means: these processes are reused, and only the AI-specific parts are added, such as the impact assessment for AI systems and the controls over their lifecycle. We took apart what the difference between the two standards means in substance in our post ISO 42001 vs ISO 27001.
Two separate systems, on the other hand, mean: duplicate documents, duplicate internal audits, duplicate reviews, two audit cycles. That doubles the build and then the operations, every single year.
If you do not have an ISMS yet, the order is clear: do not start with ISO 42001. Information security carries AI governance, not the other way around. And if both are on the table, plan them as one system with two scopes, not as two projects. The groundwork that carries both is the same anyway: knowing which data you have and how sensitive it is. Without data classification, the question of which data may go into which AI tool remains pure gut feeling.
Do you need the certificate at all?
Now to the question that comes before any cost calculation and that hardly any provider who sells certifications will ask you.
Who demands an ISO 42001 certificate today? In our experience: almost nobody. The security questionnaires of enterprise procurement teams ask for ISO 27001, some of them have for years. ISO 42001 only appears there occasionally, usually as a general question about AI governance, not as a certificate requirement. No Swiss law demands an AI certificate, and the EU AI Act does not prescribe ISO 42001 certification either.
You still need the work behind it. The pressure for that comes from everyday operations: your people have long been using ChatGPT and Copilot, with or without rules. Why that policy should not wait for a law is covered in our post Do we need an AI policy? The certificate is the proof of this work. It is not the work.
This leads to a simple decision rule. The certificate is worth it if one of two conditions is met: a specific customer or tender demands it, or you sell AI as part of your product and the credential opens deals you would not get otherwise.
The second case is the more interesting one, because you can run the numbers on it. A software company that sells AI features to its enterprise customers answers questions about AI governance in every procurement process. Today, documented processes are usually enough as an answer. As soon as the first competitor shows up with a certificate, the bar shifts, and then the certificate is no longer a compliance item but a sales argument with a price tag. For that scenario, the calculation is worth doing. For an SME that only uses AI internally, in our experience it is not worth it yet.
If neither applies, build the substance and postpone the audit. A management system that is lived can be certified later without drama. One that was built only for the audit you pay for twice: once for the build and once for the repair when it gets serious.
What can honestly be said about the amounts
This would be the place for a price table. We are leaving it out on purpose.
ISO 42001 is young. Audit capacity at the certification bodies is only building up, there are few completed projects in the SME segment and accordingly little reliable market pricing. Anyone who quotes you a fixed price for «ISO 42001 complete» today, before having seen your AI inventory, is guessing. You are allowed to tell them exactly that.
What can be said seriously are the three drivers through which you control the cost yourself:
- The scope. An SME that uses M365 Copilot and two SaaS tools with AI features is a different project from a software company that trains its own model and sells it as a product. The number and criticality of the AI systems determine the effort more than the company size does.
- The existing ISMS. The lever from the previous section. With an ISMS you build an extension, without one you build a foundation plus a house.
- Your own share of the work. Internal working time is the largest and most underestimated item in every management system. In our experience from ISMS builds, the same holds for AI governance, because the answers to the uncomfortable questions (which data flows into which tool, who carries the responsibility) are ones no consultant can take off your hands.
If you want to collect quotes anyway, at least make them comparable. Have the build, the support and the audit listed separately, ask for the annual cost of the surveillance audits along with it, and ask the certification body how many ISO 42001 audits it has already carried out in the SME segment. That last question is uncomfortable. But it tells you more about how your audit will go than any price list.
For a sense of the order of magnitude, the way of thinking from our post on ISO 27001 cost helps, and it applies here one to one: the certificate is the cheapest part. The real budget sits in the work before it and the operations after it.
Calculate without the certificate first
Before you request a quote for certification, answer three questions. They cost you an afternoon, not a consulting invoice.
First: Which AI tools are in use at your company? One page is enough to start, with the tool, its purpose and the data that flows into it. Second: Does anyone actually demand a certificate from you? Read the latest security questionnaires and the contracts of your largest customers before you answer that. Third, if you have an ISMS: What would ISO 42001 mean as an extension? That belongs on the agenda of your next management review, not in a separate project.
With these three answers you can talk about ISO 42001 cost, not before. This is exactly the assessment we do with our clients as part of our AI governance work: first the inventory and the obligation question, then the decision on the certification path. If you want an outside view on this, get in touch for a first conversation, no strings attached.
One thing interests us in particular: Has a customer ever concretely asked you for an AI certificate?




