Wie erhält man eine ISO-Zertifizierung?
The editing instructions ask for a German translation, but the language rules in this task require the entire output to be in English. The reminder also explicitly states „The article is in English.“ I must follow the system rules and keep the article in English. I will return the article as-is, since no English-language edits are specified.You get ISO-certified by building a management system that meets the requirements of a specific ISO standard, engaging an accredited certification body, and successfully completing a multi-stage audit. The process applies to organisations of any size and industry. The following sections answer the most important questions about standards, prerequisites, process, duration, costs, and validity.
Which ISO standards are relevant for certification?
The choice of the right ISO standard depends on the area an organisation wants to certify. The best-known standards include ISO 9001 for quality management, ISO 27001 for information security, and the relatively new ISO/IEC 42001 for AI management systems. Each standard defines minimum requirements for a specific management system.
ISO/IEC 42001 is particularly relevant for organisations that use or develop artificial intelligence. It is the first internationally recognised standard for establishing and operating AI management systems (AIMS). A certificate under this standard confirms that an organisation has defined, established, and continuously improved the necessary framework for safe, effective, and responsible AI use.
Other relevant standards in the AI space are:
- ISO/IEC 42006:2025 – Requirements for certification bodies conducting AIMS audits
- ISO/IEC 42005:2025 – AI system impact assessment
- ISO/IEC 23894:2023 – AI risk management
- ISO/IEC 38507:2022 – AI governance at the organisational level
Which standard fits best depends on your strategic direction, regulatory requirements, and stakeholder expectations. For organisations keeping an eye on the EU AI Act, ISO/IEC 42001 provides a particularly solid foundation.
What are the prerequisites for ISO certification?
The central prerequisite for ISO certification is a functioning management system that meets the requirements of the relevant standard. This includes documented policies and processes, clearly defined responsibilities, and evidence of continuous improvement through the PDCA cycle.
Specifically, an organisation should ensure the following points before the certification audit:
- A fully documented management system is in place
- Internal audits have been conducted and evaluated
- A gap analysis shows where the organisation stands relative to the standard
- Management is actively involved and has formally confirmed the system’s objectives
- Employees with relevant responsibilities are sufficiently qualified and trained
For ISO/IEC 42001, this additionally means: the organisation must demonstrate that it systematically assesses AI-specific risks and opportunities, implements control measures, and has built the necessary AI competencies within the team. An internal conformity review — for example through an ISO 42001 gap analysis — is not strictly mandatory, but is strongly recommended.
How does the ISO certification process work, step by step?
The ISO certification process follows a clearly structured sequence: select a certification body, define the scope, conduct an internal assessment, complete the two-stage certification audit, and receive the certificate. This process applies in essentially the same way to all ISO management system standards, including ISO/IEC 42001.
In detail, the path to certification looks like this:
- Select a certification body: The chosen body must be accredited. For ISO/IEC 42001, certification bodies must meet the standards ISO/IEC 17021-1 and ISO/IEC 42006. It is worth submitting an application early, as capacity may be limited.
- Define the certification scope: The so-called scope statement defines which areas, locations, and processes of the organisation are to be certified.
- Conduct an internal assessment: A gap analysis compares the current state of the management system with the standard’s requirements and identifies open items.
- Certification audit stage 1: The certification body reviews the documentation and determines whether the organisation is ready for the actual audit.
- Certification audit stage 2: The actual conformity and effectiveness of the management system are verified on-site or remotely.
- Certificate issuance: Upon a successful audit, the certification body issues the certificate.
If nonconformities are identified during stage 2, the organisation must resolve them within an agreed timeframe before the certificate is issued.
How long does it take to obtain ISO certification?
The time it takes to achieve ISO certification depends heavily on how far the management system has already been developed. Organisations building from scratch typically need six to twelve months. Those who already operate a similar system can significantly shorten the process.
Key factors that influence the timeframe:
- Maturity of the existing system: The more requirements already met, the shorter the preparation phase.
- Size and complexity of the organisation: More locations, processes, and employees mean more effort in documentation and internal audits.
- Availability of the certification body: Appointments may need to be booked several weeks in advance depending on demand.
- Speed of resolving nonconformities: Identified gaps must be closed before the certificate is issued.
For ISO/IEC 42001 specifically: since this is a comparatively new standard, finding a suitable, accredited certification body may take additional time.
What does ISO certification cost?
The costs of ISO certification consist of several components and vary considerably depending on the standard, the size of the organisation, and the chosen certification body. Broadly, three cost areas can be distinguished: preparation, audit fees, and ongoing surveillance costs.
Preparation costs
These include internal efforts for building the management system, employee training, and optional external support through audits or gap analyses. Training costs are particularly relevant for ISO/IEC 42001, as specific AI competencies must be demonstrated. Those who want to prepare their team specifically for the standard’s requirements will find suitable training offerings for various qualification levels.
Certification body audit fees
The actual audit fees are based on the effort involved in the certification audit, which is determined by the size of the organisation and the extent of the scope. Certification bodies typically charge by audit day. For smaller organisations, the pure audit costs may be in the low four-figure range; for larger organisations, significantly more.
Ongoing costs
After initial certification, annual surveillance audits are required, which also carry a fee. However, these are generally less expensive than the initial certification audit.
How long is an ISO certificate valid and how is it renewed?
An ISO certificate is generally valid for three years. After this period, a recertification audit must be completed to renew the certificate. In the intervening years, annual surveillance audits take place to ensure the ongoing conformity of the management system.
The cycle looks like this in concrete terms:
- Year 1: Initial certification, the certificate is issued
- Year 2: First surveillance audit
- Year 3: Second surveillance audit
- Year 4: Recertification audit to renew the certificate
Surveillance audits are not a mere formality. They verify whether the management system continues to be operated effectively, whether internal audits have taken place, and whether the continuous improvement process is actively being lived. In the case of serious nonconformities, a certificate can be suspended or withdrawn before the three years are up.
For ISO/IEC 42001, the same three-year validity principle applies. Since the field of AI governance and regulatory requirements is currently evolving rapidly, it is especially important to continuously adapt the AIMS to new requirements rather than waiting until just before the recertification audit.
How mITSM supports you on the path to ISO certification
We at mITSM support professionals, managers, and organisations in building the knowledge needed for successful ISO certification. Our offering around ISO/IEC 42001 includes:
- Training and certifications for the ISO 42001 AI Officer and AI Manager roles, available as in-person seminars, online live training, or in-house corporate training
- Internal audits and gap analyses based on ISO/IEC 42001, which quickly and cost-effectively measure the degree of conformity, identify gaps in the AIMS, and deliver a concrete action plan for certification readiness
- Personal certifications via ICO-Cert as a recognised certification partner for AI topics, which concretely increase your market value in the job market
- Experienced practitioners as trainers, who are active experts in AI management and convey the standard’s requirements in an understandable and applicable way
Whether you are just starting out or already close to your audit: we help you take the next step with confidence. Take a look at our consulting offering or contact us directly for a free initial consultation.
Dieser Inhalt wurde mithilfe von KI erstellt und kann Fehler enthalten.