The procurement manager asks it point-blank, in front of the evaluation committee: "Are you ISO 42001 certified?" The PMO leader had prepared the schedule, the budget, the project's technical risks. Not this question. The silence lasts three seconds too long, then comes a vague answer about "internal governance processes" that convinces no one in the room.
That evening the PMO leader opens a browser and finds out ISO 42001 has existed longer than expected: the standard was published in December 2023, not in 2026 (theiso42001.com, 2026). In Europe it is being adopted as EN ISO/IEC 42001:2026, with national adoption due by September 2026. It isn't a sudden novelty launched because of the AI Act — it's a management system some companies have already been running for two years.
Many think ISO 42001 certification proves compliance with the EU AI Act. In reality it only proves that documented AI governance exists and has been verified by a third party, because legal presumption of conformity requires a harmonized CEN-CENELEC standard — such as prEN 18286 — still under development.
What ISO 42001 actually certifies (and what it doesn't)
ISO 42001 defines how an organization should manage AI systems: roles, controls, risk assessment, decision documentation. An accredited auditor checks that these processes exist and function — not that the provider satisfies every specific AI Act obligation. The technical distinction is sharp: legal presumption of conformity and evidence of good governance are two different things, achieved through two different instruments (Konfirmity, 2026-07-07).
The AWS case makes this concrete: in November 2024 it became the first major cloud provider to earn accredited ISO 42001 certification (Openlayer, 2026-06-17). That's a signal that major players are taking the standard seriously, not proof it's already a universal requirement in enterprise tenders. Confusing the two — adoption by a handful of market leaders versus a widespread obligation — is exactly the mistake that triggers unwarranted panic in the meeting room.
How much certification costs, and why the bill is never fixed
Initial certification costs vary widely depending on scope and organization size: estimates range from roughly $7,000 to over $50,000, with timelines stretching from 6 to 12 months (Openlayer, 2026-06-17). A PMO running two internal AI systems out of a single production site pays close to the minimum; a group with multiple business units and external AI vendors easily lands above $30,000.
A shortage of qualified lead auditors relative to demand pushes these costs above comparable ISO 27001 benchmarks, with longer waits to book an audit slot (Openlayer, 2026-06-17). For a PMO facing a tender deadline, this means formal certification is rarely ready in time for the first RFP that asks about it: the decision needs to be made months in advance, not as a reaction to a question in a boardroom.
Declared simulation — Simulated scenario
An R&D PMO manages five AI-assisted projects and receives an RFP requiring 'demonstrated AI governance,' without explicitly citing ISO 42001. Before starting any certification process, the team maps its existing decision logs and risk registers against the standard's Annex A controls, to measure how large the gap actually is. The result: three out of ten controls turn out to already be covered by current operational documentation, which meaningfully shrinks the scope — and cost — of a formal certification path, should the team choose to pursue one.
Trade-off
- Benefit: Third-party-verified evidence the PMO can reuse across multiple tenders, cutting the time spent manually answering every AI due-diligence questionnaire.
- Cost: An estimated budget of $7,000 to over $50,000 and a 6-12 month timeline, made worse by waits for an available lead auditor (Openlayer, 2026-06-17).
- Risk: Certification does not reduce the PMO's legal exposure under the AI Act by a single obligation: it attests to governance, not compliance, and it can go stale if the AI management approach changes after the audit.
- Prerequisite: Concrete artifacts need to already exist — decision logs, risk registers, traceable project-decision history — because without that foundation, cost and timeline stretch even further. A cockpit like ControlRoom, which keeps a deterministic history of decisions, risks and EVM data, helps organize this evidence ahead of an audit, but it does not replace or shortcut certification itself.
- Limit: Even once certified, the PMO gains no presumption of conformity under the AI Act: that legal recognition will only arrive with a harmonized CEN-CENELEC standard still under development.
A six-question framework before signing the contract with the certification body
- Does the tender literally require 'ISO 42001,' or a generic phrase like 'demonstrated AI governance'? In the second case, other evidence might be enough.
- How many Annex A controls are already covered by decision logs, risk registers and existing project documentation, before adding new processes?
- Does the available budget absorb a figure between $7,000 and over $50,000 without cutting resources from other program priorities (Openlayer, 2026-06-17)?
- Has anyone checked whether direct competitors in the same sector already hold the certification, or whether it's still a differentiator?
- Is there real time for a full audit (6-12 months) before the deadline of the tender that triggered the question, or is the team chasing a certification that will arrive too late?
- Once obtained, will the certification be reused across multiple tenders, or does it only serve to answer a single isolated request?
The author's point of view
Getting certified early feels like the prudent choice, the gesture that reassures procurement and management. But it doesn't shrink the PMO's legal exposure under the AI Act by even one obligation — it produces evidence of governance, not compliance. A PMO should treat ISO 42001 as an investment decision with explicit trade-offs — cost, time, reusability — not as a box to tick to close an awkward question in a boardroom. This article focuses on the certification decision itself, its costs and its evidence boundary. How a PMO designs governance roles and organizational controls, and how human oversight works inside AI-assisted processes, are separate questions covered elsewhere in this cluster.
Frequently asked questions
Is ISO 42001 mandatory to bid on enterprise or public contracts?
No. It's a voluntary certification. Some tenders cite it as a preferred requirement, others only ask for 'demonstrated AI governance' without naming the standard, which leaves room for alternative evidence.
Does getting certified reduce the PMO's legal obligations under the AI Act?
No. It attests that a third-party-audited AI management system exists, not legal compliance. The presumption of conformity will require a CEN-CENELEC harmonized standard, such as prEN 18286, still under development (Konfirmity, 2026-07-07).
How much time does it realistically take to prepare for an ISO 42001 audit?
Between 6 and 12 months, depending on scope and the availability of an accredited lead auditor, often scarce relative to demand (Openlayer, 2026-06-17). Teams who get the question mid-tender rarely manage to certify in time for that same deadline.
In the end, the procurement question had no right or wrong answer to give on the spot. It needed a decision process that PMO hadn't built yet. Many think ISO 42001 certification proves AI Act compliance: in reality it only proves that documented, third-party-verified AI governance exists, because the legal presumption of conformity still depends on a harmonized standard that is not yet finished. Whoever approaches the question with a framework of costs, timelines and evidence gaps answers from a position of deliberate choice, not tender-drivenpanic.
For those who want to start by mapping the evidence already available — decision logs, risk registers, traceability of project decisions — before evaluating the investment in certification, the useful next step is a structured comparison with an AI governance framework applied to existing project processes.