ISO/IEC 42001 has real value for some UK businesses and is the wrong answer for others. Here's how to tell which one you are before you spend anything on it.
ISO/IEC 42001 is the international standard for an AI management system, and it’s increasingly what people reach for by default when “AI governance” comes up.
It’s the right answer for some UK businesses and an expensive detour for others. Here’s how to tell which one you are before spending anything on it.
Certification to ISO 42001 is a structural answer to one specific question: can you prove, to an independent accredited body, that you have a management system governing how AI is developed, deployed and monitored.
That’s worth real money when someone external is asking, or will soon ask, exactly that question. Most commonly that’s a customer’s procurement team running due diligence on a deal, or a regulator in a sector where it’s becoming expected evidence.
It’s also a much smaller club than the marketing around it suggests. Estimates put certified organisations globally in the low hundreds as of early 2026, not thousands. There’s no official public register, so treat any precise figure, including that one, as an estimate rather than a count.
BSI became the first UKAS-accredited certification body for the standard only in January 2026, which tells you how early this still is in the UK specifically.
The clearest signal is an external trigger with a date attached:
If you’re a software company that’s added AI to a product you sell to enterprise customers, this is the situation you’re most likely to be in. Certification, or at least demonstrable readiness for it, has a direct commercial payoff here, helping you answer any due-diligence questionnaires.
If nobody outside your organisation has asked, and nothing suggests they’re about to, certification is solving a problem you don’t have yet.
The management system requirements are real ongoing costs rather than a one-off project. Internal audit, management review and continual improvement all run every year, indefinitely.
Taking that on before there’s a reason to is the expensive version of governance. A lighter internal policy and a clear owner for AI risk covers most of the actual exposure for a business that isn’t being asked to prove anything to anyone.
Two things apply whether or not you certify to anything.
UK GDPR, as amended by the Data (Use and Access) Act 2025, already covers a large part of what “AI governance” means in practice for most UK organisations: lawful basis, data minimisation, automated decision-making. Most AI governance conversations turn out to be a data protection conversation wearing an AI hat.
The EU AI Act, whose timeline has shifted more than once. The Digital Omnibus deferred the Annex III high-risk obligations to 2 December 2027, while Article 50’s transparency obligations apply from 2 August 2026. Article 50 is narrower than the headlines imply: it covers telling people they’re interacting with an AI, marking AI-generated content, notifying people exposed to emotion recognition, and labelling deepfakes. Systems already on the market get until 2 December 2026 for the machine-readable marking requirement in Article 50(2).
Most UK SMEs are out of scope of the high-risk provisions entirely. It’s worth checking which parts apply to you rather than assuming the loudest headline about the Act is the relevant one.
If the answer to that third one is yes, ISO 42001 is a sound, structured way to do it. If it’s “not yet,” the money is better spent getting the first two right.
We’re 10 Kinds, a UK AI consultancy. We map where AI is being used in a business, put governance around it, get you to the point where you can prove it to a customer or a regulator, and then build the systems that make it pay. For a straight read on whether ISO 42001 is worth it for you, book a free call, or take the free AI Readiness Checklist first.