Certificate Issue, Scope Wording and Use of the Certification Mark
Once all non-conformities and findings have been closed and the auditor has verified that your management system operates effectively, your certification body will issue your ISO 42001 certificate. The certificate is a formal document that states your organisation’s name, the scope of systems and locations covered, the date of issue, the date of expiration and the accreditation body (UKAS or equivalent).
The wording of your scope in the certificate is important because it defines what you are certified for. If your certificate scope states “All AI systems used for internal business automation”, then you are only certified for those systems. If you later deploy an AI system for customer-facing applications and claim ISO 42001 certification for those systems, your claim is inaccurate because the certificate does not cover them.
Scope boundaries in certificates are precise. If your organisation is multi-site and the certificate includes only your London office, you cannot claim certification for your Manchester operations. If the certificate covers “Generative AI systems” and you deploy a machine learning classification system, that system is not covered. If your organisation acquires another company with different AI systems, those systems are not covered until you request a scope extension and pass an additional audit.
Your certificate scope will be publicly available if your organisation includes it in published compliance statements or marketing materials. Customers reviewing your certificate can read the scope and verify that it covers the systems they interact with or depend on. A narrow scope is not a problem; it is simply an accurate reflection of your current operations. However, a scope that does not cover systems customers expect to be covered undermines trust. This is why expanding scope at recertification is common as organisations’ AI portfolios grow.
The certification mark can be used on your website, marketing materials and proposals to indicate that your organisation is certified. However, there are rules about how the mark can be used. You cannot modify or distort the mark. You cannot use the mark to imply that products or services are certified if only your management system is certified. For example, if you develop an AI product for sale and your organisation is ISO 42001 certified, you can state that your product is developed by an ISO 42001 certified organisation, but you cannot state that the product itself is ISO 42001 certified (unless the certification body has specifically assessed and approved the product as part of your scope, which is unusual).

Certificate Validity and Surveillance
Your certificate is valid for three years from the date of issue. During this three-year period, your certification body is required to conduct surveillance audits to ensure that you are maintaining your management system. Surveillance audits are typically smaller than Stage 1 and Stage 2 audits. They occur annually or semi-annually depending on the certification body’s policy.
During surveillance audits, the auditor will sample your controls and evidence to verify that the management system continues to operate effectively. They will interview staff, review documentation and examine operational records. Surveillance audits typically take one to two days per visit. If the auditor finds that controls have deteriorated or that you have not maintained your system, they may issue a non-conformity. Repeated issues may result in suspension or withdrawal of your certificate.
Surveillance audits are not punitive visits. They are opportunities to demonstrate that your management system is alive and working. An auditor will look for evidence of continuous improvement, updated documentation and responsive management. If your system has evolved to address new risks or new AI systems, that demonstrates maturity.
If your management system remains compliant throughout the three-year validity period, you can apply for recertification at the end of year three. Recertification involves another full Stage 1 and Stage 2 audit with the same scope or an updated scope that reflects your current operations.
If significant changes occur in your business or your AI systems during your three-year certificate period, you should consider requesting a scope extension. Scope extensions allow you to add new systems or locations to your existing certificate without waiting for recertification. A scope extension typically involves an additional audit focused on the new systems or locations. The cost and timeline for a scope extension are usually less than the cost and timeline for a full new certification because your existing controls are already documented and operating.
