Skip to content
Montevive

/ Blog /

News

Montevive

ISO 42001 in Spain: what it's really for, and who shouldn't bother

·Regulation, Artificial Intelligence
ISO 42001 in Spain: what it's really for, and who shouldn't bother

ISO/IEC 42001 certifies that an organisation manages its artificial intelligence with an inventory, risk analysis, controls and auditable evidence. It does not replace the AI Act, nor does it exempt you from complying with it: it helps you bid for public contracts, pass a large client's due diligence, and organise the documentation the regulation demands. For some companies it simply isn't worth it, and this article gives you the criteria to find out.

Contents


Almost everything published about ISO 42001 explains what it is. Very little explains what it is for, and practically nothing says who shouldn't bother.

This article is about the second and the third: what the certificate actually attests to, how it differs from the legal obligation it gets confused with daily, what the auditor reviews when they arrive, and when spending money on the full standard is using a sledgehammer to crack a nut.

What ISO 42001 is, and why it matters right now

ISO/IEC 42001 is the international standard certifying that an organisation manages its artificial intelligence systematically: with an inventory, risk analysis, controls and auditable evidence. It was published in December 2023 and is the first certifiable standard for AI management systems.

It is to AI what ISO 27001 is to information security, and it shares the same high-level structure. Its Annex A adds 38 AI-specific controls: policy, roles, impact assessment, lifecycle, data, transparency and suppliers.

We didn't choose the timing: two external calendars set it. The first belongs to Regulation (EU) 2024/1689: it applies generally from 2 August 2026, and the obligations for Annex III high-risk systems arrive on 2 December 2027 following the digital omnibus postponement. In Spain, the draft Organic Law on the good use and governance of AI, which designates AESIA as the supervisory authority and sets the national penalty regime, is still going through parliament. The second calendar belongs to your clients: public tender specifications and large companies' supplier questionnaires are starting to ask about AI management.

On paper the standard is voluntary. In practice, anyone selling technology to corporations or to public administration is going to run into it.

It is also worth knowing how much company you have: ISO does not yet include 42001 in its ISO Survey, the official annual census of certificates, because the standard is too recent to appear in it. To put it next to something familiar, ISO 27001 has accumulated 96,709 certificates according to the ISO Survey 2024. That doesn't make 42001 a lesser standard: it means it is newly born, and that whoever certifies now arrives ahead of their competition.

In one sentence: ISO 42001 is voluntary, but tender specifications and clients are starting to ask for it, and that brings it close to a de facto requirement. It is so recent that ISO does not yet publish a certificate census, and that window for differentiation is still open.

What ISO 42001 is actually for

For three specific things, and it is worth being clear about them because they are what justifies the investment, or doesn't.

Bidding for public contracts. Public tenders are beginning to give weight to accredited AI management, and a certificate counts for more than a hundred self-declarations.

Selling to corporations. Large clients' procurement and risk departments are folding AI into their supplier due diligence, and the certificate answers a good part of a long questionnaire in one go.

Organising your AI Act compliance. The standard does not replace it, but it systematically generates the documentation and evidence the regulation demands: inventory, risk classification, the Article 4 AI literacy requirement, transparency and human oversight.

Notice that all three are commercial or a matter of internal order. None of them is legal, and that is the distinction most often confused.

What ISO 42001 is not for: the difference with the AI Act

Let nobody mistake it for a legal safe-conduct. The AI Act is mandatory and ISO does not exempt you from complying with it.

There is also a technical nuance worth knowing before signing anything: ISO 42001 is not a harmonised standard under the regulation, so the certificate does not grant presumption of conformity. It serves as evidence before an auditor or a client, not as an exemption before the authority.

Nor is it a seal you can buy: certification is issued by an independent body after auditing your system, and it is revalidated through surveillance audits. Anyone selling you otherwise is selling you a piece of paper.

AI ActISO 42001
NatureEuropean regulation, mandatoryInternational standard, voluntary
Who supervisesNational supervisory authority; in Spain, AESIA under the draft law in progressCertification body
If you don't complyPenalty regime of Regulation (EU) 2024/1689Nothing legally; you lose contracts and tenders
What it gives youCompliance with the lawEvidence you can show a client, without presumption of conformity
TimelineGeneral application from 2 August 2026; Annex III high-risk from 2 December 2027; Spanish penalty regime in progressWhenever you decide

In one sentence: The AI Act tells you what you have to comply with; ISO 42001 is the orderly way of demonstrating that you comply. They are complementary, never alternatives.

Who shouldn't bother certifying

This is the part almost nobody writes, because almost nobody makes money writing it.

If these three conditions hold at the same time, the full standard is probably a sledgehammer to crack a nut:

  • Your use of AI is incidental. General-purpose tools for support tasks, with no automated decisions affecting people or clients.
  • You don't bid for public contracts, and it isn't in your short-term plans.
  • No client has asked you for guarantees about your use of AI, neither in a contract nor in a supplier questionnaire.

In that scenario there are far cheaper preliminary steps that solve most of the problem: inventory what is already in use, set a usage policy, train the team, and close the obvious leaks. The gap assessment exists precisely to answer that question before spending a single euro on the standard.

And if a full ISO is still too much, the step before it is the AI Ready Seal, our own certification: it attests that your use of AI is secure, documented and lawful. It does not replace ISO 42001 and does not claim to. Everything it documents is reused later in implementing the standard, so you don't start from scratch.

What the auditor will ask you for

It is worth knowing what lies at the end of the road before setting off. In the certification audit, the body reviews a fairly stable set of documents:

  • The AI policy approved by management.
  • The inventory of AI systems with their risk classification.
  • The impact assessments of the relevant systems.
  • The risk register with its treatments.
  • The Statement of Applicability, justifying which Annex A controls you apply and which you don't.
  • The operating records of those controls.
  • The minutes of internal audits and of management review.

None of those documents is hard to write. What is hard is making them tell a coherent story with months of evidence behind it. Implementing ISO 42001 consists of demonstrating with records that the system works, not of drafting a manual: an auditor does not certify intentions, they certify evidence with a track record.

From that comes the most useful practical rule in this whole article. Be wary of anyone who promises to certify you in a few weeks, because the calendar is not set by the consultancy: it is set by how long your controls have been leaving records.

Where the ones who fail, fail

We don't have our own non-conformity statistics to publish, and we are not going to invent them. What we can tell you about are the weak points an auditor looks at first, because they are the ones that give away a system built to pass rather than to work. It is worth reviewing them before the auditor arrives:

Poorly defined scope. A perimeter is certified that leaves out systems the auditor finds with their first question.

Freshly manufactured evidence. Every record dated the month before the audit. It is the clearest sign of a system that exists on paper and not in operation.

Controls copied from an ISO 27001 template without adapting them to AI. They give themselves away the moment the auditor asks about a model's lifecycle.

Shadow AI. Tools employees use without approval that don't appear in the inventory. If the auditor finds it and your system doesn't account for it, the message is that the system doesn't reflect reality. And that is precisely what the standard certifies doesn't happen.

What gets published about cost and timelines, and what drives them

We don't yet have our own project base from which to publish our own range, and we are not going to invent one. So we have done the next best thing: gather the ranges that are published in Spain, with their source, and explain why they look so little like one another.

ItemRange published in SpainSource
First year, consultancy and audit (small company)€3,000 – 15,000; large organisations exceed that rangeNovaciber, July 2026
First year, SME of 10 to 50 employees€12,000 – 30,000 implementation + €6,000 – 12,000 initial auditKnowlee, April 2026
First year, company of 50 to 250 employees€30,000 – 80,000 implementation + €12,000 – 25,000 initial auditKnowlee, April 2026
Timeline with no prior management system6 – 12 months / 12 – 18 monthsNovaciber / Knowlee
Timeline with ISO 27001 already implemented6 – 9 monthsNovaciber and Knowlee agree
Initial gap assessment with MonteviveFree of chargeMontevive

The total range runs from a few thousand euros to more than €100,000 in the first year. That spread is not noise: it reflects very different projects, and it is the best reason to ask for an assessment rather than a closed quote.

Four variables move the budget and the calendar, in order of weight.

Whether you already have ISO 27001. By far the most decisive. Both standards share a structure, and a good part of the governance, risk management, documentation and continuous improvement controls are reusable. In the assessment it is always the first thing we look at: which existing evidence works as is, which needs adapting, and what has to be created from scratch.

Scope. Certifying the use of AI tools in one department is not the same as certifying the full lifecycle of a product that sells AI.

The size and complexity of the organisation, because more processes mean more controls to evidence.

Your documentary maturity at the outset. A company already working with policies, records and internal audits moves far faster than one starting from zero.

In one sentence: The timeline of an ISO 42001 certification is not set by the consultancy, it is set by how long your controls have been leaving auditable records.

Who certifies in Spain, and why we don't

Bodies such as AENOR, Bureau Veritas, DEKRA and TÜV NORD offer ISO 42001 certification for the Spanish market, all with published offerings for this standard. The market is already moving: AENOR has certified Sanitas as the first hospital network in Spain, and KPMG was the first Big Four firm to certify to ISO 42001 in Spain. It is worth not confusing the two roles: KPMG appears here as a certified company, not as a certification body.

And here is a nuance almost nobody mentions, and one worth checking before you sign. In Spain, accreditation of certification bodies falls to ENAC, but as of September 2026 its register of accredited bodies shows no entity accredited specifically for ISO/IEC 42001, and several certification bodies state they are in the process. It is worth noting that other published sources claim otherwise; our check of ENAC's register on 23 September 2026 does not confirm it, and neither AENOR's accreditations page nor its ISO 42001 certification page mentions ENAC accreditation for this standard. Some multinationals may issue the certificate under accreditations from bodies in other countries.

So the buyer's advice is concrete: always ask under which accreditation your certificate is issued, and who grants it. A certificate without recognised accreditation is worth far less in the Spanish market, and today that question is not rhetorical.

We implement and prepare; we don't certify, and that is deliberate. Whoever designs a management system should not audit it: the certifier's independence is exactly what gives value to the certificate you are going to show a client. We leave you ready for the audit by the body you choose, and we accompany you through it.

What to do on Monday morning

Three things you can do this week without hiring anyone, and which are also the starting point of any management system:

  1. Ask procurement and sales whether any client or tender has already mentioned AI management, ISO 42001 or AI supplier questionnaires. If the answer is yes, you have a real deadline and not an abstract worry.
  2. Make a rough inventory of the AI your team already uses, with two columns: tool and what for. No judgement. It is usually the first surprise.
  3. Check whether your ISO 27001 is live or expired. It is the variable that moves the budget and the calendar most.

Frequently asked questions

Is ISO 42001 mandatory?

No, it is voluntary. In practice, public tender specifications and large clients' supplier questionnaires are starting to ask for it or score it, which is a different way of making it obligatory.

Does ISO 42001 serve to comply with the AI Act?

It does not replace it: the AI Act is mandatory and ISO is voluntary. It is also not a harmonised standard under the regulation, so the certificate does not grant presumption of conformity. It serves as evidence, not as an exemption.

How much does it cost to certify to ISO 42001 in Spain?

Published estimates range from around €3,000 in small companies to more than €100,000 in medium-sized companies in the first year, consultancy and audit included. The difference is driven by scope, size, documentary maturity and whether you already have ISO 27001.

How long does it take?

Published estimates range from 6 to 18 months with no prior management system, and agree on 6 to 9 months if you already have ISO 27001 in place. Fundamentally it is set by how long your controls have been leaving auditable records, not by the consultancy.

Who certifies ISO 42001 in Spain?

Bodies such as AENOR, Bureau Veritas, DEKRA and TÜV NORD. ENAC is the body that accredits certification bodies in Spain, although as of September 2026 its register shows no accreditation specifically for ISO/IEC 42001; other published sources claim otherwise, so always ask under which accreditation your certificate is issued and who grants it. Montevive implements and prepares; it does not certify.

How many companies are certified?

ISO does not yet publish an official census for 42001, because the standard is too recent to appear in the ISO Survey. That is an indicator in itself: the window for differentiation is still open.

Sources

  • ISO/IEC 42001:2023 — Information technology. Artificial intelligence. Management system (iso.org)
  • ISO Survey 2024 — official census of management system certificates (ISO/IAF, September 2025)
  • Knowlee — "ISO 42001 en España: cómo implantar el sistema de gestión de IA paso a paso", April 2026 (knowlee.ai)
  • Novaciber — "Cuánto cuesta la ISO 42001 en 2026", July 2026 (novaciber.com)
  • AENOR — UNE-ISO/IEC 42001 certification for AI management systems (aenor.com)
  • AENOR — Accreditations and recognitions, consulted on 25 September 2026 (aenor.com)
  • Bureau Veritas España, DEKRA and TÜV NORD — ISO 42001 certification pages, consulted on 23 September 2026
  • KPMG España — press release on its ISO 42001 certification (kpmg.com)
  • ENAC — Register of accredited bodies, consulted on 23 September 2026 (enac.es)
  • Regulation (EU) 2024/1689 (AI Act) and Regulation (EU) 2026/1744 postponing the high-risk obligations (EUR-Lex)
  • Draft Organic Law on the good use and governance of artificial intelligence, BOCG Series A no. 97-1, 12 June 2026 (congreso.es)

Antonio Vílchez García is Compliance Manager at Montevive, where he leads AI governance and compliance with the AI Act, the GDPR, and alignment with the ENS and ISO 27001/42001. He holds a degree in Computer Engineering with a specialisation in Information Systems and a Master's in Business Process Management and Technologies from the University of Granada.


Is ISO 42001 worth it for you, or is less enough? The gap assessment answers that question with data, at no cost. Request an assessment and we'll tell you what you have, what you're missing, and what it would cost to close the gap.