Yes, a small company with fewer than 50 employees can absolutely get ISO 42001 certified. The standard has no minimum employee requirement; it applies to any organization that develops, provides, or uses AI systems, regardless of size. In fact, many early adopters of ISO 42001 are small digital businesses and tech startups. Below, we cover the most common questions small companies ask before starting the process.

What are the employee size requirements for ISO 42001?

There are no employee size requirements for ISO 42001. The standard is explicitly designed to be scalable and applies to organizations of any size, from solo consultancies to large enterprises. What matters is not how many people you employ, but whether your business develops, deploys, or uses AI systems in a meaningful way.

ISO 42001 is the international standard for AI management systems. It was published by the International Organization for Standardization and focuses on responsible AI governance, risk management, and transparency. Because AI is increasingly embedded in small digital businesses, from automated customer support to data-driven decision-making, the standard is highly relevant for companies well below the 50-employee mark.

If your company uses AI tools as part of your core service or product, you are a valid candidate for certification. The scope of your management system simply needs to reflect the AI-related activities your business actually performs.

What does ISO 42001 actually require from a small company?

ISO 42001 requires a small company to establish, document, implement, and continually improve an AI management system (AIMS). This means defining how your organization governs AI use, assesses AI-related risks, and ensures your AI applications are transparent, fair, and accountable. The documentation effort is proportional to your actual AI activities.

In practical terms, a small company working toward ISO 42001 certification typically needs to address the following areas:

  • AI policy: A clear statement of your organization’s commitment to responsible AI use
  • Risk and impact assessment: Identifying where AI could cause harm or bias and what controls you have in place
  • Roles and responsibilities: Defining who is accountable for AI-related decisions within your team
  • Objectives and performance monitoring: Setting measurable goals for your AI management system and tracking progress
  • Supplier and third-party AI: Addressing AI tools or models you use from external providers
  • Continual improvement: A process for reviewing and improving your AIMS over time

For a small company, this does not require a dedicated AI ethics department or a team of compliance specialists. Many of these requirements can be addressed with straightforward documentation and clear internal processes. The standard is built around the same high-level structure as ISO 9001 and ISO 27001 certification, so if you have experience with either, you will find the framework familiar.

How long does ISO 42001 certification take for a small business?

For a small business, ISO 42001 certification typically takes between a few weeks and three months, depending on how prepared your organization is and which certification body you work with. If you start with minimal documentation, expect the preparation phase to take the most time. The audit itself is usually completed within one to two days for a small company.

The main phases of the certification process are:

  1. Gap analysis: Comparing your current AI governance practices against ISO 42001 requirements
  2. Documentation and implementation: Building your AI management system, writing policies, and putting processes in place
  3. Internal audit: Reviewing your own system before the external audit
  4. Stage 1 audit (document review): The certification body checks your documentation
  5. Stage 2 audit (on-site or online): The auditor verifies that your system is actually implemented and working
  6. Certification decision: If successful, you receive your ISO 42001 certificate

Digital companies have a particular advantage here because online audits are straightforward to arrange. There is no need for an auditor to travel to a physical location, which speeds up scheduling and reduces cost. With modern AI-assisted documentation platforms, the preparation phase that once took months can be compressed significantly.

How much does ISO 42001 certification cost for a small company?

For a small company with fewer than 50 employees, ISO 42001 certification costs typically range from a few hundred to a few thousand euros or dollars, depending on the certification body, audit format, and how much preparation support you need. Online certification providers generally offer lower fees than traditional audit firms that require on-site visits.

The total cost breaks down into a few components:

  • Preparation costs: This includes your time, any software or platform you use to build documentation, and optional consulting support
  • Certification body fees: The fees charged by the auditor for conducting the Stage 1 and Stage 2 audits
  • Annual surveillance costs: ISO 42001 certificates are valid for three years, with annual surveillance audits required to maintain them

The biggest cost driver for small businesses is usually the preparation phase, particularly if external consultants are involved. Platforms that automate or guide documentation can reduce this significantly. For digital companies, the absence of travel costs for on-site audits also makes online certification considerably more affordable than the traditional route.

Should a small company pursue ISO 42001 or ISO 27001 first?

If your small company handles sensitive data or operates in a sector where clients ask about data security, pursue ISO 27001 first. If your business is built around AI products or services and you want to differentiate on responsible AI governance, ISO 42001 may be the more strategic starting point. Many companies will eventually want both, and they complement each other well.

Here is a practical way to think about the choice:

  • Choose ISO 27001 first if your clients or prospects regularly ask about data security, if you handle personal data, or if you operate in regulated industries like finance, healthcare, or legal services. ISO 27001 has broader market recognition right now and is often a prerequisite for enterprise contracts.
  • Choose ISO 42001 first if AI is central to your product or service offering, if you are positioning your company as an AI-first business, or if your target clients are specifically concerned about AI ethics and transparency.

It is worth noting that ISO 42001 and ISO 27001 share the same high-level structure (Annex SL), which means implementing one makes it significantly easier to implement the other. If your roadmap includes both, starting with ISO 27001 gives you a strong compliance foundation, and adding ISO 42001 later becomes a natural extension rather than starting from scratch.

For companies that also want to signal quality management maturity to clients, ISO 9001 certification is another complementary standard worth considering alongside ISO 42001.

How DICIS AG helps small companies get ISO 42001 certified

We built our platform specifically for small digital companies that want a straightforward path to ISO 42001 certification without the overhead of traditional consulting or drawn-out audit processes. Here is what working with us looks like in practice:

  • AI-assisted documentation: Our platform guides you through building your AI management system with smart templates and prompts, reducing weeks of manual work to a matter of hours
  • Fully online audits: No travel, no scheduling headaches, audits are conducted entirely online, which is ideal for digital companies operating remotely or across locations
  • Transparent, fixed pricing: No surprise consulting fees or hidden costs, you know what certification will cost before you start
  • Fast turnaround: Small companies can go from onboarding to certified in days rather than months
  • Scalable scope: We tailor the certification scope to what your company actually does, so you are not building a compliance system designed for a 500-person organization

If you are a small digital company ready to get ISO 42001 certified, start your certification process with us today and see how quickly it can be done.

Related Posts

There is no related posts