Beta
ISO 42001 procurement · scanned 1 August 2026

ISO 42001 procurement: the evidence

Nearly every page you will read on this asks whether ISO 42001 is becoming a UK procurement expectation. None of them counts. We did.

Across the whole of our UK notice corpus, the AI management system standard appears in one notice of 745,098 scanned notices. That is not because UK buyers are behind — it is because until the first UKAS accreditation in January 2026, no UK body could issue the certificate at all.

The infrastructure, in order
  1. 18 Dec 2023ISO/IEC 42001 published
  2. 6 Nov 2024DSIT consults on AI Management Essentials
  3. 17 Feb 2025PPN 017 on AI transparency
  4. 7 Jul 2025ISO/IEC 42006:2025 published — accredited certification becomes possible
  5. 15 Jan 2026First UKAS accreditation granted, to BSI
  6. 6 Feb 2026AI Management Essentials cancelled
  7. 18 May 2026The one UK notice naming the standard
  8. 27 Jul 2026EU AI Omnibus in force
  9. 2 Dec 2027EU high-risk obligations apply
Read the two accented nodes together. Accredited UK certification became possible in January 2026; the only UK notice naming the standard was published four months later, and there is one of it. Sources for every date are in the record.
Scroll to descend
01
A standard can exist for two years and still be impossible to demand.

ISO 42001 procurement, measured on the whole corpus

Before the number, what it counts. We read the published text of every notice — its title and its description. We do not read the tender pack, and the pack is where a requirement like this usually lives. So this is a floor: the count of notices that say it out loud, not the count of procurements that want it.

With that stated: our classifier read every notice we hold, and 745,098 of them carry a publication date and so enter the count, scanned on 1 August 2026. It found one. For comparison, and on exactly the same method, ISO 9001 appears in 412 notices and Cyber Essentials appears in 291 notices.

That gap is the subject of this page. It is not a gap in enthusiasm, and it is not evidence that UK buyers are slow. It is a gap in infrastructure, and it has a documented cause with a date attached to every link in it.

Two things follow, and they point in opposite directions. If you are being told that ISO 42001 is now a condition of winning UK public work, that is not what the notices say. If you are being told the standard is therefore pointless, that is not what this page says either — the standard is real, accredited UK certification now exists, and one notice is a beginning rather than a verdict.

What the number is
one notice out of 745,098 scanned, extracted by one matcher with an evidence sentence stored behind it. You can read it in the notice section and the method in how we counted.
What the number is not
It is not a census of demand. A requirement stated only in an ITT pack, a supplier questionnaire or an evaluation matrix is invisible to it, and those are exactly where certifications get asked for. The direction of the error is known: it understates.
Why we can say it at all
Because the scan is the whole corpus rather than a sample. 745,098 is every dated notice the classifier has read — the same population the counts themselves are built from, so numerator and denominator cannot drift apart. There is no sampling error to argue about, only the stated limit above. The Requirements Observatory runs the same matcher across every certification, clearance and scheme we track.
02
If almost nobody asks for it, the useful question is not why buyers are behind — it is who was allowed to issue the certificate, and when.

The chain that explains the number

Three things have to exist before a buyer can put a certification in a tender: the standard, a rulebook for the bodies that audit against it, and an accredited body willing to issue it. For ISO 42001 the last of those arrived in the UK in January 2026.

ISO/IEC 42001:2023 is published

The certifiable management-system standard for artificial intelligence. ISO’s own stage record reads “60.60 2023-12-18 International Standard published”. [1]

DSIT consults on AI Management Essentials

A self-assessment tool distilled from ISO/IEC 42001, the EU AI Act and the NIST AI RMF, which the department intended to embed in government procurement. [6]

PPN 017 is published

The Procurement Act 2023 instrument on AI in procurement. It governs disclosure of a supplier’s AI use. It does not require an AI management certification. [8]

ISO/IEC 42006:2025 is published — the load-bearing node

The standard specifying requirements for the bodies that audit and certify to 42001, eighteen months after 42001 itself. Until it existed, accredited certification was structurally impossible: accreditation bodies had no harmonised basis on which to assess certifiers. [2]

UKAS grants the first UK accreditation

UKAS: “UKAS has granted BSI the first accreditation for certification of artificial intelligence (AI) management systems to ISO/IEC 42001:2023.” [3] The live proof is better than the press release — BSI’s UKAS Schedule of Accreditation, issue date 23 July 2026, carries the granted scope. [4]

The procurement plan is cancelled

DSIT’s government response: “DSIT will not be publishing AIME and therefore will not be making it a requirement of the government procurement process.” [7]

The one UK notice appears

FIRST RAIL HOLDINGS LIMITED publishes “First Cyber Security Tooling & Managed Services Tender” — £3,433,993, naming ISO 42001 among the frameworks its managed service must operate within. Four months after the first UK-accredited certificate could exist at all. [5]

The EU AI Omnibus enters into force

The European Commission: “On 27 July 2026, the AI Omnibus enters into force across the EU.” Regulation (EU) 2026/1744. [10] [11]

The load-bearing sentence. The single UK notice naming ISO 42001 was published 18 May 2026 — four months after the first UK-accredited certificate could exist at all, and ten months after the standard governing the certifiers was published. A buyer cannot demand a certificate nobody in the country is accredited to issue. That is the mechanism, and every link in it has a primary source.

ISO 42001 certification UK: who can issue it, and since when

A certificate is only worth what the accreditation behind it is worth, and in the UK that accreditation is very new.

The United Kingdom Accreditation Service is the sole national accreditation body, and it is what makes a certificate from a UK certification body mean something to a buyer. On 15 January 2026 it announced that it had granted BSI “the first accreditation for certification of artificial intelligence (AI) management systems to ISO/IEC 42001:2023”. [3]

The stronger evidence is not the announcement but the schedule. BSI’s UKAS Schedule of Accreditation, issue date 23 July 2026, carries the granted scope in terms: “ARTIFICIAL INTELLIGENCE MANAGEMENT SYSTEMS / In accordance with ISO/IEC 17021-1:2015 and ISO/IEC 42006:2025 / ISO/IEC 42001:2023 Certification”. [4] A press release states an intention; a schedule is the live grant.

So how many UK bodies can actually issue you one? Five. We counted them rather than estimating, and the counting method is the point, because “very few” is what everybody says and nobody checks.

UKAS publishes a Schedule of Accreditation for every body it accredits, listing the exact scopes that body may certify against, with an issue number and an issue date. We enumerated the population rather than searching it — UKAS’s own keyword search caps its result set — by probing every management-systems schedule number from 0001 to 4000. Fifty-four exist. Five carry an artificial intelligence management systems scope, and all five cite ISO/IEC 42006:2025 as the basis on which they were assessed. [16]

This is the supply side of the whole argument, in one number. A buyer writing a condition of participation has to believe the market can satisfy it. Five accredited bodies is not a market a procurement officer can safely gate on — and it is a better answer to “why is nobody asking for this” than any claim about buyer conservatism.

Every UK body accredited to certify to ISO/IEC 42001
BSI Assurance UK LtdUKAS 0003Schedule issue 192 · 23 Jul 2026
LRQA LimitedUKAS 0001Schedule issue 220 · 24 Jun 2026
NQA Certification LtdUKAS 0015Schedule issue 194 · 5 May 2026
ISOQAR Limited (Alcumus)UKAS 0026Schedule issue 160 · 4 Jun 2026
TUV UK LimitedUKAS 0065Schedule issue 059 · 8 Jun 2026
All five carry the identical grant: “ARTIFICIAL INTELLIGENCE MANAGEMENT SYSTEMS / In accordance with ISO/IEC 17021-1:2015 and ISO/IEC 42006:2025 / ISO/IEC 42001:2023 Certification”. Counted by exhaustive sweep of every UKAS management-systems schedule, not by keyword search. [16]
One body from the pilot list did not make it
UKAS’s AIMS development page names seven organisations in the pilot. Of those, Intertek Certification Ltd (UKAS 0014, schedule issue 096, 25 March 2026) carries no ISO 42001 scope at all, and Schellman Compliance LLC is not a UKAS-accredited certification body. Being in a pilot is not holding a scope, and the difference is checkable on the schedule. [16]
Two transcription errors in UKAS’s own PDFs
Noted so they do not confuse you: LRQA’s summary bullet says “ISO/IEC 42001:2025” while its scope page correctly says 2023, and ISOQAR’s scope page says “ISO/IEC 42001:2013” under a heading reading “ARTIFICAL”. There is one edition and it is 2023. Typing errors in the schedules, not different scopes. [16]
The limit of this count, stated
The sweep covers schedules published under the management-systems type, which is where an ISO/IEC 17021-1 scheme belongs and where all five sit. If UKAS ever filed an AIMS scope under a different type, this method would miss it. Schedules are reissued, so check the live PDF before relying on a row.

Four things it is tempting to say here, and why each is wrong

These matter because they are what the most-linked pages on this topic say, and a reader arriving from one of them should be able to see the correction rather than a flat contradiction.

Not “the first in the world”
UKAS does not claim it. Its “world first” wording attaches to the standard“ISO/IEC 42001 is the world’s first management system standard for artificial intelligence” — and not to the accreditation. BSI also already held RvA (Netherlands) accreditation from 9 December 2024. The accurate phrasing is the first UKAS accreditation. [3]
ISO/IEC 42006 is published, not a draft
It is ISO/IEC 42006:2025, published 7 July 2025. The UKAS AIMS development page still says “DIS”, but that page was last modified 6 February 2025 and is stale. Any page telling you 42006 is still at draft stage is quoting it. [2]
Not still a pilot
Same stale page. Five certification bodies now hold granted, live scopes on their published schedules, the most recent reissued 23 July 2026. Whatever the pilot’s formal status, its participants are accredited and the schedules prove it. [16]
A date conflict we are not papering over
BSI’s own press release of 17 November 2025 says it “has become the first Certified Body in the world accredited by the United Kingdom Accreditation Service (UKAS)” — two months before UKAS announced the same grant, and it names UKAS separately from RvA, so it is not explained away as the Dutch one. We prefer 15 January 2026: the accreditation body is the authority on its own grants, UKAS’s own post index carries no November 2025 item, and UKAS said on 5 September 2025 that no accreditation had yet been granted. We state both rather than choose silently. [12]

We have no source explaining why BSI published in November, and we are not guessing at one. The two dates are recorded, the reason for preferring the UKAS date is given, and that is as far as the evidence goes.

The AI management system standard, and what it certifies

The most consequential misunderstanding on this topic is not about dates. It is about scope: what the certificate is a certificate of.

ISO/IEC 42001:2023 certifies an artificial intelligence management system — the organisational apparatus by which a company decides what AI it will build, how it assesses risk, who is accountable, and how it reviews what it has deployed. [1] It is a management-system standard in the same family as ISO 9001 for quality and ISO/IEC 27001 for information security, and it works the same way: an auditor examines your processes and your records.

It does not certify a model. It does not evidence that any particular algorithm has been tested, that a system is accurate, or that a specific output is fair. An organisation can hold a valid ISO 42001 certificate and ship a bad model, in the same way an ISO 9001 holder can ship a bad product — the standard says the process exists and is followed, not that the output is good.

This matters commercially in both directions. If you are selling, claiming that the certificate demonstrates model quality is a claim the standard will not support and an informed evaluator will discount. If you are buying and you actually want assurance about a model, the certificate is the wrong instrument and you should be asking for testing evidence, not a certificate number.

The companion document people confuse it with
ISO/IEC 23894:2023 is guidance on AI risk management, published February 2023. It is guidance, not a requirements standard, so you cannot be certified against it — a supplier claiming “ISO 23894 certified” has misunderstood their own compliance position. [13]
Why the distinction shows up in tenders specifically
Conditions of participation under the Procurement Act 2023 must be proportionate to the contract. A management-system certificate is easy to specify and easy to verify, which is why buyers reach for one — and why a buyer who needs model assurance often asks for the wrong thing. [9]

The UK plan to put AI governance into procurement, and its cancellation

This is the strongest fact on the page, and it is the one most competing content gets backwards — because the intention is easy to find and the reversal is not.

DSIT built AI Management Essentials, a self-assessment tool distilled from ISO/IEC 42001, the EU AI Act and the NIST AI Risk Management Framework, and consulted on it between 6 November 2024 and 29 January 2025. The report Assuring a Responsible Future for AI, published 6 November 2024, states both the lineage and the intent verbatim:

“Drawing on key principles from existing AI-related standards and frameworks — including ISO/IEC 42001 (Artificial Intelligence - Management System), the EU AI Act, and the NIST AI Risk Management Framework — AI Management Essentials will provide a simple, free baseline of organisational good practice”, and “In the medium term we are looking to embed this in government procurement policy and frameworks to drive the adoption of assurance techniques and standards in the private sector.” [6]

That quote must never be published without what follows it. It is a November 2024 aspiration that a February 2026 decision explicitly reversed, and quoting the intent alone — which several competing pages do — is the single easiest way to be wrong on this topic.

The government response, published 6 February 2026:

“DSIT will not be publishing AIME and therefore will not be making it a requirement of the government procurement process.” [7]

The reasons given include that a size- and role-agnostic tool “struggled to meet the diverse needs of different users”, that “SMEs may lack the resources and in-house expertise needed to navigate them effectively”, and that “insights regarding the potential impact on competition” would inform future policy. [7]

An accuracy note, because the two documents are not interchangeable. The February 2026 government response does not mention ISO/IEC 42001. The 42001 lineage comes from the November 2024 Assuring a Responsible Future for AI report. We cite each claim to the document that actually says it.

What UK procurement policy says about AI, and what it does not

Two Procurement Policy Notes carry AI. Between them they cover disclosure and national security. Neither mentions a certification.

PPN 017 — transparency of AI use in procurement

Published 17 February 2025, PPN 017 is the Procurement Act 2023 instrument. Its subject is the disclosure of the supplier’s AI use — whether you used AI to write your bid, and what the buyer may ask about it. It is not about certifying an AI management system, and it does not require one. [8]

It is also more permissive than most bidders assume, and says so in terms: “It is important to note that suppliers’ use of AI is not prohibited during the commercial process but steps should be taken to understand the risks associated with the use of AI tools in this context, as would be the case if a bid writer has been used by the supplier.” [8]

Two precision points. PPN 017 does not use the language of superseding PPN 02/24; its actual sentence is “For procurements commenced and contracts awarded before this date, please refer to PPN 02/24”, and PPN 02/24 remains listed under the Public Contracts Regulations 2015 section of the PPN collection. And the PDF’s own dateline reads “Originally issued: November 2023 / Updated: February 2025”, which contradicts the GOV.UK publication date — we cite the GOV.UK page date. [8]

PPN 025 — national security, and AI as a critical sector

Published 19 June 2026, PPN 025 names artificial intelligence as one of four critical national-security sectors, alongside shipbuilding, steel and energy infrastructure, with DSIT as the AI Sector Lead. It “applies only to central government departments, their executive agencies and non-departmental public bodies”. [14]

This is the honest answer to “where is UK AI procurement policy actually going”: towards strategic market shaping and the national security exemption, not towards a certification gate. GOV.UK contradicts itself on the date — the publication page says 19 June 2026, the collection listing says 3 July 2026, and the document’s own dateline says “Issued: June 2026”. We use 19 June 2026.

The checkable negative
We ran a full-text check on both documents. Neither PPN 017 nor PPN 025 contains the string “ISO” or “42001” anywhere. So: nothing in current UK procurement policy names ISO 42001. That is a claim a competitor cannot make without doing the work, and one you can verify in two minutes. [8] [14]

The notice that does name it, read closely

One notice is a small number, and it is also a document you can read. Three details in it tell you more about the state of this market than any survey would.

First Cyber Security Tooling & Managed Services Tender
FIRST RAIL HOLDINGS LIMITED · published 18 May 2026 · £3,433,993 · closed 17 June 2026
The sentence our matcher stored as evidence
Supporting Compliance and Regulatory Obligations: The managed SOC operates within recognised frameworks (e.g., ISO 27001, ISO 42001, ISO 22301, Cyber Essentials and UK NIS and GDPR) and supplies compliance reporting and rapid incident response evidence proactively.

Read live from our own corpus at the moment this page was served, including the evidence sentence — not transcribed. Every count here is a floor. We match the text of the notice, and a notice description is a summary — most tender packs demand things it never mentions. [5]

It is not central government
FIRST RAIL HOLDINGS LIMITED is a private rail operator — a utilities buyer. The only UK notice naming the AI governance standard is not a government one, which is worth holding against every claim that government is driving 42001 into procurement.
The standard is misspelled in the source
A second sentence in the same notice asks suppliers to “Ensure alignment and certification to industry best practices CSO/IEC 42001 (Artificial Intelligence Management System)”. The one time a UK buyer asks for it, they typo the name of it. That is the whole maturity story in a single character. [5]
It is not obligation language
The reference sits in a list of frameworks the managed service should operate within, not in a requirement. Our extractor records a separate mandatory flag when a match uses explicit obligation wording, and this one does not carry it. That flag is a confidence tier describing how the text is phrased — it is not a filter, and a match without it is not thereby “optional”. A requirement can bind through the pack while the notice describes it loosely.

ISO 42001 vs ISO 27001: what UK buyers actually ask for

The useful version of “do I need ISO 42001” is comparative. Put it beside the certifications that appear in the same notices and the answer stops being a matter of opinion.

Pick one and the instrument reads its live numbers straight out of our corpus. The bar is drawn against the most-demanded certification in the set rather than against the corpus, because against 745,098 notices every one of these rounds to nothing.

Which certification?
ISO/IEC 42001
1
one notice of 745,098 scanned

Every figure read live through the same extractor that powers the Requirements Observatory, at the moment this page was served. Every count here is a floor. We match the text of the notice, and a notice description is a summary — most tender packs demand things it never mentions. “Open right now” counts notices whose deadline has not passed. [15]

On the same corpus and the same method, ISO 9001 appears in 412 notices against ISO 42001's 1 — roughly 412 times as often. That ratio, not the raw count, is the thing to carry away.

Read live from the corpus · 745,098 notices scanned
ISO 9001412 notices143 in obligation language (34.7%)3 notices open now
Cyber Essentials291 notices75 in obligation language (25.8%)2 notices open now
ISO/IEC 27001224 notices48 in obligation language (21.4%)one notice open now
Cyber Essentials Plus132 notices24 in obligation language (18.2%)2 notices open now
ISO/IEC 42001one notice0 in obligation language (0%)none open now
Counts are floors: the notice text only, never the tender pack. The middle column is a confidence tier describing how the demand is worded, not a subset you should filter to — a requirement can bind through the pack while the notice describes it loosely.
ISO 42001 procurement evidence chart: notices naming ISO 9001, Cyber Essentials, ISO/IEC 27001, Cyber Essentials Plus and ISO/IEC 42001 across 745,098 scanned UK public tender notices
The same comparison as a single image, regenerated from the corpus rather than drawn by hand — the card carries the date it was drawn, so a stale one is visible rather than silent.

The practical reading for a supplier: ISO/IEC 27001 and Cyber Essentials are the certifications that actually gate UK public work in this space, and if you are choosing where to spend a certification budget with a tender in mind, that is where the evidence points. ISO 42001 is a differentiator you can lead with, not a gate you are failing. We break the wider set down on UK tender certifications, and per-requirement on the ISO 42001 requirement page.

AI buying is accelerating while the standard is absent

The negative finding above would be misleading on its own. The spend is arriving; it is the certificate that is not the gate.

Notices naming artificial intelligence have gone from 7.2 per 10,000 in 2019 to 12.9 per 10,000 in 2026 (a part year). That is the demand curve for the work. It is not the demand curve for the certificate.

7.2
2019
8.1
2020
7.0
2021
8.7
2022
7.3
2023
10.4
2024
9.1
2025
12.9
2026*
Before the Procurement Act After — not a continuous series

Two caveats, both load-bearing. The series is a rate per 10,000 notices, never a raw count, because how much we ingest differs by year and raw counts across years would be invalid. And the 24 February 2025 Procurement Act go-live sits inside this series — notice conventions changed then, so the difference between the two colours is partly a change in how notices are written and not purely a change in what buyers are buying. 2026 is marked with an asterisk because it is a part year; the rate handles that correctly where a raw count would not. [15]

What rising AI demand does change
More AI work means more buyers writing AI clauses for the first time, and a first-time clause is usually copied from somewhere. That is the mechanism by which a standard eventually does become an expectation — and the reason to hold the certificate is that it is cheap to state and hard to acquire quickly, not that it is currently being demanded.
What it does not change
Nothing in the corpus, in PPN 017, in PPN 025 or in the AIME outcome converts that trend into a certification requirement. If someone tells you the market has moved, ask them for the count. This page publishes its own count, which is one.

The EU AI Act dates, and why the old one is everywhere

Most pages arguing that ISO 42001 is about to become a procurement requirement lean on an EU deadline that moved. If you are reading a page that still says 2 August 2026, you are reading a page written before the Omnibus.

The AI Omnibus entered into force on 27 July 2026. The European Commission’s own wording: “On 27 July 2026, the AI Omnibus enters into force across the EU.” [10] The instrument is Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026. [11] Cite the regulation number and the OJ date rather than an adoption month: the number is checkable and the month is what gets misremembered.

High-risk obligations now apply from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for Annex I systems embedded in products. [10] Citing the OJ number rather than a tracker is both the correct source and a visible freshness signal, because nearly every competing page still carries the superseded date.

Two things this does not do, and they are the ones that get overstated. It does not make ISO 42001 mandatory anywhere — the Act works through conformity assessment against harmonised standards, and 42001 is a management-system standard rather than a harmonised standard under the Act. And it does not bind a UK buyer at all. It matters to a UK supplier because it may bind you, in the EU market, on those dates.

ISO 42001 tender requirements: where they would actually appear

If a buyer did want this, there are only a few places in a UK procurement where it could legitimately land — and knowing which one changes what you have to do about it.

Under the Procurement Act 2023 a certification can appear as a condition of participation, which is a gate: you either satisfy it or you are excluded, and the condition must be proportionate to the contract. [9] It can appear as an award criterion, which is scored rather than pass/fail — here the certificate earns you points and its absence costs you some. Or it can appear as a contractual term, an obligation to hold or obtain something during delivery rather than at bid time, which is the most negotiable of the three and the one most often missed.

The one notice we hold is the fourth case, and it is the commonest: a mention in a capability list. It is neither a gate nor a scored criterion — the buyer is describing the frameworks the service should operate within. That is worth recognising, because responding to a capability list as though it were a gate is how suppliers talk themselves out of bidding.

This is also why our count is a floor, restated concretely
Conditions of participation are set out in the associated tender documents, and those are attachments. Our matcher reads the notice’s published title and description. A 42001 gate could exist today, in a pack, and this page would not see it — which is the honest limit of the whole exercise and the reason we publish the method rather than only the number. How we counted.
What to do if you meet one
Ask which of the three it is, in a clarification question, in writing. Buyers answer these, the answer is published to all bidders, and the difference between “condition of participation” and “we would like to see it” is the difference between a no-bid and a strong bid.

How we counted, and the match we threw away

A method section that shows you its own false positive is worth more than three paragraphs asserting rigour. Here is ours.

The population is every UK notice we hold from Find a Tender and Contracts Finder — 753,990 at the moment this page was served, the most recent published 19 August 2026. Of those, our requirements classifier has scanned 745,098, at classifier version 5, on 1 August 2026. It matches against the notice’s title and description, stores the sentence each match came from, and records a separate flag for obligation language.

A crude string search returns more, and the extra one is not a standard. Searching the whole corpus for the raw digits “42001” returns 2 matches, where the classifier keeps 1. The one it rejected is below.

Piezo surgical drill maintenance contract
Wirral University Teaching Hospital NHS Foundation Trust · 13 June 2022
…unit and the following parts: Piezosurgery PLUS Serial No: 420019086 1 standard handpiece Serial No: 408066023 1 Plus hand…
Rejected: the digits are part of a serial number, not a reference to a standard.

Pulled live from the corpus with the surrounding text, so you can see the rejection rather than take our word for it. If a future notice makes this list longer or shorter, this section changes with it. [15]

The same conservatism holds across the whole set rather than being tuned for this page. Raw string against extracted, on the two nearest comparators: ISO 9001 returns 508 raw and the extractor keeps 412; ISO 27001 returns 238 raw and the extractor keeps 224. The extractor understates by design, because a false positive in a published count is worse than a missed match.

One matcher, not two
The figures on this page come through the same extractor that powers the Requirements Observatory and every per-requirement page on this site. We deliberately did not write a second query for this page: a second matcher is a second truth, and the moment a term changed the two would disagree and nothing would say so.
What would change the answer
A pack-level scan. We hold notice text, not attachments, and every limit stated on this page follows from that one fact. If that changes, the number will move — upward, since the error only runs one way — and because this page reads the database live rather than quoting a stamped figure, it will move here on its own.
03
Back to the surface — the questions, the glossary, and the record.
The sourced record

Questions people actually ask about ISO 42001 and procurement

These are real search strings from this page’s own query data, reproduced as typed.

how long will it take before iso 42001 becomes a market expectation?

Nobody can give you a date, but the constraint is now supply rather than appetite, and that is a change. Accredited UK certification only became possible in July 2025 when ISO/IEC 42006:2025 gave accreditation bodies a basis to assess certifiers, and the first UKAS accreditation was granted in January 2026. A requirement cannot become normal faster than the certificates can be issued. Against that, the UK government’s one concrete plan to embed AI governance in procurement was cancelled in February 2026, so there is currently no policy driver pushing it. The honest answer is that as at 1 August 2026 it is present in one notice of 745,098, and the number to watch is not a forecast but that count — which this page re-reads every hour.

what industries are most likely to require iso 42001 from vendors?

On UK public-sector evidence the honest answer is that no industry requires it yet, and the single notice we hold is instructive about where it will start. It is not central government: it is a private rail operator buying a managed security service, and the standard appears alongside ISO/IEC 27001, ISO 22301 and Cyber Essentials in a list of frameworks the service should operate within. That is the pattern to expect — AI governance arriving as an extra line in an existing security schedule rather than as a standalone AI requirement. Regulated sectors that already run mature management-system certification, and buyers of AI-enabled managed services, are where it appears first.

how do procurement teams evaluate iso 42001 certifications

Ask for three things and the certificate becomes checkable rather than decorative: the certification body, the accreditation behind it, and the scope statement. The accreditation matters most — a certificate from a body with no accreditation for AI management systems has not been assessed against ISO/IEC 42006:2025 at all, and UKAS publishes each accredited body’s schedule showing exactly which scopes it holds. The scope statement matters second, because a management-system certificate covers named activities and sites and not necessarily the part of the business delivering your contract. And under the Procurement Act 2023, if a buyer intends to treat it as a condition of participation rather than an award criterion, that must be proportionate to the contract being let.

how do ai firms position iso 42001 in competitive proposals

The position that survives an informed evaluator is a narrow one: the certificate evidences that you run a governed AI development process, and it evidences nothing about any particular model. Firms that claim it demonstrates model quality, safety or fairness are making a claim the standard does not support, and an evaluator who knows the standard will mark it down. Used well it is a credibility shortcut in a section you have to write anyway — risk management, accountability, human oversight — letting you answer with an audited process rather than assertions. On UK public work it is currently a differentiator rather than a gate: what is actually being asked for is ISO/IEC 27001 and Cyber Essentials.

is iso 42001 mandatory for uk government contracts

No. Nothing in UK procurement policy names it: we ran a full-text check on both AI-relevant Procurement Policy Notes, PPN 017 and PPN 025, and neither contains the string “ISO” or “42001”. The nearest thing to a plan was AI Management Essentials, a DSIT self-assessment tool drawn partly from ISO/IEC 42001, which the department intended to embed in government procurement; on 6 February 2026 DSIT confirmed it “will not be publishing AIME and therefore will not be making it a requirement of the government procurement process”. A specific buyer can always choose to require a certification in a specific procurement, provided it is proportionate — but there is no general mandate, and on our corpus almost no instances.

iso 42001 vs iso 27001 which do i need for tenders

If you are choosing one with UK public tenders in mind, ISO/IEC 27001 — and it is not close. On our corpus ISO/IEC 27001 appears in 224 notices and Cyber Essentials in 291 notices, against one notice for ISO 42001. They also do different jobs: 27001 certifies an information security management system, 42001 an AI management system, and holding one says nothing about the other. Where AI governance is asked about at all, it is usually asked about inside a security schedule, which is another reason the security certification is the one that unlocks the conversation. The counts here are floors, and they are read live from our corpus.

does the eu ai act make iso 42001 mandatory

No. The Act works through conformity assessment against harmonised standards, and ISO/IEC 42001 is a management-system standard rather than a harmonised standard under the Act — holding it can help evidence parts of a risk-management obligation, but it is not a route to conformity in itself. The dates also moved, which is where most of the confusion on this comes from. The AI Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744, and high-risk obligations now apply from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for systems embedded in products. Any page telling you that a 2 August 2026 deadline is forcing ISO 42001 into tenders is working from a superseded timetable.

how much does iso 42001 certification cost uk

We do not publish a figure, and we would treat any page that does with caution unless it names its source. Certification pricing depends on headcount, the number of sites, the scope of the management system and whether you already hold a certificate the auditor can build on, and it is quoted per organisation by the certification body. What we can tell you is the structural fact that bears on cost right now: very few UK bodies hold UKAS accreditation for this scope, so there is little competitive pressure on price and limited auditor availability. If you need a number, get quotes from accredited bodies and check each one’s UKAS schedule covers AI management systems before you compare them.

The terms, defined by whoever owns them

Ten terms you will meet in this argument, each with the source that defines it where one exists.

AIMSArtificial Intelligence Management System — the thing ISO/IEC 42001 certifies. An organisational management system, not a model. [1]
AIMEAI Management Essentials. A DSIT self-assessment tool drawn partly from ISO/IEC 42001, intended for embedding in government procurement; not published, and that plan dropped on 6 February 2026. [7]
AccreditationWhat a national body (UKAS in the UK) grants to a certification body, authorising it to issue certificates in a named scope. Distinct from certification, which is what that body then grants to you. [3]
Conditions of participationWhat replaced the selection questionnaire under the Procurement Act 2023: proportionate requirements on legal, financial and technical capacity. Where a certification is mandated if it is mandated at all. [9]
ISO/IEC 42001:2023“Information technology — Artificial intelligence — Management system”. Certifiable, organisation-level, published 18 December 2023. [1]
ISO/IEC 42006:2025Requirements for bodies providing audit and certification of AI management systems. Published 7 July 2025 — the document that made accredited certification possible. [2]
ISO/IEC 23894:2023Guidance on AI risk management, published February 2023. Guidance, so not certifiable. [13]
PPN 017Improving transparency of AI use in procurement, 17 February 2025. Governs disclosure of a supplier’s AI use; names no certification. [8]
PPN 025Protecting the UK’s national security through public procurement, 19 June 2026. Names AI as a critical national-security sector; applies to central government only. [14]
Schedule of AccreditationThe published document listing exactly which scopes a certification body is accredited for, with an issue date. The thing to check before accepting a certificate. [4]

The figures on this page, and what each one measures

Four numbers, each labelled with exactly what it counts, and all four read live rather than quoted.

1
UK notice naming ISO 42001, of 745,098 scanned
Extracted from notice title and description by the classifier that powers the Requirements Observatory, version 5, scanned 1 August 2026. A floor, not a census — the tender pack is not in the corpus. [15]
0
of those open right now
Nothing currently open names it. This is a live count and it changes without anyone editing this page. [15]
224
UK notices naming ISO/IEC 27001, on the same method
The comparison that makes the headline meaningful: same corpus, same matcher, same limits. Cyber Essentials returns 291. [15]
745,098
notices scanned by the classifier
The denominator. Of 753,990 notices held in total from Find a Tender and Contracts Finder under the Open Government Licence v3.0. Full corpus, not a sample. [15]

And the number we are not publishing. There is no defensible figure for the share of UK AI tenders that “now expect” ISO 42001. Several vendor pages publish one. We are not reproducing any of them, because we cannot tell you how they were counted, and the count we can do ourselves returns one notice.

Sources

  1. ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, ISO. Stage record: “60.60 2023-12-18 International Standard published”.
  2. ISO/IEC 42006:2025, Requirements for bodies providing audit and certification of artificial intelligence management systems, ISO. Stage record: “60.60 2025-07-07 International Standard published”. This is the document that made accredited certification to 42001 structurally possible.
  3. UKAS grants first AIMS accreditation, United Kingdom Accreditation Service, 15 January 2026. “UKAS has granted BSI the first accreditation for certification of artificial intelligence (AI) management systems to ISO/IEC 42001:2023.”
  4. BSI Assurance UK Ltd, UKAS Schedule of Accreditation (PDF), issue date 23 July 2026. Carries the granted scope “ARTIFICIAL INTELLIGENCE MANAGEMENT SYSTEMS / In accordance with ISO/IEC 17021-1:2015 and ISO/IEC 42006:2025 / ISO/IEC 42001:2023 Certification”.
  5. FIRST RAIL HOLDINGS LIMITED, “First Cyber Security Tooling & Managed Services Tender”, Find a Tender. Procurement identifier ocds-h6vhtk-069b2e; published 18 May 2026; £3,433,993. Names ISO 42001 among recognised frameworks; a second sentence carries the typo “CSO/IEC 42001”.
  6. Assuring a Responsible Future for AI, Department for Science, Innovation and Technology, published 6 November 2024. Source for the AI Management Essentials lineage (ISO/IEC 42001, the EU AI Act, the NIST AI RMF) and for the intent to embed it in government procurement policy and frameworks.
  7. Guidance for using the AI Management Essentials tool: government response, DSIT, published 6 February 2026. “DSIT will not be publishing AIME and therefore will not be making it a requirement of the government procurement process.” This document does not mention ISO/IEC 42001 — the lineage claim is cited to [6], not to this.
  8. PPN 017: Improving transparency of AI use in procurement, Cabinet Office, published 17 February 2025. Full text (PDF). The PDF’s own dateline reads “Originally issued: November 2023 / Updated: February 2025”, which contradicts the GOV.UK publication date; we cite the GOV.UK date. Full-text checked: contains neither “ISO” nor “42001”.
  9. Procurement Act 2023, legislation.gov.uk. Source for conditions of participation, award criteria and the proportionality requirement.
  10. AI Omnibus enters into force, European Commission, 27 July 2026. “On 27 July 2026, the AI Omnibus enters into force across the EU.” Source for the 2 December 2027 and 2 August 2028 high-risk application dates.
  11. Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI), Official Journal L, 24 July 2026; in force 27 July 2026. The high-risk application dates are stated at article level: “(i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I”. The sequence, because a wrong one circulates: proposal 19 November 2025, political agreement 7 May 2026, Regulation dated 8 July 2026, OJ 24 July 2026, in force 27 July 2026. There is no official act on 29 June 2026.
  12. BSI becomes the first certification body accredited by UKAS and RvA to deliver certification for ISO/IEC 42001, BSI press release, 17 November 2025. Recorded here because it conflicts with [3] on the date of the UKAS grant. We prefer the UKAS date and state both rather than choosing silently. BSI’s RvA (Netherlands) accreditation dates from 9 December 2024, which is why this page never says “first in the world”.
  13. ISO/IEC 23894:2023, Information technology — Artificial intelligence — Guidance on risk management, ISO. Published 2023-02. Guidance, not a certifiable requirements standard.
  14. PPN 025: Protecting the UK’s national security through public procurement, Cabinet Office, published 19 June 2026. Names artificial intelligence as one of four critical national-security sectors with DSIT as Sector Lead; applies only to central government departments, their executive agencies and non-departmental public bodies. GOV.UK is internally inconsistent on the date (collection listing says 3 July 2026); we use the publication page date. Full-text checked: contains neither “ISO” nor “42001”.
  15. rfp.quest corpus, read live at the moment this page was served. 753,990 UK notices ingested from Find a Tender and Contracts Finder under the Open Government Licence v3.0, most recent published 19 August 2026. Requirement counts are produced by the extractor at src/lib/requirements/extract.ts, classifier version 5, whose last full scan covered 745,098 notices on 1 August 2026; matches are against notice title and description only, each with a stored evidence sentence. The AI-demand series is a phrase match for “artificial intelligence” against the search index built over each notice’s title and description, expressed as a rate per 10,000 notices published in the same year, with the per-year totals taken from the same daily-refreshed aggregate the Observatory divides by. A phrase match on an index is not a substring match: it reads slightly lower than a raw text scan (93 against 97 in 2026), and it is used because a full text scan of the corpus cannot complete inside a single request. The trend is identical either way and the trend is the only thing claimed. Unlike this page’s sibling Descent pages, no figure here is a stamped literal — every one is re-read hourly, so a reader and a later auditor see the same number.
  16. UKAS accredited-body schedules of accreditation, United Kingdom Accreditation Service. Counted 17 August 2026 by an exhaustive sweep rather than a keyword search, because CertCheck caps its result set: every management-systems schedule number from 0001 to 4000 was probed, 54 exist, and 5 carry an artificial intelligence management systems scope citing ISO/IEC 42006:2025 — BSI Assurance UK Ltd (0003, issue 192, 23 July 2026), schedule; LRQA Limited (0001, issue 220, 24 June 2026); NQA Certification Ltd (0015, issue 194, 5 May 2026); ISOQAR Limited (0026, issue 160, 4 June 2026); TUV UK Limited (0065, issue 059, 8 June 2026). Cross-checked against the UKAS AIMS development page’s pilot list of seven: Intertek Certification Ltd holds no 42001 scope and Schellman Compliance LLC is not a UKAS certification body. The sweep covers the management-systems schedule type only.