Registrar Index

Guides

The 9001 → 27001 → 42001 path

Why mid-market manufacturers and professional-services firms should treat quality, information security, and AI management as a sequence — not three disconnected badges.

2026-08-20 · 16 min

There is a fashionable way to buy ISO certificates: collect logos. There is a more durable way: build one management-system habit and extend it.

Registrar Index uses a simple framing for mid-market manufacturing and professional services:

Quality → security → AI governance.

That maps to ISO 9001, ISO/IEC 27001, and ISO/IEC 42001. Environmental and safety systems (14001, 45001) sit beside quality as an operations stack. They are important. They are not a substitute for information-risk discipline if you are about to certify AI.

Why the order is not a religion — but it is a default

You can certify 27001 without 9001. Many software firms do. You can pursue 42001 without 27001. Fewer should.

The default order exists because of how evidence works:

  1. 9001 teaches you to define processes, owners, documented information, internal audit, and management review. Without that, every later standard becomes a documentation project.
  2. 27001 teaches you to scope information assets, assess risk, treat risk, and operate controls. AI systems are information systems with extra impact modes.
  3. 42001 asks for an AI management system — policy, impact, lifecycle, and supplier control around AI. It assumes you can already run a management system and talk about risk without theater.

Skipping steps is how organizations buy a 42001 project that is actually a missing ISMS, then discover their CB’s AIMS accreditation does not cover the way they use third-party models.

Manufacturing versus professional services

Manufacturers usually cannot skip 9001. Customers, primes, and export paperwork still start there. Many will add 14001/45001 before they ever hear a 27001 questionnaire. That is rational. The mistake is treating plant AI (vision inspection, scheduling, copilots) as a facilities project with no security or AIMS owner.

Professional-services and IT-led firms often meet 27001 first. 9001 may still help if you deliver repeatable client work. 42001 becomes relevant when you embed models in delivery, not when you have used a chatbot once.

This directory does not cover construction-specific AI products. The path here is operations quality, enterprise security, and AI governance.

What “integrated” should mean in year two

Annex SL gives you shared clauses: context, leadership, planning, support, operation, performance evaluation, improvement. Use that. Do not write three document-control procedures.

A practical target operating model:

  • One internal-audit program with specialist modules.
  • One management review with a security and AI section, not a separate executive meeting that never happens.
  • One supplier-risk process that can see both heat-treat vendors and model vendors.
  • Certificate strategy decided on purpose: one CB versus a factory CB plus a security CB.

Read the integrated path page for the buying pattern.

Accreditation will not move at the same speed

9001 and 14001 CBs are plentiful. Accredited 42001 CBs are fewer, and the list is changing. Publicly discussed names in 2024–2026 include Schellman (early ANAB AIMS), SGS, BSI, LRQA, DNV, Intertek SAI Global, and DEKRA — among others. Treat that as a research queue. Confirm each entity’s current schedule before Stage 1.

If your preferred 9001 registrar cannot yet issue an accredited 42001 certificate, you have three honest options:

  • Wait and keep the ISMS tight.
  • Add a second CB for AIMS.
  • Switch later, with a planned transfer.

There is no fourth option called “the brochure said they do AI.”

Readiness is not the audit

Certification bodies are independent. They should not design the system they later certify. Gap assessments they sell are bounded; implementation is yours or a consultant’s.

If the missing piece is executive ownership — who may approve a model, what “good” looks like in 90 days, how the board hears risk — that is governance readiness, not a registrar problem. Chris Daigle / ChiefAIOfficer.com works that problem for mid-market teams. Use it if you need an operating cadence. Do not confuse it with an accredited certificate.

A 24-month sketch (not a quote)

This is a planning sketch, not a priced project plan:

Window Focus
Months 0–6 9001 stable (or 27001 first if you are ISMS-led). Internal audit actually finds things.
Months 6–14 27001 scoped. SoA real. Privileged access and supplier security no longer tribal knowledge.
Months 12–24 42001 only if AI is material. Confirm CB accreditation again. Integrate evidence with 27001.

EHS certificates can land in parallel with 9001 if customers require them.

What to do this week

  1. Write down which certificates are customer-gated versus internally fashionable.
  2. Open the directory and shortlist CBs that list your next standard — then verify accreditation off-site.
  3. Read how to choose a registrar and what quotes include.
  4. Send one scope pack via Get quotes.