What “AI governance” actually costs in time, from someone who checked
By Jermaine F. Barker · Founder & CEO, JMCB Technology Group
I keep seeing the same pitch. Some vendor promises "fully governed AI in 30 days," usually right next to a logo wall and a stock photo of a handshake. I used to just roll my eyes and move on. Then I decided to actually check the published timelines for the two frameworks everyone name-drops, NIST's AI Risk Management Framework and ISO/IEC 42001, and write down what I found. Short version: nobody who has actually read these documents would say 30 days with a straight face.
This isn't a knock on governance. It's the opposite. I think the discipline is worth having. But I'd rather tell you the real number and let you plan around it than sell you a fantasy and let you find out the hard way, three weeks into a project that was never going to make its date.
NIST AI RMF: not a certification, a discipline
First thing worth knowing: NIST AI RMF isn't something you get certified against, and it isn't a finish line. NIST itself describes it as intended for voluntary use, built around four functions that run on a loop rather than a checklist: Govern, Map, Measure, and Manage. It was published January 26, 2023, and NIST has kept adding to it since, including a Playbook and a Trustworthy and Responsible AI Resource Center meant to help organizations work through it in practice.
That structure matters for the 30-day claim, because there's no version of "stand up Govern, Map, Measure, and Manage" that is a one-time task you complete and file away. It's an ongoing management loop, the same way your accounting isn't something you finish in January and never touch again. Anyone telling you they'll have you "NIST AI RMF compliant" in a month is selling you a category error, because compliant in the certification sense isn't what this framework offers. What it offers is a structure for a process you keep running.
ISO 42001: the one with an actual clock on it
ISO/IEC 42001 is different. It's an actual certifiable management system standard, with real auditors and a real certificate at the end, which means it also has real, published timelines you can check instead of guess at.
ISMS.online, one of the compliance platforms that runs organizations through this process, publishes the range plainly: an organization starting from zero should expect five to nine months from kickoff to a passed Stage 2 audit. If you already hold ISO 27001 certification and can reuse that management system's risk processes and controls, that compresses to three to five months. Their fastest quoted case, a mature ISO 27001 shop with a tight scope, dedicated program management, and platform support doing a lot of the heavy lifting, is eight to twelve weeks. That's the best case they publish, not the typical one, and it's still two to three times longer than 30 days.
Schellman, an accredited ISO certification body that actually performs these audits, breaks down what happens inside that window. The Stage 1 audit, which checks whether your documentation and readiness are even in shape for a real audit, typically runs one to two days. Then there's a gap before Stage 2, typically four to twelve weeks, and by Schellman's own guidance it shouldn't stretch past six months or the certification body will want to re-check your readiness. Stage 2, the audit that actually decides certification, runs three to nine-plus days depending on organization size. After you're certified, it's not over: annual surveillance audits run for the three-year life of the certificate, each one roughly a third the length of the original review.
Add that up and the honest floor, for a small, well-prepared organization with an existing ISO 27001 program, is around three months. For everyone else, closer to six to nine. None of that includes the work before Stage 1 even happens: the gap assessment, writing the policies, building the risk register, training staff on a system that didn't exist yet. That work isn't optional and it isn't fast, because the auditors are specifically checking whether it was done properly, not whether it exists on paper.
Why the 30-day pitch survives anyway
I think the confusion is mostly a language problem, and vendors have learned to exploit it. "Governed" can mean two very different things. It can mean the internal discipline I described in an earlier post here: access controls, audit logging, a human checkpoint where the stakes justify it, a named owner for what the system does. That kind of internal governance, scoped to one workflow, can genuinely take shape inside a 90-day build, and I stand by that timeline for what it actually covers.
Or "governed" can mean formally certified against a named external standard, with an accredited third party signing off on it. That's the ISO 42001 path, and the published numbers above are what that actually costs in time. Selling the second thing with the first thing's timeline is where the lie lives. Nobody who reads Schellman's own audit breakdown would promise a Stage 2 pass in 30 days, because the vendor doesn't control the auditor's calendar, and the standard requires evidence of a working system, not a freshly written policy binder.
If someone quotes you a 30-day timeline for certified governance, ask them one question: which stage, exactly, happens in week one, which in week two, and who is the accredited body doing your Stage 2 audit on that schedule. Watch how fast the specificity disappears.
What to actually plan for
If you want internal governance controls around a single AI workflow, that 90-day build I described in my pilots post is still the right target. If you want an actual ISO 42001 certificate, plan for a minimum of three months if you already have ISO 27001 and a realistic six to nine if you don't, and build your roadmap around the certification body's calendar, not your marketing calendar. If you're working from the NIST AI RMF, stop looking for a finish date, because there isn't one. It's a loop you run, and the honest measure of progress is whether Govern, Map, Measure, and Manage are actually happening this quarter, not whether you can check a box that says done.
None of this is a reason to skip governance. It's a reason to scope it honestly, on its own timeline, the same way I'd tell you to scope a procurement cycle separately from a build. If you want help figuring out which kind of "governed" your organization actually needs, and on what real calendar, the free AI readiness assessment is a five-minute way to start that conversation honestly.