Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 42001 internal audit explained

ISO 42001 Internal Audit: A Clear 2026 Guide to Clause 9.2

An ISO 42001 internal audit is the check you run on your own AI management system before a certification body runs theirs. Clause 9.2 of ISO/IEC 42001:2023 requires it, a stage 2 auditor will refuse to proceed without evidence of it, and — done properly — it is the single cheapest way to find out whether your AI governance works or merely exists on paper.

This guide covers what clause 9.2 actually asks for, how an AI management system audit differs from the ISO 27001 audits most teams already know, what to sample, and the findings that come up again and again in first-year systems.

ISO 42001 internal audit: the six things clause 9.2 requires you to show
Clause 9.2 is short. The evidence it expects is not.

What clause 9.2 requires of an ISO 42001 internal audit

Clause 9.2.1 says the organization shall conduct internal audits at planned intervals to provide information on whether the AI management system conforms to the organization’s own requirements and to the requirements of the standard, and whether it is effectively implemented and maintained. Clause 9.2.2 then asks for an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, and says the programme shall consider the importance of the processes concerned and the results of previous audits.

Three further requirements sit inside 9.2.2 and are the ones certification auditors check first:

  • Audit objectives, criteria and scope are defined for each audit — not once for the programme.
  • Auditors are selected, and audits conducted, so that objectivity and impartiality are preserved. The person who wrote the AI policy does not audit the AI policy.
  • Results are reported to relevant managers, and documented information exists as evidence of both the programme and the results.

The wording of the ISO 42001 internal audit clause is deliberately generic — it is the harmonized management-system text that ISO 27001, ISO 9001 and the rest also use. What makes an ISO 42001 internal audit different is not the clause; it is what you have to look at to satisfy it.

How an ISO 42001 internal audit differs from an ISO 27001 one

If your organization already runs an information security management system, the temptation is to bolt AI onto the existing audit programme and reuse the checklist. That works for the shared clauses (4 to 10) and fails for everything that makes 42001 its own standard.

Area ISO 27001 audit looks at ISO 42001 internal audit looks at
Unit of scope Information assets and the controls around them AI systems — each one, across its life cycle, plus the data and models behind it
Risk artefact Information security risk assessment (6.1.2) AI risk assessment (6.1.2) and AI system impact assessment (6.1.4, 8.4) — two documents, two subjects
Control reference Annex A, 93 controls in 4 themes Annex A, 38 controls in 9 sections (A.2–A.10), with Annex B implementation guidance
Who is affected The organization and its interested parties Individuals, groups and societies outside the organization — explicitly
Typical evidence Access logs, change records, incident tickets Impact assessments, data provenance records, verification and validation results, human oversight logs, event logs from the AI system
Hardest question Is the control operating? Is the AI system doing what the impact assessment said it would — and to whom?

The practical consequence: a combined audit is fine, but the AI portion needs its own working papers, its own sampling of AI systems, and at least one auditor who understands what a model card or a validation report is supposed to contain. Our guide to ISO 27001 vs ISO 42001 sets out the structural overlap in more detail.

Planning the ISO 42001 internal audit programme

Clause 9.2.2 wants a programme, and the standard tells you what should drive it: the importance of the processes and the results of previous audits. For an AI management system, importance is not evenly distributed, so a flat “audit every clause once a year” plan is defensible but wasteful. A better programme is built around your AI system inventory:

  1. List every AI system in scope, with its role (developer, provider, user) and the impact rating from its impact assessment.
  2. Weight the programme by impact. A system that makes or informs decisions about people gets audited end to end every cycle. An internal summarisation tool gets sampled.
  3. Cover every clause and every applicable Annex A control at least once in the three-year certification cycle, with clauses 6, 8 and 9 every year. Certification bodies expect the whole system to have been through an ISO 42001 internal audit before stage 2.
  4. Feed back previous findings. Where the last audit raised a nonconformity, the next audit tests the corrective action, not just the original requirement.
  5. Fix the method per audit — document review, interviews, walkthrough of a system’s life cycle, technical sampling — and the auditor, with a note on why they are independent of the area.

ISO 19011 remains the reference for audit method; ISO 42001 cites it directly in its definition of audit. You do not need a separate methodology for AI, only AI-specific criteria and evidence.

What to sample: the ISO 42001 internal audit checklist that matters

A clause-by-clause checklist is a starting point for an ISO 42001 internal audit, not the audit itself. The following is what an experienced auditor actually pulls, grouped by where first-year systems fail.

Planning (clause 6)

  • The AI risk criteria (6.1.1) — do they exist as a document, and can the risk owner explain what “acceptable” means in practice?
  • The AI risk assessment (6.1.2) — does it identify risks against the AI objectives, analyse consequences to the organization, individuals and societies, and prioritise for treatment? Repeat it for one system and see whether you get comparable results, because 6.1.2 b) requires that.
  • The Statement of Applicability (6.1.3 f) — is every Annex A control either included with a justification or excluded with one? Check three included controls back to the documents that implement them.
  • The AI system impact assessment (6.1.4) — one per system or group of systems, covering intended use and foreseeable misuse, with the jurisdiction noted. See our guide to the AI system impact assessment for what a defensible one contains.

Operation (clause 8)

  • Evidence that the risk treatment plan was implemented and its effectiveness verified (8.3) — not just written.
  • Impact assessments repeated at planned intervals or when significant changes were proposed (8.4). Pick a system that changed model or vendor this year and ask for the re-assessment.
  • Life-cycle records under A.6.2: requirements and specification, design documentation, verification and validation results, a deployment plan, operation and monitoring records, technical documentation, event logs. For one system, walk the chain end to end.

Data and third parties (A.7 and A.10)

  • Data provenance and data quality records (A.7.4, A.7.5) for the training and test data of one model.
  • Supplier and customer responsibilities (A.10.2–A.10.4) — who is accountable for what when the model is bought in, and where is that written down?

Performance and improvement (clauses 9 and 10)

  • Monitoring results (9.1) — what was measured, by what method, and whether anyone evaluated it.
  • Management review minutes (9.3) containing the inputs the standard lists: previous actions, changes in issues and interested parties, trends in nonconformities, monitoring results and audit results.
  • Nonconformities and corrective actions (10.2) with root cause, not just a fix.

ISO 42001 internal audit findings that recur in first-year systems

Finding Why it happens What closes it
Impact assessment lists ‘users’ as the only affected group The assessment was written by the product team about the product Re-run it with someone outside the team naming the people decided about, excluded or displaced
Risk assessment and impact assessment are the same document with two titles Teams conflate organizational risk with impact on others Split them: 6.1.2 is risk to objectives, 6.1.4 is consequence to individuals and societies; 6.1.4 feeds 6.1.2, not the other way round
Statement of Applicability marks all 38 controls as applicable with no justification Copied from an ISO 27001 SoA habit Justify each inclusion against the risk treatment plan; exclusions are allowed if the risk assessment does not need the control
No re-assessment after a model change Change control lives in engineering; the AIMS never hears of it Add a trigger in the change procedure: material model, vendor or use change → impact assessment review (8.4)
Human oversight is described in policy but nobody can produce a record of it happening Oversight was designed as a principle, not a process Define the review points, log them, and sample the log in the audit
Auditor is the AIMS manager Small teams, one competent person Use a trained auditor from another function, or an external auditor for the AI-specific parts — 9.2.2 b) is explicit about impartiality

Reporting and what happens next

The ISO 42001 internal audit report goes to the managers responsible for the areas audited — 9.2.2 c) says so — and its findings become inputs to the management review under 9.3.2 d) 3). Classify findings as major nonconformity (a requirement is missing or systemically failing), minor nonconformity (an isolated lapse) or observation, and write each against the specific clause or Annex A control so the corrective action owner does not have to interpret it.

Then run the corrective action process in clause 10.2 on every ISO 42001 internal audit finding: react, evaluate the cause, act, review effectiveness, and keep the record. Certification auditors read your internal audit report and your corrective action log together; a report with no follow-through is worse than no report, because it shows the system does not respond to its own evidence.

Frequently asked questions

Is an ISO 42001 internal audit mandatory before certification?
Yes. Clause 9.2 is a requirement of the standard, and certification bodies expect at least one complete internal audit and a management review before the stage 2 audit.

Can we use our ISO 27001 internal auditors?
For the shared management-system clauses, yes. For the AI-specific evidence — impact assessments, data provenance, verification and validation, human oversight — they need training in what those artefacts should contain, or you pair them with someone who has it.

How often should the ISO 42001 internal audit run?
The standard says planned intervals and leaves the interval to you. Annual full coverage is the common practice, with higher-impact AI systems audited more often and every clause covered within the three-year certification cycle.

Does the internal audit have to cover every AI system?
Every system in scope should be covered over the cycle. Within a single audit, sample by impact: high-impact systems end to end, lower-impact ones by rotation.

Can an external consultant perform it?
Yes. ISO 42001’s own definition of audit notes that an internal audit can be conducted by an external party on the organization’s behalf. It remains a first-party audit, and the impartiality requirement still applies.

Where this leaves you

Treat the ISO 42001 internal audit as a rehearsal for the questions a certification auditor will ask, run by someone who is allowed to give you bad news. Build the programme around your AI system inventory rather than the clause list, sample the life cycle of at least one high-impact system end to end, and make sure the findings reach management review and the corrective action log. That closes the loop the standard is really testing: not whether the documents exist, but whether the organization acts on what they reveal.

References

  • ISO/IEC 42001:2023 — the AI management system standard; clause 9.2 sets the internal audit requirement.
  • ISO 19011:2018 — guidelines for auditing management systems, cited by ISO 42001 for audit method.

More on AI governance

An internal audit procedure, annual audit plan, audit summary report, action log and nonconformity report for the AIMS are included in the ISO 42001 Toolkit (68 templates), or start with the free ISO templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.