How to use this checklist
Use the checklist to build an audit programme and working papers around your actual AIMS. Start with the audit criteria: the licensed ISO/IEC 42001:2023 standard, your organisation’s own AIMS requirements and the controls declared applicable in your Statement of Applicability.
Planning aid, not the standard. This page paraphrases practical audit checks. It does not reproduce ISO text, guarantee conformity or replace professional judgement.
Set scope and sampling according to AI risk, process importance, recent change and previous results. Record the evidence actually examined and the conclusion actually reached; a completed tick box with no sample trail is not an audit record.
Pre-audit evidence pack
Ask for the source records early enough to select samples before interviews. The list is a starting point; the final request should follow the agreed AIMS scope and Statement of Applicability.
- Approved AIMS scope, AI policy, objectives and assigned responsibilities
- Current AI system inventory, including externally supplied and embedded AI
- AI risk assessments, impact assessments and treatment decisions
- Statement of Applicability with implementation status and justification
- Lifecycle, data, human-oversight, transparency and supplier records
- Competence, awareness, communication and document-control evidence
- Monitoring results, incidents, complaints and performance trends
- Management-review outputs, previous findings and corrective actions
Clauses 4–10 audit checks
Test whether the management system is designed coherently and whether its processes operate. Documents show design; interviews, decisions and retained records show implementation.
| Clause | Requirement area | Audit question | Evidence to request | Common finding |
|---|---|---|---|---|
| 4 | Context and scope | Does the AIMS boundary match the organisation, interested parties and AI systems actually governed? | Approved scope, context analysis, interested-party register and reconciled AI inventory. | An in-use or embedded AI system sits outside the documented AIMS scope without a defensible reason. |
| 5 | Leadership | Are accountability, policy, roles and management commitment visible in current decisions and records? | Approved AI policy, role assignments, governance minutes, decisions and resource approvals. | Roles exist on paper, but approvals or escalations show that nobody exercises the assigned authority. |
| 6 | Planning | Are AI risks, impacts, opportunities, objectives and treatment decisions current, traceable and owned? | Risk register, impact assessments, objectives, treatment plan and acceptance records. | An impact assessment was completed once but was not updated after a material system or use-case change. |
| 7 | Support | Do resources, competence, awareness, communication and document controls support the AIMS? | Competence records, awareness material, communications, document register and access history. | A control owner performs AI governance work but has no defined competence requirement or supporting record. |
| 8 | Operation | Do planned AI governance processes operate through the AI system life cycle? | Approvals, design records, testing, monitoring, change, supplier and retirement records. | The documented approval or monitoring step is not present in the sampled release or operating record. |
| 9 | Evaluation | Do monitoring, measurement, internal audit and management review produce evidence and management action? | Metrics, audit programme, audit reports, management-review inputs, minutes and decisions. | Management review records attendance and discussion but no decisions, actions or resource changes. |
| 10 | Improvement | Are nonconformities corrected, root causes addressed and effectiveness verified? | Corrective-action register, root-cause record, follow-up sample and closure approval. | A finding is marked closed after the immediate correction with no root-cause action or effectiveness check. |
Annex A evidence themes
Sample applicable controls against the organisation’s Statement of Applicability. Do not treat this theme list as a substitute for the licensed control requirements.
A.2
Policies related to AI
Approval, communication, review history and evidence that the policy drives operating decisions.
A.3
Internal organisation
Accountable roles, reporting paths, segregation and escalation for AI-related decisions.
A.4
Resources for AI systems
Documentation, data, tooling, compute and competent people available across the system life cycle.
A.5
Assessing AI impacts
Repeatable impact assessments performed per relevant AI system, reviewed after meaningful change and linked to treatment.
A.6
AI system life cycle
Requirements, design, verification, validation, deployment, operation, monitoring and retirement records.
A.7
Data for AI systems
Provenance, quality, preparation, access, representativeness and retention decisions supported by evidence.
A.8
Information for interested parties
Transparency, instructions, limitations, incident communication and reporting mechanisms.
A.9
Use of AI systems
Responsible-use requirements, human oversight and operation within intended purpose and limits.
A.10
Third-party and customer relationships
Supplier due diligence, shared responsibilities, contractual controls and change notification.
Sampling and interviews
Select samples that can challenge the system: higher-impact AI systems, recent releases, incidents, exceptions, material suppliers, systems using sensitive data and controls changed since the last review. Record the population, sample rationale and items selected.
Interview the accountable owner and the people doing the work. Reconcile what they describe against inventories, approvals, logs, model documentation, impact assessments and supplier records. Where an automated control is relied on, inspect its configuration and output rather than accepting a screenshot of the setting alone.
Record findings so they can be closed
A finding must be traceable from requirement to evidence to conclusion. Keep these fields in the audit file:
- 1Audit criterion: the clause, applicable control or internal AIMS requirement tested
- 2Objective evidence: the record, interview or observation that supports the conclusion
- 3Conclusion: conformity, nonconformity or opportunity for improvement
- 4Finding statement: requirement, evidence and the precise gap—without prescribing the solution
- 5Correction and root cause: immediate fix plus why the gap was able to occur
- 6Corrective action, owner and date: the durable change and accountable person
- 7Effectiveness check: follow-up evidence showing the action worked before closure
Editable working file
Download the ISO 42001 internal audit checklist
The CSV includes clause and Annex A theme prompts plus fields for evidence, result, finding reference, owner and due date. Adapt it to your scope and licensed audit criteria.
Download editable CSVProtect auditor objectivity and impartiality
Document who selected the auditor, which AIMS work they designed or operate, and how conflicts are avoided. The clearest boundary is that a person does not audit their own work.
Aegentra does not perform the internal audit where Aegentra implemented the AIMS. For systems built in-house or by another provider, see our independent ISO 42001 internal audit service. For the wider certification sequence, see the ISO 42001 guide for Australia.
The checklist helps organise workpapers; it does not turn a conflicted reviewer into an impartial auditor.
FAQs
No. This is an independent planning aid created by Aegentra. It paraphrases practical audit checks and does not reproduce or replace ISO/IEC 42001:2023. Your audit criteria must include the licensed standard, your AIMS requirements and the controls your organisation has declared applicable.
The audit programme must cover the AIMS over its planned cycle. The scope and sampling for an individual audit should reflect process importance, AI risk, change, previous findings and the Statement of Applicability. A checklist should support that judgement, not replace it.
The organisation must select auditors and run the audit so objectivity and impartiality are protected. Someone should not audit controls or AIMS work they designed, implemented or operate. Small teams often use an independent external auditor for that reason.
Start with the AIMS scope, AI policy, AI system inventory, AI risk and impact assessments, Statement of Applicability, objectives, competence records, operational records, monitoring results, management-review outputs, previous findings and corrective-action evidence.
The internal audit is the Clause 9.2 assurance activity your organisation must arrange. Certification Stage 1, Stage 2 and surveillance audits are separate and are performed by an accredited certification body. Aegentra provides internal audit services; it does not issue ISO 42001 certificates.