Clause 9.2 requirement
Internal audit
Tests whether the AIMS conforms to your requirements and ISO/IEC 42001, and whether it is effectively implemented and maintained.
Performed by objective, impartial auditors. This is Aegentra’s role.
/ ISO/IEC 42001 · Clause 9.2
Independently run. Evidence-led. Certification-ready.
An ISO/IEC 42001 internal audit is the Clause 9.2 review of whether your AI management system conforms to your own requirements and the standard—and whether it is effectively implemented and maintained.
Aegentra plans the audit, reviews Clauses 4–10 and the Statement-of-Applicability decisions, then samples applicable Annex A controls using AI risk, process importance, change and prior results. We report traceable findings and verify agreed corrective-action close-out. We audit; an accredited certification body certifies.
Delivered across Australia — all states and territories — with remote delivery and onsite attendance by arrangement. New Zealand and wider Asia Pacific engagements may be available by arrangement.
/ Delivery team
The audit record identifies the accountable lead, the assigned auditor, any specialist support and how objectivity is protected before fieldwork begins.
Responsibility
Assigned role
How it is confirmed
Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.
Qualifications, professional credentials and formal training held across Aegentra’s delivery team.
Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.
NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.
Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.
The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.
The assigned auditor retains responsibility for audit judgements and conclusions. Aegentra is not the certification body.
Open the engagement record / Featured ISO 42001 case study
August 2026A mid-market SaaS provider had committed to an ISO/IEC 42001 certification audit while its AI inventory, risk method, impact assessments, accountability and supplier controls were still incomplete. This anonymised engagement record shows what changed before the deadline.
Client name withheld. Identifying details are generalised; the findings, sequence and reported outcome reflect the supplied engagement record.
Read the full case study/ Scope and price
Available for smaller organisations with a clearly defined AIMS scope and limited AI-system complexity. Final fixed pricing depends on the AIMS scope, AI systems, locations, evidence volume and sampling requirements.
The scope, evidence request, fieldwork dates, deliverables and fee are agreed before work begins. Certification-body fees are separate.
Request a fixed-scope audit quoteISO 42001 internal audit at a glance
/ Published credential evidence
Director and Principal Consultant, Aegentra
Harry Sidhu is the named principal consultant for Aegentra’s Govern practice. Implementation and internal-audit work are accepted as separate engagements, with independence and conflict checks applied before any audit scope is confirmed. His published credential and issuer-verification link are shown below.
The written audit scope names the lead, any additional delivery roles, the criteria, sampling rationale and independence safeguards. Aegentra does not represent a credential or clearance as team-wide unless the named holder and evidence are published.
Harry’s published PECB Certified ISO 27001 Lead Implementer credential, certificate no. 9303577-2026-05, can be checked using PECB’s verification tool. It is an ISO 27001 implementation credential shown for practice accountability; it is not an ISO 42001 auditor credential and does not identify the auditor assigned to this engagement. Aegentra does not perform the internal audit where Aegentra implemented the AIMS.
/ Choose the right audit
Clause 9.2 requires an internal audit. A readiness review can help you prepare, but cannot be relabelled as that audit. Certification is a separate independent decision by an accredited certification body.
Clause 9.2 requirement
Tests whether the AIMS conforms to your requirements and ISO/IEC 42001, and whether it is effectively implemented and maintained.
Performed by objective, impartial auditors. This is Aegentra’s role.
Optional diagnostic
Identifies gaps before formal audit activity. Useful, but it does not replace the documented internal audit programme Clause 9.2 requires.
Performed before the internal or certification audit when additional preparation is needed.
Independent certification
Stage 1 and Stage 2 determine whether an accredited certificate can be issued. Surveillance follows during the certification cycle.
Performed by an accredited certification body—not by Aegentra.
/ Audit coverage
The audit criteria include ISO/IEC 42001:2023, your organisation’s own AIMS requirements and the controls you declared applicable. Sampling follows the risks, processes and AI systems inside the agreed scope.
View ISO/IEC 42001 at ISO.orgClauses 4–6
AIMS scope, interested parties, AI policy, accountable roles, AI objectives, risk assessment and treatment decisions.
Clauses 7–8
Competence, awareness, documented information, operational controls and the way AI systems move through their life cycle.
Clauses 9–10
Monitoring, measurement, management review, previous audit results, nonconformity and corrective action.
Annex A
Applicable controls across policies, organisation, resources, impact assessment, life cycle, data, transparency, use and suppliers.
Your AIMS
The policies, procedures, Statement of Applicability and commitments your organisation has chosen—not only the standard text.
Evidence
AI inventory records, impact assessments, approvals, monitoring, oversight, supplier reviews, incidents and retained evidence.
/ Evidence sampling
The audit begins with the agreed criteria and follows evidence through the systems and processes inside scope. Samples are selected to challenge the AIMS: higher-impact systems, recent changes, exceptions, incidents, material suppliers and areas with previous findings.
SAMPLE 01
We reconcile scope, policy, objectives, accountable roles and management decisions. The test is whether leadership governs the AIMS through current decisions, resources and review—not whether a policy file exists.
SAMPLE 02
We compare the declared inventory with procurement, identity, cloud, product and supplier records to find embedded or externally supplied AI that may sit outside the governance team’s working list.
SAMPLE 03
We sample whether AI risks and impacts were assessed per relevant system, revisited after meaningful change and connected to treatment, approval, human oversight and measurable objectives.
SAMPLE 04
For developed or materially configured systems, we follow requirements through design, verification, validation, release, monitoring, change and retirement records. A process description alone does not prove the process operated.
SAMPLE 05
Samples can cover provenance, quality, preparation, access, representativeness, retention, user information, limitations and incident communication—selected according to the systems and impacts inside the AIMS scope.
SAMPLE 06
We test due diligence, shared responsibilities, contractual controls, change notifications, complaints, incidents and approved exceptions. These records show whether governance holds when normal operating assumptions break.
/ Engagement boundaries
We deliver the Clause 9.2 internal audit. Stage 1, Stage 2, surveillance and the certificate remain the responsibility of an accredited certification body selected by the client.
Where Aegentra implemented the AIMS, we recommend a separate independent provider. The audit should be objective, impartial and straightforward to defend when the certification body reviews it.
The audit plan follows AI risk, process importance, previous results, recent change and the Statement of Applicability. It does not promise that the same fixed sample fits every organisation.
Close-out requires evidence of correction and, for nonconformities, action addressing root cause. The final status records what was verified, when it was verified and what remains open.
/ Supported technical evidence
Where the agreed scope includes supported Microsoft 365 evidence, Aeges can collect current technical configuration evidence read-only and help identify changes in control state. It is an evidence source—not the auditor.
Supported Microsoft 365 configuration evidence can be reproduced on demand instead of relying only on point-in-time screenshots.
The collected evidence can support requirement and control traceability, while policies, interviews, management decisions and non-Microsoft systems retain their own records.
The human auditor sets the criteria, selects samples, evaluates conformity and owns every finding and conclusion in the issued audit report.
/ The audit file
Every conclusion must be traceable. Your final pack shows what was tested, what evidence supported the conclusion, where the AIMS did not conform and what needs to happen next.
The criteria, scope, methods, schedule, interviewees and initial evidence list are agreed before fieldwork.
Each sample connects the requirement tested, evidence reviewed, interview performed and conclusion reached.
Nonconformities and improvement opportunities are mapped to the exact clause or control and supported by evidence.
Owners, actions and dates are tracked, then the evidence of correction is reviewed before closure.
/ Engagement sequence
The schedule and fixed fee are confirmed after the AIMS scope, systems, locations, evidence access and sampling needs are understood.
Scope
We review the AIMS boundary, AI estate, locations, previous results and Statement of Applicability, then agree the audit programme and fixed fee.
Fieldwork
We interview control owners and sample records, model documentation, approvals, monitoring and logs against the criteria in the plan.
Report
Every finding identifies the requirement, observed evidence and gap. The register is walked through with accountable management.
Close-out
Corrective actions are prioritised and follow-up evidence is reviewed so open issues do not drift into the certification audit.
/ Method and working resources
Use the checklist to prepare your evidence, then inspect an ISO 42001 engagement that moved from serious AI-governance gaps to certification readiness in eight weeks.
Free working resource
Prepare the evidence pack, work through Clauses 4–10 and Annex A themes, record sampling and download the editable CSV—without an email gate.
Open the audit checklistISO 42001 engagement record
A mid-market SaaS provider had eight weeks to correct its AI inventory, risk method, impact assessments, accountability and supplier controls before the external audit.
Read the ISO 42001 case studyBuilding impartial audit capability inside a larger team? The PECB ISO 42001 Lead Auditor course teaches the audit method; training does not remove a conflict where the same person designed or operates the controls being tested.
/ Integrated audit programme
ISO 27001 and ISO 42001 share the Annex SL management-system structure. Where scopes align, a combined programme can test shared processes once and sample the standard-specific controls separately—without confusing which requirement each finding belongs to.
/ Frequently asked questions
/ Scope the audit
Bring the AIMS scope, AI inventory, Statement of Applicability and target certification date. We will confirm the evidence request, sampling approach, schedule and fixed fee before fieldwork.