Clause 9.2 of ISO/IEC 42001 requires your AI management system to be audited at planned intervals — by someone objective and impartial. If you built your AIMS in-house or with another consultant, you cannot credibly audit your own work. We run the independent internal audit your certification cycle requires: audit plan, evidence sampling across Clauses 4–10 and the 38 Annex A controls, findings register, and corrective-action close-out. We audit; a JAS-ANZ-accredited body certifies.
ISO/IEC 42001 Clause 9.2 requires you to conduct internal audits at planned intervals to determine whether your AI management system conforms to both your own requirements and the requirements of the standard, and whether it is effectively implemented and maintained. The clause is explicit about auditor selection: the audit programme must ensure objectivity and impartiality of the audit process. In practice that means the people who designed your AI governance controls cannot be the people who test them. You also have to plan the programme against the importance of the processes concerned and the results of previous audits, define criteria and scope for each audit, report results to relevant management, and retain documented evidence of the programme and its outcomes. A certification body will ask to see all of it at Stage 1.
AI governance is new, and the teams running it are small. The person who wrote your AI system impact assessment methodology is usually the same person who maintains the AI inventory, chairs the AI governance forum, and would otherwise be nominated as internal auditor. That fails the impartiality test in Clause 9.2, and certification auditors know exactly where to look for it — an internal audit report signed by the AIMS owner is one of the fastest routes to a nonconformity at Stage 2. Outsourcing the internal audit solves the problem outright: you get an auditor with no stake in the controls under test, a documented independence position, and a report that survives scrutiny from the certification body.
The audit covers the management-system clauses and the AI-specific control set. On the clause side we test context and scope of the AIMS, leadership and AI policy, AI risk assessment and treatment, objectives and planning, competence and awareness, documented information, operational planning and control, performance evaluation, management review, and improvement. On the Annex A side we sample against the 38 controls under the nine control objectives: policies related to AI, internal organisation, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. The AI system impact assessment is where most findings land — auditors want to see it applied per system, kept current, and actually feeding risk treatment rather than filed once and forgotten.
Four phases, fixed fee, agreed before fieldwork starts. We scope with a short call and a document request list, then issue a documented audit plan naming criteria, scope, schedule and interviewees. Fieldwork is interviews with control owners plus hands-on sampling of records, configurations, model documentation and logs — remote-first, with onsite fieldwork available where you need it. The report lands as a findings register: major and minor nonconformities plus opportunities for improvement, each mapped to the exact clause or Annex A control with its evidence trail. Then close-out — a prioritised corrective-action plan with owners and dates, and a follow-up review so findings are closed before your certification body arrives rather than after.
ISO 42001 shares the Annex SL high-level structure with ISO 27001, so the management-system clauses line up almost one to one — context, leadership, planning, support, operation, evaluation, improvement. If you hold or are pursuing both, a combined internal audit programme tests the shared clauses once and the standard-specific controls separately, which cuts audit days and stops the two programmes from generating contradictory findings. We run both audits under a single programme where it makes sense, and sequence them so each certification cycle gets its Clause 9.2 evidence in time for its own surveillance visit. See also our independent ISO 27001 internal audit service.
| What this service is | Independent ISO/IEC 42001 Clause 9.2 internal audit |
|---|---|
| What it is not | Certification — that is done by a JAS-ANZ-accredited body |
| Standard audited against | ISO/IEC 42001:2023, Clauses 4–10 and 38 Annex A controls |
| Why it is required | Clause 9.2 mandates internal audit by objective, impartial auditors |
| Who it is for | AIMS built in-house or by another consultant |
| Audit duration | 1–3 days of fieldwork depending on scope |
| End to end | ~15 business days from kickoff to final report |
| Deliverables | Audit plan, findings register, corrective-action plan, close-out review |
| Fee | Fixed fee agreed after a scoping call |
| Delivery | Remote-first, Australia-wide; onsite available |
Need the AIMS built before it can be audited? See ISO 42001 implementation. Want your own people to hold the audit methodology? Aegentra Academy runs the ISO 42001 Lead Auditor course for $849 + GST, exam voucher and one free 12-month resit included — though training your team does not by itself solve the Clause 9.2 independence problem.