Skip to main content

ISO 42001 internal audit, independently run.

Clause 9.2 of ISO/IEC 42001 requires your AI management system to be audited at planned intervals — by someone objective and impartial. If you built your AIMS in-house or with another consultant, you cannot credibly audit your own work. We run the independent internal audit your certification cycle requires: audit plan, evidence sampling across Clauses 4–10 and the 38 Annex A controls, findings register, and corrective-action close-out. We audit; a JAS-ANZ-accredited body certifies.

What Clause 9.2 actually requires

ISO/IEC 42001 Clause 9.2 requires you to conduct internal audits at planned intervals to determine whether your AI management system conforms to both your own requirements and the requirements of the standard, and whether it is effectively implemented and maintained. The clause is explicit about auditor selection: the audit programme must ensure objectivity and impartiality of the audit process. In practice that means the people who designed your AI governance controls cannot be the people who test them. You also have to plan the programme against the importance of the processes concerned and the results of previous audits, define criteria and scope for each audit, report results to relevant management, and retain documented evidence of the programme and its outcomes. A certification body will ask to see all of it at Stage 1.

Why independence is the hard part for AI governance teams

AI governance is new, and the teams running it are small. The person who wrote your AI system impact assessment methodology is usually the same person who maintains the AI inventory, chairs the AI governance forum, and would otherwise be nominated as internal auditor. That fails the impartiality test in Clause 9.2, and certification auditors know exactly where to look for it — an internal audit report signed by the AIMS owner is one of the fastest routes to a nonconformity at Stage 2. Outsourcing the internal audit solves the problem outright: you get an auditor with no stake in the controls under test, a documented independence position, and a report that survives scrutiny from the certification body.

What we audit — Clauses 4–10 and 38 Annex A controls

The audit covers the management-system clauses and the AI-specific control set. On the clause side we test context and scope of the AIMS, leadership and AI policy, AI risk assessment and treatment, objectives and planning, competence and awareness, documented information, operational planning and control, performance evaluation, management review, and improvement. On the Annex A side we sample against the 38 controls under the nine control objectives: policies related to AI, internal organisation, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. The AI system impact assessment is where most findings land — auditors want to see it applied per system, kept current, and actually feeding risk treatment rather than filed once and forgotten.

How the engagement runs

Four phases, fixed fee, agreed before fieldwork starts. We scope with a short call and a document request list, then issue a documented audit plan naming criteria, scope, schedule and interviewees. Fieldwork is interviews with control owners plus hands-on sampling of records, configurations, model documentation and logs — remote-first, with onsite fieldwork available where you need it. The report lands as a findings register: major and minor nonconformities plus opportunities for improvement, each mapped to the exact clause or Annex A control with its evidence trail. Then close-out — a prioritised corrective-action plan with owners and dates, and a follow-up review so findings are closed before your certification body arrives rather than after.

Running ISO 27001 and ISO 42001 together

ISO 42001 shares the Annex SL high-level structure with ISO 27001, so the management-system clauses line up almost one to one — context, leadership, planning, support, operation, evaluation, improvement. If you hold or are pursuing both, a combined internal audit programme tests the shared clauses once and the standard-specific controls separately, which cuts audit days and stops the two programmes from generating contradictory findings. We run both audits under a single programme where it makes sense, and sequence them so each certification cycle gets its Clause 9.2 evidence in time for its own surveillance visit. See also our independent ISO 27001 internal audit service.

ISO 42001 internal audit — at a glance

What this service isIndependent ISO/IEC 42001 Clause 9.2 internal audit
What it is notCertification — that is done by a JAS-ANZ-accredited body
Standard audited againstISO/IEC 42001:2023, Clauses 4–10 and 38 Annex A controls
Why it is requiredClause 9.2 mandates internal audit by objective, impartial auditors
Who it is forAIMS built in-house or by another consultant
Audit duration1–3 days of fieldwork depending on scope
End to end~15 business days from kickoff to final report
DeliverablesAudit plan, findings register, corrective-action plan, close-out review
FeeFixed fee agreed after a scoping call
DeliveryRemote-first, Australia-wide; onsite available

Need the AIMS built before it can be audited? See ISO 42001 implementation. Want your own people to hold the audit methodology? Aegentra Academy runs the ISO 42001 Lead Auditor course for $849 + GST, exam voucher and one free 12-month resit included — though training your team does not by itself solve the Clause 9.2 independence problem.