Skip to main content

/ ISO/IEC 42001 · Clause 9.2

ISO 42001 Internal Audit Services Australia

Independently run. Evidence-led. Certification-ready.

An ISO/IEC 42001 internal audit is the Clause 9.2 review of whether your AI management system conforms to your own requirements and the standard—and whether it is effectively implemented and maintained.

Aegentra plans the audit, reviews Clauses 4–10 and the Statement-of-Applicability decisions, then samples applicable Annex A controls using AI risk, process importance, change and prior results. We report traceable findings and verify agreed corrective-action close-out. We audit; an accredited certification body certifies.

Delivered across Australia — all states and territories — with remote delivery and onsite attendance by arrangement. New Zealand and wider Asia Pacific engagements may be available by arrangement.

Evidence trail
CriteriaClause or control
SampleEvidence reviewed
ConclusionConformity or finding
ActionOwner and close-out

/ Delivery team

Who will deliver your ISO 42001 internal audit?

The audit record identifies the accountable lead, the assigned auditor, any specialist support and how objectivity is protected before fieldwork begins.

ResponsibilityAudit accountability
Assigned roleEngagement lead and assigned auditor
How it is confirmedThe people performing those functions and their responsibilities are named in the scope and audit plan.
ResponsibilityCompetence and support
Assigned roleCompetence relevant to the agreed AIMS scope
How it is confirmedRelevant competence and any specialist contribution are confirmed before fieldwork.
ResponsibilityObjectivity
Assigned rolePrior-involvement and conflict check
How it is confirmedAegentra does not audit an AIMS it implemented; the boundary is checked before the audit is accepted.

Qualified delivery matched to your scope

Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.

The assigned auditor retains responsibility for audit judgements and conclusions. Aegentra is not the certification body.

Cover of the ISO/IEC 42001:2023 internal audit report case studyOpen the engagement record

/ Featured ISO 42001 case study

August 2026

A mid-market SaaS provider had committed to an ISO/IEC 42001 certification audit while its AI inventory, risk method, impact assessments, accountability and supplier controls were still incomplete. This anonymised engagement record shows what changed before the deadline.

8 weeks
To external audit
6
Priority governance gaps
0
Major nonconformities reported

Client name withheld. Identifying details are generalised; the findings, sequence and reported outcome reflect the supplied engagement record.

Read the full case study

/ Scope and price

ISO 42001 internal audits from $2,500 + GST.

Available for smaller organisations with a clearly defined AIMS scope and limited AI-system complexity. Final fixed pricing depends on the AIMS scope, AI systems, locations, evidence volume and sampling requirements.

The scope, evidence request, fieldwork dates, deliverables and fee are agreed before work begins. Certification-body fees are separate.

Request a fixed-scope audit quote

ISO 42001 internal audit at a glance

What this service is
Independent ISO/IEC 42001 Clause 9.2 internal audit
What it is not
Certification — that is done by an independent accredited certification body
Standard audited against
ISO/IEC 42001:2023, Clauses 4–10 and 38 Annex A controls
Why it is required
Clause 9.2 mandates internal audit by objective, impartial auditors
Who it is for
AIMS built in-house or by another consultant
Audit duration
Confirmed after scope, criteria, systems and sampling needs are reviewed
Schedule
Audit plan agreed before fieldwork
Deliverables
Audit plan, findings register, corrective-action plan, close-out review
Fee
From $2,500 + GST for a smaller, clearly defined AIMS scope; final fixed pricing depends on AI systems, locations, evidence volume and sampling requirements
Delivery
Remote-first, Australia-wide; onsite available

/ Published credential evidence

Harry Sidhu

Director and Principal Consultant, Aegentra

Harry Sidhu is the named principal consultant for Aegentra’s Govern practice. Implementation and internal-audit work are accepted as separate engagements, with independence and conflict checks applied before any audit scope is confirmed. His published credential and issuer-verification link are shown below.

The written audit scope names the lead, any additional delivery roles, the criteria, sampling rationale and independence safeguards. Aegentra does not represent a credential or clearance as team-wide unless the named holder and evidence are published.

Harry’s published PECB Certified ISO 27001 Lead Implementer credential, certificate no. 9303577-2026-05, can be checked using PECB’s verification tool. It is an ISO 27001 implementation credential shown for practice accountability; it is not an ISO 42001 auditor credential and does not identify the auditor assigned to this engagement. Aegentra does not perform the internal audit where Aegentra implemented the AIMS.

/ Choose the right audit

Internal audit, readiness and certification are different jobs.

Clause 9.2 requires an internal audit. A readiness review can help you prepare, but cannot be relabelled as that audit. Certification is a separate independent decision by an accredited certification body.

Clause 9.2 requirement

Internal audit

Tests whether the AIMS conforms to your requirements and ISO/IEC 42001, and whether it is effectively implemented and maintained.

Performed by objective, impartial auditors. This is Aegentra’s role.

Optional diagnostic

Readiness assessment

Identifies gaps before formal audit activity. Useful, but it does not replace the documented internal audit programme Clause 9.2 requires.

Performed before the internal or certification audit when additional preparation is needed.

Independent certification

Certification audit

Stage 1 and Stage 2 determine whether an accredited certificate can be issued. Surveillance follows during the certification cycle.

Performed by an accredited certification body—not by Aegentra.

/ Audit coverage

We test the system you operate—not a template.

The audit criteria include ISO/IEC 42001:2023, your organisation’s own AIMS requirements and the controls you declared applicable. Sampling follows the risks, processes and AI systems inside the agreed scope.

View ISO/IEC 42001 at ISO.org

Clauses 4–6

Context, leadership and planning

AIMS scope, interested parties, AI policy, accountable roles, AI objectives, risk assessment and treatment decisions.

Clauses 7–8

Support and operation

Competence, awareness, documented information, operational controls and the way AI systems move through their life cycle.

Clauses 9–10

Performance and improvement

Monitoring, measurement, management review, previous audit results, nonconformity and corrective action.

Annex A

The 38 AI controls

Applicable controls across policies, organisation, resources, impact assessment, life cycle, data, transparency, use and suppliers.

Your AIMS

Your own requirements

The policies, procedures, Statement of Applicability and commitments your organisation has chosen—not only the standard text.

Evidence

Whether controls operate

AI inventory records, impact assessments, approvals, monitoring, oversight, supplier reviews, incidents and retained evidence.

/ Evidence sampling

What we examine during fieldwork.

The audit begins with the agreed criteria and follows evidence through the systems and processes inside scope. Samples are selected to challenge the AIMS: higher-impact systems, recent changes, exceptions, incidents, material suppliers and areas with previous findings.

SAMPLE 01

AIMS governance records

We reconcile scope, policy, objectives, accountable roles and management decisions. The test is whether leadership governs the AIMS through current decisions, resources and review—not whether a policy file exists.

SAMPLE 02

AI inventory completeness

We compare the declared inventory with procurement, identity, cloud, product and supplier records to find embedded or externally supplied AI that may sit outside the governance team’s working list.

SAMPLE 03

Risk and impact assessment

We sample whether AI risks and impacts were assessed per relevant system, revisited after meaningful change and connected to treatment, approval, human oversight and measurable objectives.

SAMPLE 04

Life-cycle control evidence

For developed or materially configured systems, we follow requirements through design, verification, validation, release, monitoring, change and retirement records. A process description alone does not prove the process operated.

SAMPLE 05

Data and transparency

Samples can cover provenance, quality, preparation, access, representativeness, retention, user information, limitations and incident communication—selected according to the systems and impacts inside the AIMS scope.

SAMPLE 06

Suppliers, incidents and exceptions

We test due diligence, shared responsibilities, contractual controls, change notifications, complaints, incidents and approved exceptions. These records show whether governance holds when normal operating assumptions break.

/ Engagement boundaries

What remains separate and why.

Aegentra does not certify

We deliver the Clause 9.2 internal audit. Stage 1, Stage 2, surveillance and the certificate remain the responsibility of an accredited certification body selected by the client.

We do not audit our own AIMS implementation

Where Aegentra implemented the AIMS, we recommend a separate independent provider. The audit should be objective, impartial and straightforward to defend when the certification body reviews it.

Sampling is scoped, not generic

The audit plan follows AI risk, process importance, previous results, recent change and the Statement of Applicability. It does not promise that the same fixed sample fits every organisation.

Findings are not closed by assertion

Close-out requires evidence of correction and, for nonconformities, action addressing root cause. The final status records what was verified, when it was verified and what remains open.

/ Supported technical evidence

Evidence-led auditing with Aeges.

Where the agreed scope includes supported Microsoft 365 evidence, Aeges can collect current technical configuration evidence read-only and help identify changes in control state. It is an evidence source—not the auditor.

Current evidence

Supported Microsoft 365 configuration evidence can be reproduced on demand instead of relying only on point-in-time screenshots.

Traceable scope

The collected evidence can support requirement and control traceability, while policies, interviews, management decisions and non-Microsoft systems retain their own records.

Human judgement

The human auditor sets the criteria, selects samples, evaluates conformity and owns every finding and conclusion in the issued audit report.

See what Aeges does and does not collect

/ The audit file

Evidence in. Defensible conclusions out.

Every conclusion must be traceable. Your final pack shows what was tested, what evidence supported the conclusion, where the AIMS did not conform and what needs to happen next.

Plan

Audit plan and evidence request

The criteria, scope, methods, schedule, interviewees and initial evidence list are agreed before fieldwork.

Test

Traceable audit workpapers

Each sample connects the requirement tested, evidence reviewed, interview performed and conclusion reached.

Report

Findings register

Nonconformities and improvement opportunities are mapped to the exact clause or control and supported by evidence.

Close

Corrective-action close-out

Owners, actions and dates are tracked, then the evidence of correction is reviewed before closure.

/ Engagement sequence

A controlled path from scope to close-out.

The schedule and fixed fee are confirmed after the AIMS scope, systems, locations, evidence access and sampling needs are understood.

  1. Scope

    Define the audit, not a generic checklist

    We review the AIMS boundary, AI estate, locations, previous results and Statement of Applicability, then agree the audit programme and fixed fee.

  2. Fieldwork

    Follow evidence through the system

    We interview control owners and sample records, model documentation, approvals, monitoring and logs against the criteria in the plan.

  3. Report

    Write findings that can be acted on

    Every finding identifies the requirement, observed evidence and gap. The register is walked through with accountable management.

  4. Close-out

    Verify correction before certification

    Corrective actions are prioritised and follow-up evidence is reviewed so open issues do not drift into the certification audit.

/ Method and working resources

See how the audit file is built.

Use the checklist to prepare your evidence, then inspect an ISO 42001 engagement that moved from serious AI-governance gaps to certification readiness in eight weeks.

Free working resource

ISO 42001 internal audit checklist

Prepare the evidence pack, work through Clauses 4–10 and Annex A themes, record sampling and download the editable CSV—without an email gate.

Open the audit checklist

ISO 42001 engagement record

Certification under pressure

A mid-market SaaS provider had eight weeks to correct its AI inventory, risk method, impact assessments, accountability and supplier controls before the external audit.

Read the ISO 42001 case study

Building impartial audit capability inside a larger team? The PECB ISO 42001 Lead Auditor course teaches the audit method; training does not remove a conflict where the same person designed or operates the controls being tested.

/ Integrated audit programme

Already operating ISO 27001?

ISO 27001 and ISO 42001 share the Annex SL management-system structure. Where scopes align, a combined programme can test shared processes once and sample the standard-specific controls separately—without confusing which requirement each finding belongs to.

Shared clauses tested once where appropriate
Standard-specific controls sampled separately
One coordinated findings and action register
Audit timing aligned to both certification cycles
See ISO 27001 internal audit

/ Frequently asked questions

What teams ask before the audit.

/ Scope the audit

Ready for an independent Clause 9.2 review?

Bring the AIMS scope, AI inventory, Statement of Applicability and target certification date. We will confirm the evidence request, sampling approach, schedule and fixed fee before fieldwork.

Book an audit scoping call