DoAIRight
ISO/IEC 42001

Common ISO 42001 Nonconformities and How to Avoid Them

PUBLISHED 06 AUG 2026

Common ISO 42001 nonconformities occur when organizations fail to separate AI risk management from societal impact assessments, neglect leadership oversight, or maintain inadequate control over third-party AI suppliers. Addressing these audit findings requires structured risk and impact methodologies, robust documentation across the AI system life cycle, regular performance evaluations, and systematic corrective action under Clause 10. By leveraging DoAIRight’s free readiness assessment, organizations can spot control gaps early and ensure their AI Management System (AIMS) is fully prepared for independent certification.

Understanding ISO 42001 Audit Findings

When an accredited certification body conducts an audit under ISO/IEC 42006, independent human auditors evaluate whether your organization complies with ISO/IEC 42003:2023 requirements. Gaps between your management system and the standard lead to audit findings, which fall into two primary categories:

  • Major Nonconformity: A total absence or systemic failure of a required clause or control, directly compromising the integrity of the AIMS or allowing unmanaged AI risks to reach users.
  • Minor Nonconformity: A localized, single-instance oversight or procedural gap that does not completely invalidate the management system or control objectives.

To secure and maintain ISO 42001 certification, major nonconformities must be resolved before a certificate can be recommended, while minor findings require a clear corrective action plan.

Top 5 ISO 42001 Nonconformities

1. Conflating Organizational Risk with AI Impact Assessment

A frequent finding involves Clause 6.1 (Actions to address risks and opportunities) and Annex A.5 (Assessing impacts of AI systems). Organizations often mistake internal business risk (e.g., financial or operational risk) for an AI impact assessment. ISO 42001 explicitly requires evaluating how AI systems affect individuals, specific demographic groups, and broader society—including ethical, fairness, and safety concerns.

2. Lack of Practical Top Management Ownership

Under Clause 5 (Leadership), top management must actively demonstrate commitment to responsible AI. Standard nonconformities surface when executive involvement is purely nominal—such as approving policies without providing required resources (Clause 7) or failing to review operational performance and AI impact reports during formal management reviews (Clause 9.3).

3. Weak Third-Party and Vendor Management

Many companies integrate third-party machine learning models, cloud APIs, or pre-trained systems into their products without extending governance controls. Under Annex A.10 (Third-party and customer relationships), auditors frequently flag organizations for failing to evaluate supplier data sources, security postures, bias mitigations, and compliance boundaries.

4. Poor AI System Life Cycle Traceability

Annex A.6 (AI system life cycle) and Annex A.7 (Data for AI systems) demand clear governance across design, data acquisition, model training, validation, deployment, and decommissioning. Common audit findings stem from missing data lineage records, undocumented model retraining procedures, or absent human oversight triggers during live operation (Clause 8).

5. Ineffective Internal Audits and Root Cause Analysis

Failing to perform comprehensive internal audits (Clause 9.2) before formal certification is a critical failure. Furthermore, when issues arise, organizations often apply superficial patches rather than implementing genuine corrective action (Clause 10.1) that eliminates the root cause.

How to Avoid Nonconformities and Pass Your Audit

To prevent audit findings and build a resilient AI Management System, organizations should implement proactive control measures across the entire governance framework:

  • Separate Risk and Impact Methodologies: Establish distinct frameworks for business risk assessment and societal/individual AI impact assessments (Annex A.5).
  • Formalize Supplier Oversight: Implement vendor questionnaires, contractual SLAs, and verification workflows for all external AI components (Annex A.10).
  • Document the Full Life Cycle: Maintain transparent documentation for data provenance, model architecture, training protocols, and continuous monitoring (Annex A.6 & A.7).
  • Engage Leadership Consistently: Ensure executive participation in regular management reviews, policy reviews (Annex A.2), and resource allocation decisions (Clause 5 & 7).
  • Conduct Thorough Readiness Assessments: Utilize DoAIRight's free readiness assessment tool to systematically scan Clauses 4 through 10 and Annex A control domains for potential gaps prior to hiring an auditor.

Resolving Audit Findings with Root Cause Analysis

When nonconformities are identified, Clause 10 requires a structured corrective action response:

  1. Containment: Take immediate action to control and correct the immediate deficiency.
  2. Root Cause Analysis: Investigate why the failure occurred (e.g., using 5 Whys or Fishbone diagrams) rather than treating symptoms.
  3. Corrective Action Plan: Implement long-term systemic changes to prevent recurrence across similar AI processes.
  4. Review Effectiveness: Re-evaluate the control after implementation to verify that the nonconformity has been completely resolved.

Remember that while specialized readiness platforms like DoAIRight prepare your organization for successful audits, official ISO 42001 certification can only be granted by an accredited third-party certification body with qualified human auditors.

Frequently asked

What is the difference between an AI risk assessment and an AI impact assessment in ISO 42001?

An AI risk assessment (Clause 6.1) evaluates operational, legal, and strategic risks to the organization. An AI impact assessment (Annex A.5) specifically analyzes potential non-financial and ethical consequences an AI system may have on individuals, groups, and society.

Can DoAIRight issue our ISO 42001 certificate directly?

No. ISO 42001 certificates are issued exclusively by accredited, independent certification bodies that deploy human auditors under ISO/IEC 42006. DoAIRight provides tools and assessments to make your organization fully certification-ready.

How long do we have to fix a major nonconformity after an audit?

Typically, certification bodies allow 90 days to implement corrective actions for a major nonconformity and provide evidence of resolution before issuing final certification approval.

What happens if we receive a minor nonconformity?

A minor nonconformity does not prevent certification, but your organization must submit an approved corrective action plan detailing how the gap will be addressed before the certificate is officially issued.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score