How to Conduct an ISO 42001 Internal Audit
An ISO 42001 internal audit is a systematic, independent assessment designed to evaluate whether an organization's Artificial Intelligence Management System (AIMS) conforms to the requirements of ISO/IEC 42001:2023 Clause 9.2 and the organization's internal AI governance policies. Running a successful internal audit requires establishing a risk-based audit programme, selecting qualified and objective auditors, inspecting core management clauses (Clauses 4 through 10) alongside Annex A controls (A.2 through A.10), and verifying that AI impact assessments appropriately evaluate risks to individuals, groups, and society. Ultimately, the internal audit generates actionable evidence for top management to address non-conformities and continuously improve the AIMS before seeking formal third-party certification.
Understanding Clause 9.2 Requirements
Clause 9.2 of ISO/IEC 42001 mandates that organizations conduct internal audits at planned intervals. The objective is twofold: ensuring the AIMS conforms to both ISO 42001 standard requirements and internal organizational specifications, and verifying that the system is effectively implemented and maintained.
To meet Clause 9.2 compliance, your organization must:
- Plan and establish an audit programme: Define the frequency, methods, responsibilities, planning requirements, and reporting structure for audits.
- Define audit criteria and scope: Determine what specific processes, AI systems, clauses, and Annex A control domains are included in each audit iteration.
- Ensure auditor objectivity and impartiality: Select internal or external human auditors who do not directly manage or develop the AI systems being audited.
- Report findings to management: Document audit evidence, non-conformities, and observations, delivering clear reports to relevant leadership roles.
- Retain documented information: Maintain records as evidence of audit programme implementation and audit results.
Step-by-Step: How to Execute an ISO 42001 Internal Audit
1. Build a Risk-Based Audit Programme
Your audit programme should not treat every process equally. ISO 42001 requires the audit schedule to account for the importance of the processes concerned, changes affecting the organization, and the results of previous audits. High-risk AI use cases—such as automated decision-making systems affecting hiring, credit scoring, or physical safety—demand more frequent and intensive audit coverage than low-risk support tools.
2. Define Scope, Criteria, and Methodology
Clarify what each audit session will evaluate. A comprehensive AIMS internal audit scope covers:
- Management Clauses (4–10): How the organization understands context (Clause 4), demonstrates leadership commitment (Clause 5), plans for risks and impacts (Clause 6), provisions resources and competencies (Clause 7), runs operational controls (Clause 8), evaluates performance (Clause 9), and drives continuous improvement (Clause 10).
- Annex A Control Domains: Verification of operational controls spanning AI policies (A.2), internal organization (A.3), AI resources (A.4), AI system impact assessments (A.5), AI lifecycle governance (A.6), data management (A.7), stakeholder transparency (A.8), AI use policies (A.9), and third-party vendor relationships (A.10).
3. Select Competent and Independent Auditors
Auditors must possess two core attributes: technical knowledge of AI risk management and structural independence from the audited domain. For example, a machine learning engineer should not audit the data lineage controls (A.7) for a model they actively trained. Organizations can use trained internal staff from standard compliance functions or external consultants.
4. Execute the Audit and Gather Evidence
During audit execution, auditors evaluate objective evidence rather than relying on verbal assurances. Sampling techniques should be applied to inspect:
- Data Governance (A.7): Source data lineage, bias mitigation records, and privacy documentation.
- AI System Life Cycle (A.6): Model card documentation, verification/validation logs, performance drift monitoring, and retirement plans.
- Impact Assessments (A.5): Documented evaluations detailing potential harms to individuals, distinct groups, and broader society.
- Third-Party Relationships (A.10): Vendor contracts, SLA monitoring, and safety assessments for imported AI tools or APIs.
5. Document Findings and Issue Corrective Actions
Auditors record findings as conformities, non-conformities (major or minor), or opportunities for improvement (OFIs). Non-conformities feed directly into Clause 10 (Improvement), requiring process owners to perform root-cause analysis and implement timely corrective actions.
Key Areas Unique to ISO 42001 Audits
Unlike traditional ISO management systems (such as ISO 27001 or ISO 9001), an ISO 42001 audit places distinct emphasis on societal impact, algorithmic transparency, and data provenance. Auditors must verify that AI impact assessments go beyond internal operational losses to measure potential discrimination, loss of autonomy, or systemic risk across affected populations.
Preparing for External Certification
Internal audits serve as the primary stress test before engaging an accredited certification body. Independent human auditors from a registrar accredited under ISO/IEC 42006 will examine your internal audit results (Clause 9.2) and management review records (Clause 9.3) as proof of system maturity.
To gauge your organization's audit readiness before scheduling a formal internal or external audit, try DoAIRight's free readiness assessment. While software platforms help prepare your documentation and track compliance, final certification can only be granted by an accredited independent certification body.
Frequently asked
How often must an ISO 42001 internal audit be conducted?
ISO 42001 Clause 9.2 requires internal audits at planned intervals, but does not mandate a fixed calendar schedule. Most organizations perform a full internal audit annually, or more frequently when major changes occur in AI models, data pipelines, or regulatory environments.
Can the person who built an AI model perform the internal audit on it?
No. Clause 9.2 explicitly requires that auditors be objective and impartial. To maintain independence, organizations must select auditors who were not directly involved in developing, deploying, or managing the specific AI system or process being audited.
Does DoAIRight issue ISO 42001 certificates after an internal audit?
No. DoAIRight provides tools and readiness assessments to help organizations design, implement, and audit their AIMS. Official ISO/IEC 42001 certification can only be granted by an independent accredited certification body following an external audit process governed by ISO/IEC 42006.
What is the difference between Clause 9.2 and Annex A controls during an audit?
Clause 9.2 defines the procedural requirements for how to plan, conduct, and report internal audits. Annex A controls (A.2 through A.10) represent the operational AI governance controls that the internal audit inspects to verify effectiveness and compliance.