ISO 42001 Internal Audit Guide for 2026
Updated:
August 25, 2026
ISO/IEC 42001 influenced responsible AI decision-making at 36% of surveyed organizations in 2025, reflecting growing adoption of formal AI governance standards. Audit readiness remains much weaker: 78% of business executives lack strong confidence that their organization could pass an independent AI governance audit within 90 days. ISO 42001 internal audits help organizations test their AIMS and address governance, evidence, and control gaps before an external assessment.
ISO 42001 Clause 9.2 requires organizations to conduct internal audits at planned intervals and maintain an audit program covering scope, criteria, responsibilities, methods, reporting, and audit evidence. In practice, this means reviewing AI risks, controls, processes, records, responsibilities, and corrective actions across the AIMS.
The requirements may sound straightforward, but conducting an effective internal audit involves more than working through a checklist. Below, we’ll break down how the ISO 42001 internal audit process works, what evidence to review, how to document findings, and what to do before your certification audit.
What Is an ISO 42001 Internal Audit?

An ISO 42001 internal audit is a planned assessment of an organization’s Artificial Intelligence Management System (AIMS). It determines whether the system conforms to ISO/IEC 42001 requirements and the organization’s own AIMS requirements and whether it is effectively implemented and maintained. The audit examines governance processes, AI risk and impact assessments, applicable controls, monitoring activities, documented information, and corrective actions to provide management with evidence of AIMS performance and gaps that require correction or improvement.
ISO 42001 Clause 9.2 Internal Audit Requirements
ISO 42001 Clause 9.2 requires organizations to conduct internal audits at planned intervals to determine whether the Artificial Intelligence Management System (AIMS) conforms to the organization’s own requirements and ISO/IEC 42001, and whether it is effectively implemented and maintained. Clause 9.2 is divided into 9.2.1 General and 9.2.2 Internal Audit Programme.
To meet Clause 9.2, an organization must:
- Conduct Audits at Planned Intervals: Schedule internal audits as part of the AIMS audit program.
- Audit Against Two Sets of Requirements: Assess conformity with ISO/IEC 42001 and the organization’s own AIMS requirements, such as approved policies, procedures, objectives, and governance processes.
- Maintain an Internal Audit Program: Define the audit frequency, methods, responsibilities, planning requirements, and reporting process. The program should consider the importance of the processes being audited and results from previous audits.
- Define Each Audit’s Objectives, Criteria, and Scope: Specify what the audit is intended to evaluate, which requirements will serve as the audit criteria, and which AI systems, processes, functions, locations, or activities fall within scope.
- Maintain Auditor Objectivity and Impartiality: Select auditors and conduct the audit in a way that prevents bias or conflicts of interest from compromising the results.
- Report Audit Results to Relevant Management: Communicate the findings to managers responsible for the audited areas so the results can support AIMS oversight.
- Retain Documented Audit Evidence: Keep documented information showing that the audit program was implemented and recording the results of completed audits. This may include audit plans, checklists, evidence reviewed, findings, and audit reports.
Scope of an ISO 42001 Internal Audit: Clauses 4 Through 10 and Annex A Controls
The scope of an ISO 42001 internal audit should cover the Artificial Intelligence Management System (AIMS) requirements that apply to the organization, including Clauses 4 through 10 and necessary Annex A controls. ISO 42001 contains 38 Annex A controls across nine control groups. Control applicability depends on risk assessment results and other relevant requirements.
Clause 6.1.3 requires the organization to determine the controls necessary for AI risk treatment and record them in the Statement of Applicability (SoA), with justification for inclusions and exclusions. Internal auditors should test the applicable controls in the SoA and confirm that exclusions have a risk-based justification.

An individual internal audit can focus on a defined process, AI system, department, or part of the AIMS. The audit program should define the objectives, criteria, and scope of each audit and give appropriate attention to important processes and previous audit results. ISO 19011:2026 describes audit scope as the boundaries and extent of an audit, which can include organizational units, functions, processes, activities, locations, and the period being examined.
The ISO 42001 Internal Audit Process Step by Step
The ISO 42001 internal audit process moves from defining the audit program and scope to collecting evidence, documenting findings, reporting results, and addressing nonconformities. Clause 9.2 sets the mandatory internal audit requirements, while ISO 19011 provides methods for planning and conducting management system audits.

1. Create the Internal Audit Program
Create an audit program that defines the frequency, methods, responsibilities, planning requirements, and reporting arrangements for internal audits. Give greater audit attention to important AIMS processes and areas with previous findings.
2. Define the Audit Objectives, Criteria, and Scope
Define what the audit will assess, which requirements will be used as criteria, and which parts of the AIMS fall within scope. Clause 9.2.2 specifically requires objectives, criteria, and scope to be defined for each audit.
The criteria can include applicable ISO 42001 requirements, internal AI policies and procedures, and applicable Annex A controls. The scope may cover specific AI systems, business functions, processes, physical or virtual locations, or a defined period.
Select an auditor who can perform the assessment objectively and impartially. Auditors should not audit work for which their responsibilities would compromise independence.
3. Prepare the Audit Plan and Review AIMS Documentation
Review relevant AIMS documentation before testing how the processes operate in practice. This helps the auditor understand the organization’s documented processes and determine which evidence should be tested.
Relevant documents may include:
- AIMS scope and AI policy
- AI system inventory
- AI risk assessments and treatment plans
- Statement of Applicability
- AI system impact assessments
- AI objectives and monitoring results
- Policies and procedures
- Training and competence records
- Supplier and third-party records
- Previous audit findings and corrective actions
- Management review records
Prepare an audit plan that maps the audit criteria to the processes, people, and evidence that will be examined. This mapping gives the auditor a clear basis for interviews, sampling, and record review.
4. Conduct the Audit and Collect Objective Evidence
Conduct the audit through a combination of document review, interviews, observation, and evidence sampling.
For example, an auditor reviewing AI risk management can sample completed risk assessments, interview the responsible owner, trace selected risks to treatment actions, and verify whether related controls were implemented. A documented risk procedure is one source of evidence within that test. The sampled records can then be compared with the procedure and related treatment plan.
ISO 19011 defines audit evidence as verifiable records, statements of fact, or other information relevant to the audit criteria. This evidence-based method supports findings grounded in verifiable information.
5. Evaluate Evidence and Document Audit Findings
Compare the collected evidence against the defined audit criteria and determine whether each requirement is fulfilled. Findings can show conformity, nonconformity, risks, good practices, or opportunities for improvement under the ISO 19011 audit framework.
Each nonconformity should clearly connect:
Requirement → Evidence Reviewed → Gap Found
Write each nonconformity so the requirement, evidence, and gap are explicit. A finding for a missing AI impact assessment should cite the applicable requirement, name the affected AI system, and state the missing or inadequate record. This format makes the basis of the finding clear and gives the responsible owner a precise issue to correct.
6. Report the Internal Audit Results
Prepare an audit report that records the scope, objectives, criteria, evidence reviewed, findings, conclusions, and any nonconformities. Clause 9.2.2 requires audit results to be reported to relevant managers and documented information to be retained as evidence of both the audit program and its results.
A closing meeting can present the findings, clarify the evidence supporting each finding, and confirm responsibility for subsequent actions. Process owners should leave the meeting with a clear understanding of the recorded gaps and required follow-up.
7. Correct Nonconformities and Verify Corrective Actions
Address recorded nonconformities through the corrective action process required under Clause 10.2. The organization must respond to the problem, determine its cause where necessary, implement appropriate corrective action, and review whether that action was effective.
Keep evidence of the nonconformity, actions taken, and corrective action results. Audit results should then feed into the management review process, since Clause 9.3 specifically lists audit results as a management review input.
Evidence Requirements and Common Nonconformities
An ISO 42001 internal audit tests whether required AIMS processes are documented, implemented, and producing the intended results. Clause 7.5 requires organizations to control the documented information ISO 42001 mandates along with any additional documentation necessary for an effective AIMS. The auditor examines both categories, since mandatory records prove conformity while supporting evidence proves the process operates.
| Audit Area | Evidence to Review | Common Nonconformity |
| AIMS Governance | AIMS scope, AI policy, assigned roles, responsibilities, and governance records | Responsibilities are unclear, the policy does not reflect current AI activities, or required governance processes exist only on paper |
| AI Risk Assessment and Treatment* | Risk criteria, risk assessment methodology and results, treatment plans, selected controls, residual risk acceptance, and management approvals | Assessments are generic or inconsistent, treatments cannot be traced to risks, or residual risks lack appropriate approval |
| Statement of Applicability* | Current SoA showing necessary controls and justification for control inclusion and exclusion | Controls are included or excluded without a risk-based justification, or the SoA does not reflect the controls actually implemented |
| AI System Impact Assessments* | Completed impact assessments covering potential consequences for individuals, groups, and society, including reassessments following significant changes | Assessments are missing, incomplete, confused with AI risk assessments, or not repeated when significant changes occur |
| Competence and Awareness* | Training records, qualifications, experience, competency evaluations, and evidence that personnel understand relevant AIMS responsibilities | Personnel are assigned AI responsibilities without sufficient evidence of competence or awareness |
| Operational Controls and Monitoring* | Control records, testing results, approvals, logs, performance measurements, change records, supplier records, and monitoring results | Procedures are documented but not followed, monitoring produces insufficient evidence, or controls cannot be shown to operate effectively |
| Internal Audit and Management Review* | Audit program, scope, criteria, audit reports, findings, auditor assignments, management review records, and resulting decisions | Audits are incomplete, auditor impartiality is questionable, findings are not reported appropriately, or management review lacks required AIMS inputs |
| Corrective Actions* | Nonconformity records, cause analysis, assigned actions, completion evidence, and effectiveness reviews | Findings are closed without addressing the cause, similar issues are not considered, or corrective action effectiveness is never verified |
ISO 42001 requires documented information for these areas. AIMS governance records support the audit without being mandated as retained documented information.
A document alone does not show that a requirement is working. The auditor traces a requirement from the documented process to a sample of actual activity, following completed assessments, treatment decisions, control implementation, approvals, and effectiveness evidence. ISO 42001 requires organizations to implement AI risk treatment plans and verify that the treatment worked, which makes the verification record itself a testable artifact.
Evidence weakness and evidence absence produce different findings. A missing AI system impact assessment is a clear nonconformity against a stated requirement. An impact assessment that exists but covers only technical performance, with no assessment of consequences for affected individuals or groups, fails the requirement on substance while satisfying it on paper. The auditor grades the second case against what Clause 6.1.4 requires the assessment to contain, not against whether a document was produced.
Auditor Competence, Independence, and Audit Frequency
ISO 42001 requires objective and impartial internal auditing, while Clause 7.2 sets competence expectations for people whose work affects AI performance. The audit program determines when internal audits occur.

Auditor Competence
Internal auditors should have sufficient knowledge and skills to evaluate the AIMS against the defined audit criteria. ISO 42001 Clause 7.2 requires organizations to determine the competence needed for people whose work affects AI performance, confirm competence through appropriate education, training, or experience, and retain evidence of that competence.
For an ISO 42001 internal audit, relevant competence can include:
- ISO/IEC 42001 requirements and the organization’s AIMS
- Management system auditing principles and methods
- AI risk and impact assessment processes
- Applicable Annex A controls
- AI governance, lifecycle, data, and third-party processes relevant to the audit scope
ISO 19011 provides methods for determining and evaluating auditor competence, including personal behavior, knowledge, skills, auditor evaluation, and maintenance of competence. ISO 42001 does not require an internal auditor to hold a specific ISO 42001 auditor certification.
Auditor Independence and Impartiality
Clause 9.2.2 requires organizations to select auditors and conduct audits in a way that maintains objectivity and impartiality. An auditor should avoid assessing activities for which their own responsibilities could influence the audit conclusions.
ISO 19011 describes independence as the basis for impartiality and objective audit conclusions. Auditors should remain free from bias and conflicts of interest and, wherever practicable, be independent of the activity being audited. Smaller organizations that cannot achieve complete separation should take practical measures to reduce bias and preserve objectivity.
An organization can use personnel from another function, an internal audit team, or an external auditor working on its behalf. ISO 19011 classifies internal audits as first-party audits conducted by or on behalf of the organization.
ISO 42001 Internal Audit Frequency
ISO 42001 does not require internal audits to occur once every year. Clause 9.2.1 requires them at planned intervals, while Clause 9.2.2 requires the audit program to define the frequency and consider both the importance of the processes concerned and the results of previous audits.

Audit frequency should reflect the organization’s risk and AIMS performance. Higher-risk AI systems, major AIMS changes, recurring nonconformities, or processes with poor previous audit results may justify more frequent review. Stable and lower-risk areas may require less frequent individual audits, provided the organization’s audit program gives adequate coverage of the AIMS.
Regular AI governance audits are still relatively uncommon. A 2025 KPMG survey found that only 25% of board members reported that their companies conduct regular audits to govern AI use.
Organizations may schedule a full internal audit cycle annually as a practical approach, particularly before certification or surveillance audits, but ISO 42001 does not mandate an annual frequency.
ISO 42001 Internal Audit FAQs
1. Is an Internal Audit Required for ISO 42001 Certification?
Yes. ISO/IEC 42001 Clause 9.2 requires organizations to conduct internal audits at planned intervals to verify that the AIMS conforms to organizational and ISO 42001 requirements and is effectively implemented and maintained. Certification bodies review internal audit results during the certification process, making a completed internal audit a core part of certification readiness.
2. How Often Should an ISO 42001 Internal Audit Be Conducted?
Set the cadence according to the AIMS, process importance, previous audit results, and material changes. Clause 9.2 requires planned intervals but gives no fixed annual schedule. More frequent reviews can be appropriate for high-risk AI activities or recurring findings.
3. Who Can Perform an ISO 42001 Internal Audit?
An ISO 42001 internal audit can be performed by a competent employee, an internal audit team, or a qualified external auditor acting on the organization’s behalf. Clause 9.2 requires auditor selection and audit conduct to preserve objectivity and impartiality, so auditors should not assess work where their own responsibilities could compromise those principles. ISO 42001 does not require a specific internal auditor certification.
4. What Is the Difference Between an ISO 42001 Internal Audit and a Certification Audit?
An ISO 42001 internal audit is a first-party assessment conducted by or on behalf of the organization to evaluate its own AIMS and find issues that require correction or improvement. A certification audit is an independent third-party assessment performed by a certification body to determine whether the organization qualifies for ISO 42001 certification.
5. How Long Does an ISO 42001 Internal Audit Take?
ISO 42001 does not specify how many hours or days an internal audit must take. The duration depends on the audit scope, number and complexity of AI systems, organizational size, locations involved, available evidence, and whether the audit covers the full AIMS or selected processes. Each audit should have a defined scope and criteria, making the required audit effort organization-specific.
6. What Documents Are Needed for an ISO 42001 Internal Audit?
The document set normally includes the AIMS scope and AI policy, AI system inventory, risk assessments and treatment records, the Statement of Applicability, AI system impact assessments, applicable Annex A control evidence, AI objectives and monitoring records, competence records, management review records, previous audit findings, and corrective action evidence. The exact package follows the audit scope and applicable ISO 42001 requirements and controls.
7. Can ISO 42001 and ISO 27001 Internal Audits Be Combined?
Yes. Organizations can combine an ISO 42001 audit with an ISO 27001 internal audit since both standards use a common management-system structure across areas such as context, leadership, planning, support, performance evaluation, and improvement.
Shared processes can be audited together, while AI-specific ISO 42001 requirements and information-security-specific ISO 27001 requirements should remain separately traceable to their respective audit criteria and evidence.
How Bright Defense Can Help With ISO 42001 Internal Audits
Bright Defense helps organizations prepare for ISO 42001 internal audits by turning the standard’s requirements into a clear, evidence-backed readiness process. We connect each applicable requirement to an owner, a working AIMS process, and supporting records that can be tested during the audit.
Our ISO 42001 internal audit support can include:
- Gap Assessment: Review the current AIMS against Clauses 4 through 10 and applicable Annex A controls.
- Audit Scope and Planning: Define audit criteria, scope, process owners, and evidence requirements.
- Evidence Review: Check AI risk assessments, impact assessments, the Statement of Applicability, policies, monitoring records, and other supporting evidence.
- Control Testing: Verify that documented AIMS processes and selected controls are operating in practice.
- Finding and Remediation Support: Document gaps, assign corrective actions, and track findings through resolution.
- Certification Readiness: Prepare internal audit records, management review evidence, and supporting documentation for the external certification assessment.
Bright Defense provides ISO 42001 readiness and implementation support, while the final certification decision remains with an independent certification body.


