How Can Companies Prepare For ISO 42001 Audits?
Updated:
August 25, 2026
78% of business executives lack strong confidence that their organizations could pass an independent AI governance audit within 90 days. As AI regulation and governance expectations increase, ISO/IEC 42001 certification is becoming more valuable for organizations that need to demonstrate responsible AI management.
Preparing for an ISO 42001 audit involves defining the AIMS scope, assessing AI risks, assigning responsibilities, documenting controls, and completing internal reviews. In practice, each of these steps requires detailed evidence, cross-functional input, and careful implementation before an organization is truly audit-ready.
This guide walks through what that preparation looks like in practice, where companies commonly need the most work, and how to approach each stage before the certification audit begins.
What Is ISO 42001 and Why Is It Important?
ISO/IEC 42001 is the international standard for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS). Published in December 2023, it gives organizations that develop, provide, or use AI systems a formal framework for managing AI governance, risks, responsibilities, and opportunities throughout the AI lifecycle.

ISO 42001 is important because it turns AI governance into documented and repeatable organizational processes. Its requirements help organizations:
- Assign AI responsibilities across leadership, technical teams, and other relevant roles.
- Assess and treat AI risks through documented risk and impact assessments.
- Set AI governance policies for the development, procurement, deployment, and use of AI systems.
- Maintain transparency and accountability around how AI systems are managed and monitored.
- Manage AI data and system controls throughout the AI lifecycle.
- Monitor performance and improve the AIMS as AI systems, risks, and organizational requirements change.
- Demonstrate responsible AI governance to customers, auditors, regulators, and other stakeholders.
ISO 42001 governs the management system surrounding AI, rather than certifying that an individual AI model is completely safe, unbiased, or error free. This distinction makes the standard particularly useful for organizations managing multiple AI systems and changing AI risks over time.
What Is an ISO 42001 Audit?
An ISO 42001 audit is a formal assessment of an organization’s AI management system against the requirements of ISO/IEC 42001. It reviews AI governance, risk management, policies, controls, documentation, and operational practices to determine whether the organization’s AI management system is properly implemented and conforms to the standard.
What Are the Types of ISO 42001 Audits?
ISO 42001 audits can be conducted as internal audits, external audits, or combined or integrated audits. The main difference is who performs the audit and whether ISO 42001 is assessed independently or alongside another management system standard.

1. Internal ISO 42001 Audits
An internal ISO 42001 audit evaluates whether the organization’s Artificial Intelligence Management System (AIMS) conforms to its own requirements and ISO/IEC 42001. Clause 9.2 requires internal audits at planned intervals as part of maintaining the AIMS.
Internal audits typically review:
- AIMS scope, policies, and objectives
- AI roles and responsibilities
- AI risk and impact assessments
- Selected Annex A controls
- Records showing that processes operate as documented
- Previous findings and corrective actions
The auditor must remain objective and impartial. The audit may be performed by qualified employees or an independent external professional acting on the organization’s behalf. Internal audit findings give the organization an opportunity to correct nonconformities before a certification audit.
2. External ISO 42001 Audits
An external ISO 42001 audit is performed by a party outside the organization. For ISO 42001 certification, an independent certification body evaluates whether the AIMS conforms to the standard and operates effectively.
The initial certification audit normally includes:
- Stage 1: Reviews AIMS scope, documentation, readiness, and key management system requirements.
- Stage 2: Examines implementation and effectiveness through evidence review, sampling, and stakeholder interviews.
Certification does not end the external audit process. Certified organizations generally undergo surveillance audits during the certification cycle and a recertification audit before the certificate is renewed.
3. Combined or Integrated ISO 42001 Audits
A combined audit assesses two or more management systems during the same audit program. ISO 19011 recognizes this approach, while an integrated audit generally refers to auditing management systems that have been brought together within a single management system.
For example, an organization operating both ISO 42001 and ISO 27001 may coordinate audits where the two standards share processes such as:
- Risk management
- Internal auditing
- Management review
- Document control
- Corrective actions
- Governance responsibilities
A combined or integrated audit can reduce duplicated evidence reviews and interviews, but each standard retains its own requirements and audit criteria. The organization must still demonstrate conformity with the applicable ISO 42001 requirements.
| Audit Type | Who Performs It? | Primary Purpose |
| Internal Audit | Organization or independent party acting on its behalf | Evaluate the AIMS and find nonconformities |
| External Audit | Independent external party or certification body | Assess conformity and support certification |
| Combined or Integrated Audit | Internal or external audit team | Assess ISO 42001 alongside other management systems |
For Which Organizations Is an ISO 42001 Audit Mandatory?
An external ISO 42001 certification audit is not legally mandatory for organizations simply because they develop, provide, or use AI. ISO states that certification to its management system standards is voluntary, meaning an organization can implement ISO/IEC 42001 without obtaining certification.

An ISO 42001 audit becomes required in specific circumstances:
- Organizations seeking ISO 42001 certification: A third party certification audit is required before an organization can receive an ISO/IEC 42001 certificate.
- Organizations maintaining certification: Certified organizations must undergo surveillance and recertification audits as part of the certification cycle.
- Organizations implementing ISO 42001: Clause 9.2 requires organizations operating an AIMS in conformity with ISO 42001 to conduct internal audits at planned intervals.
- Organizations with contractual requirements: A customer, partner, procurement program, or service agreement may require ISO 42001 certification or independent evidence of conformity.
- Organizations subject to organization specific requirements: A parent company, government procurement program, industry program, or internal governance policy may make ISO 42001 auditing a condition for doing business or operating particular AI systems.
Legal requirements should be distinguished from ISO certification requirements. A law may require an organization to maintain AI risk management, documentation, human oversight, or other governance measures without requiring ISO 42001 certification itself.
The EU AI Act is a good example. European harmonized standards can provide a presumption of conformity with covered AI Act requirements, but their use remains voluntary. The European Commission stated in August 2026 that organizations may use other methods to demonstrate compliance. It has further clarified that ISO/IEC 42001 alone is not aligned with the specific quality management system required under the AI Act, which is why a separate European standard is being developed for that purpose.
| Organization or Situation | Is an ISO 42001 Audit Required? |
| Organization uses or develops AI | No |
| Organization implements ISO 42001 without certification | Internal audits are required under the standard |
| Organization wants ISO 42001 certification | Yes, a certification audit is required |
| Organization already holds certification | Yes, ongoing certification audits are required |
| Customer or contract requires certification | Yes, according to the contractual requirement |
| Organization must comply with the EU AI Act | ISO 42001 certification itself is not mandatory |
The key distinction is that ISO 42001 is voluntary, but auditing becomes mandatory once an organization chooses to claim conformity under the standard or pursue and maintain accredited certification.
What Is the ISO 42001 Audit Process? Step-by-Step
The ISO 42001 audit process moves through eight stages, from defining the Artificial Intelligence Management System (AIMS) scope to ongoing certification oversight. Internal readiness comes first. An independent certification body conducts the initial assessment, reviews corrective actions, makes the certification decision, and then performs surveillance and recertification across the certification cycle.

1. Define the AIMS Scope and Audit Criteria
The first step defines the boundaries of the AIMS and the criteria used during the audit. A clear scope states which AI activities, organizational units, and relevant products or services fall within the management system, giving auditors a precise basis for evaluating conformity across the organization.
The organization documents the AI systems covered by the AIMS and the business functions within scope. Relevant legal, contractual, and interested-party requirements form part of the audit criteria.
The documented scope must correspond with the organization’s actual AI activities and reflect how in-scope systems operate throughout their lifecycle.
2. Complete the Internal Audit and Management Review
The organization completes its internal audit and management review before the external certification assessment. Clause 9.2 requires internal audits at planned intervals to evaluate conformity with organizational requirements and ISO 42001. Management review confirms that top management has examined AIMS performance and the actions needed to maintain effectiveness.
The internal audit examines AI governance and risk processes. Its scope includes AI system inventories and the Annex A controls selected for the AIMS, with lifecycle controls tested through records that show how those requirements operate.
Top management then completes the management review required under Clause 9.3. The review covers AIMS performance and significant changes, along with actions needed for improvement.
3. Select a Certification Body and Plan the Audit
The organization selects an independent certification body to perform the external assessment. The certification body confirms the certification scope and calculates the required audit duration. It then appoints an audit team with the necessary competence.
Audit planning sets the dates and locations for the assessment. It specifies the documentation that must be available and the personnel who will participate.
ISO/IEC 42006:2025 provides AI-specific requirements for bodies that audit and certify ISO 42001 management systems. It supplements the management system certification requirements in ISO/IEC 17021-1.
4. Complete the Stage 1 Audit
The Stage 1 audit determines whether the organization is ready for the detailed Stage 2 assessment. During this phase, the certification body evaluates AIMS readiness, reviews the documented foundation of the management system, and gathers the information needed to plan the scope, depth, and focus of Stage 2.
Stage 1 reviews the Statement of Applicability required under Clause 6.1.3, including the necessary controls and justification for their inclusion or exclusion. The certification body reviews the AI risk treatment plan and other documented information needed to judge readiness.
The organization corrects Stage 1 concerns that prevent readiness and updates the supporting evidence. The certification body proceeds to Stage 2 after confirming that the AIMS is ready for the full assessment.
5. Complete the Stage 2 Certification Audit
The Stage 2 audit evaluates whether the AIMS is implemented and operating effectively. Auditors gather objective evidence through interviews and record review. Sampling connects documented requirements with actual practices across selected AI systems and processes.
Evidence covers:
- AI risk treatment and AI system impact assessments
- AI lifecycle documentation and data governance controls
- Human oversight and accountability
- Transparency requirements and related information
- Monitoring and incident management
- Supplier governance and internal audit evidence
The audit team uses this evidence to determine whether the AIMS meets ISO 42001 requirements within the approved certification scope.
6. Review Audit Findings and Nonconformities
The audit team documents its findings and presents the conclusions at the end of Stage 2. The certification body evaluates each nonconformity according to its significance, links it to the applicable ISO 42001 requirement, and records the objective evidence supporting the finding and the required follow-up.
Major nonconformities represent significant or systemic failures that affect the AIMS or its ability to meet applicable requirements. Minor nonconformities represent limited failures where an applicable requirement has not been fully met.
The audit report provides the basis for corrective action and the subsequent certification review.
7. Correct Nonconformities and Complete the Certification Decision
Corrective action addresses recorded nonconformities before a certificate is granted. The organization documents each correction, analyzes the root cause, and implements action that removes or controls that cause. This evidence gives the certification body a clear basis for deciding whether unresolved issues still affect conformity.
The certification body reviews the audit results and corrective action evidence. Major nonconformities must be satisfactorily addressed before the organization can receive its certificate.
A successful decision results in an ISO/IEC 42001 certificate covering the approved AIMS scope.
8. Complete Surveillance and Recertification Audits
ISO 42001 certification continues through a three-year certification cycle that includes surveillance and recertification. Surveillance confirms that the AIMS remains conformant and effective after the initial decision. Recertification provides the broader reassessment required before the next cycle begins.
Surveillance audits review selected parts of the AIMS, with emphasis on previous findings and management system performance. Significant changes since the preceding assessment receive audit attention as part of continued oversight.
Recertification provides a broader evaluation of the AIMS before the next certification cycle begins. The assessment confirms continued conformity and supports the renewal decision.
| Audit Phase | Primary Purpose | Main Result |
| Scope Definition | Set the AIMS boundaries and audit criteria | Documented AIMS scope |
| Internal Audit | Evaluate internal conformity and management oversight | Audit findings and management review records |
| Audit Planning | Set the external assessment parameters | Confirmed scope, audit duration, team, and schedule |
| Stage 1 | Evaluate readiness for the detailed assessment | Stage 1 conclusions and readiness decision |
| Stage 2 | Evaluate AIMS implementation and effectiveness | Audit evidence and findings |
| Findings Review | Classify and document audit results | Recorded nonconformities and audit conclusions |
| Certification Decision | Review corrective actions and determine eligibility | ISO 42001 certificate |
| Surveillance and Recertification | Confirm continued conformity across the certification cycle | Maintained or renewed certification |
How to Prepare for Your ISO 42001 Audit
Preparing for an ISO 42001 audit requires a defined AIMS scope, current AI risk documentation, operational evidence, a completed internal audit and management review, and resolved corrective actions. Each applicable requirement should connect to a responsible owner, an implemented process, and evidence that demonstrates how the Artificial Intelligence Management System (AIMS) operates.

1. Confirm Your AIMS Scope and AI Inventory
Confirm which organizational functions, AI activities, and systems fall within the certification scope. Keep the AI system inventory current so auditors can see which systems are governed through the AIMS.
Review the scope for new AI tools, third party services, retired systems, and organizational changes before the audit begins.
2. Map ISO 42001 Requirements to Evidence
Create an audit readiness matrix connecting ISO 42001 requirements to responsible owners, documented processes, and supporting evidence.
For each applicable requirement, record:
- The responsible owner
- The relevant policy or procedure
- Evidence showing the process operates
- Any unresolved gap
This makes missing documentation or unsupported controls easier to address before the certification audit.
3. Review AI Risks, Impacts, and the Statement of Applicability
Confirm that AI risk assessments, risk treatment records, and AI system impact assessments reflect current systems and activities.
Review the Statement of Applicability (SoA) required under Clause 6.1.3. It should document the controls needed for risk treatment and justify their inclusion or exclusion. The AI risk treatment plan should correspond with those decisions.
4. Test Controls and Collect Operational Evidence
Auditors need evidence that documented AIMS processes operate in practice. Review applicable controls and collect current records that demonstrate implementation.
Relevant evidence can include:
- AI lifecycle and change records
- Monitoring and human oversight records
- Training and competence records
- Incident and corrective action records
- Supplier and third party AI records
A written policy alone does not demonstrate effective implementation. Organizations should also retain evidence showing how automated and AI-assisted processes perform in practice and where human review remains necessary. This is particularly important for security testing, where support for fully automated penetration testing dropped to just 9% in 2026 after security teams reported missed critical vulnerabilities. Operational records should therefore show how automated outputs are monitored, validated, escalated, and reviewed by responsible personnel when the associated AI system or control requires human oversight.
5. Complete the Internal Audit and Management Review
Complete the internal audit required under Clause 9.2 before the certification assessment. The audit should test relevant ISO 42001 requirements and applicable Annex A controls across the AIMS scope.
Top management then completes the Clause 9.3 management review, covering AIMS performance, audit results, significant changes, and improvement actions.
Keep both sets of records ready for Stage 1.
6. Close Gaps and Document Corrective Actions
Resolve readiness gaps before the certification audit. Record each nonconformity, its cause, the corrective action taken, and evidence that the action was effective.
Material findings should be retested so the organization can demonstrate that the underlying issue has been addressed.
7. Prepare Process Owners for Auditor Interviews
Process owners should understand their responsibilities and know where relevant evidence is stored. Auditors use interviews to compare documented procedures with actual working practices.
Leadership should be prepared to explain AI governance responsibilities, AIMS objectives, and management oversight.
8. Prepare Your Stage 1 Audit Package
Organize the core documentation the certification body will need to assess readiness for Stage 2.
The Stage 1 package should include:
- AIMS scope
- Statement of Applicability
- AI risk treatment plan
- Risk and impact assessment records
- Internal audit report
- Management review records
Confirm audit dates, required personnel, locations, and document access before the assessment begins.
A strong final readiness test is straightforward: every applicable ISO 42001 requirement should connect to an owner, a working process, and supporting evidence.
What Are the Requirements for ISO 42001 Audits?
ISO 42001 audit requirements center on demonstrating that an Artificial Intelligence Management System (AIMS) conforms to ISO/IEC 42001 and operates effectively.
An organization needs a defined scope, documented AI governance and risk processes, applicable controls, operational evidence, completed internal audit and management review activities, and records showing that nonconformities receive corrective action.
The main requirements auditors examine include:

Certification audits add requirements for objective evidence and demonstrated implementation. Auditors test whether documented processes operate across the approved scope through interviews, record review, observation, and sampling.
Organizations seeking third-party certification are assessed by a certification body. ISO/IEC 42006:2025 sets additional AI-specific requirements for bodies conducting ISO 42001 audits and certification, supplementing ISO/IEC 17021-1.
How Does Bright Defense Help With ISO 42001 Audit Readiness?
Bright Defense helps organizations prepare for ISO 42001 audits through hands-on compliance support, risk assessment, policy development, evidence management, remediation tracking, and audit preparation. We help teams turn ISO/IEC 42001 requirements into documented AIMS processes and operational evidence that can be presented during an independent certification audit.
Our ISO 42001 audit readiness support can include:
- Gap assessment: Review the current AI governance program against ISO 42001 requirements and document areas that need remediation.
- AIMS scope and AI governance: Define the management system boundaries, responsibilities, and governance processes needed for the audit.
- AI risk management: Support AI risk assessments, treatment planning, and the documentation required to show how AI risks are managed.
- Policies and controls: Develop and update policies, procedures, and supporting controls across the AIMS.
- Evidence preparation: Organize evidence so requirements, controls, owners, and operating records are easy to trace during the audit.
- Remediation support: Track gaps through resolution and help teams document corrective actions before the certification assessment.
- Ongoing compliance: Support control monitoring and evidence collection after initial readiness work so the AIMS remains prepared for surveillance and recertification activities.
Bright Defense supports ISO 42001 readiness and audit preparation, while the certification decision remains with an independent certification body. This separation gives organizations practical implementation support without confusing readiness consulting with third-party certification.
FAQ
1. Do I Need to Implement All Controls in ISO 42001 Annex A Before the Audit?
No. ISO/IEC 42001 uses a risk-based approach to Annex A controls, so organizations do not need to implement every control. Clause 6.1.3 requires you to determine the controls needed for AI risk treatment and document them in the Statement of Applicability. Excluded controls need a clear justification, and additional controls can be used when necessary.
2. How Long Does an ISO 42001 Audit Take?
An ISO 42001 audit has no fixed duration. Audit time depends on the AIMS scope, organizational size, complexity, and the AI activities being assessed. Certification includes separate Stage 1 and Stage 2 audits, so the overall certification schedule extends beyond the audit days themselves. DNV recommends allowing about 6 to 8 weeks between Stage 1 and Stage 2 to address readiness issues.
3. How Often Do ISO 42001 Audits Occur?
ISO 42001 certification follows a three-year certification cycle. After the initial Stage 1 and Stage 2 audits, surveillance audits occur at least once each calendar year, except during the recertification year. The first surveillance audit must take place within 12 months of the initial certification decision, followed by recertification before the certificate expires.
4. What Happens If the ISO 42001 Auditor Finds Nonconformities?
The organization must address nonconformities through correction and corrective action. Major nonconformities require the certification body to verify the correction and corrective action before certification can be granted. For minor nonconformities, the certification body can accept a corrective-action plan and verify effective implementation during a subsequent audit.
5. Who Conducts an ISO 42001 Audit?
An ISO 42001 certification audit is conducted by an independent certification body, not ISO itself. ISO/IEC 42006:2025 sets AI-specific requirements for bodies that audit and certify AIMS against ISO/IEC 42001. Internal audits can be performed by competent employees or external professionals, provided the audit process remains objective and impartial.
6. Is an ISO 42001 Audit Mandatory?
ISO 42001 certification is voluntary in general, and organizations can implement the standard without pursuing third-party certification. Internal audits are required for organizations claiming conformity with the standard because Clause 9.2 requires them at planned intervals. External certification can become necessary when a customer, contract, procurement program, or applicable legal requirement specifically requires certification.
7. Can I Start ISO 42001 Prep Without an In-House AI Team?
Yes. ISO 42001 does not require a dedicated in-house AI team. Clause 7.2 requires the organization to have access to people with the competence needed for work affecting AI performance. Organizations can develop that competence through training or use qualified contractors and external specialists while retaining internal responsibility for the AIMS and its requirements.


