August 24, 2026

ISO 42001 internal audits: what to expect and how to prepare 

If you’re working towards ISO 42001 certification, your internal audit is one of the most important steps in the process. It’s where you find out whether your artificial intelligence management system (AIMS) works in practice, rather than just in theory. 

Of course, you’ll want to pass your internal audit. That will allow you to move forward to the certification audit with confidence. However, don’t be overly concerned if you get something wrong.  

Here at ISO QSL, our ISO consultants can help you develop an ISO 42001 AIMS, implement it, and prepare for your audits. On this page, we’ll show you exactly what happens during an ISO 42001 internal audit, what your auditors will look for, and how to get ready. 

Are you prepared for ISO 42001?

We here to help you review your current AI management system, identify any gaps and help you get ISO 42001 certified.

About the author

Jodie Turner – Marketing Team Leader

During my time as ISO QSL, I’ve developed extensive knowledge of digital marketing alongside a strong understanding of the ISO standards that help organisations improve.  

 What an ISO 42001 internal audit is 

In the context of ISO 42001, an internal audit is a structured review of your AIMS. The objective is to confirm that its documents and processes meet the standard’s requirements, and that your employees are following it in daily operations. 

An internal audit can be carried out by a dedicated in-house team. More commonly, especially for small- to medium-sized organisations, an external ISO consultant (such as ISO QSL) is brought in to complete the internal audit. 

Even if you bring in an external auditor, an internal audit isn’t your certification audit. Its results won’t affect your compliance with ISO 42001. But not carrying out your audit, or failing to act on its findings, will. 

In fact, even if your internal audit uncovers some nonconformities, these should lead to actionable corrective measures which, in and of themselves, are good evidence of ISO 42001 compliance that your certification auditors will want to see. 

You’ll carry out internal audits at planned intervals. You should complete and act on at least one internal audit covering the full scope of your AIMS before your certification audit, and regularly thereafter as part of your continual improvement cycle.  

What to expect during an ISO 42001 internal audit 

An internal audit is a structured process. Here are the basics of what it involves:  

Audit planning and scope 

The audit will focus on specific areas of your AIMS, often based on risk. This might include particular AI systems, lifecycle stages or governance processes.  

Document and evidence review 

Internal auditors will review your documented information, including policies, procedures, risk assessments and records. They’re checking for completeness, accuracy and alignment with ISO 42001. 

Interviews with your team 

Key personnel will be asked questions about how processes work in practice, especially senior leaders and managers. This helps confirm whether your workforce and leaders understand and apply your system on a consistent basis.  

Process and control verification 

Auditors will test whether your controls are actually being followed by sampling real activities, not just reviewing documents.  

Audit findings and report 

At the end of the audit, you’ll receive the auditor’s findings: conformities, nonconformities, and observations for improvement.  

What internal auditors look for in ISO 42001 

During the process of your ISO 42001 internal audit, auditors will be looking for objective evidence. Importantly, this doesn’t just mean reading your documents. It also includes live evidence of your AIMS operating in practice.  

AIMS foundation and alignment 

Auditors will check that your AIMS is built on a clear understanding of your organisation’s context, relevant stakeholders, and defined objectives. This ensures your AIMS is aligned with real-world risks, stakeholder expectations and business objectives.  

AIMS implementation 

Your policies and procedures must reflect what actually happens day to day. Any gap between documentation and reality will be flagged. For instance, if your documented process requires risk assessments before deployment, you should be able to show completed assessments for live systems and evidence that your staff have consistently followed the process.  

AI risk management 

You need clear evidence that your organisation identifies, assesses, mitigates and monitors AI risks on an ongoing basis. This may include a current risk register or equivalent risk assessment, documented assessment methods, defined mitigation controls and ongoing monitoring or review records.  

Control over the AI lifecycle 

Auditors will expect to see governance across the full AI lifecycle, from design and development through to deployment, monitoring and change management. You should be able to provide evidence of this in the form of lifecycle procedures, testing and validation records, deployment approvals, change logs and monitoring data.  

Governance and accountability 

Within your AIMS, your roles and responsibilities must be clearly defined, with leadership actively involved in oversight and decision-making. Internal auditors will look for defined role descriptions, clear ownership of AI risks and controls, and evidence of leadership involvement, such as review records and documented decisions.  

Monitoring and continual improvement 

You should be measuring performance, conducting reviews and taking corrective action where needed. As part of this, you’ll need to provide evidence in the form of performance metrics, past internal audit results, corrective action records and management review outputs.  

How to prepare for an ISO 42001 internal audit 

Do treat an internal audit as a critical step in your certification process. It’s your opportunity to identify gaps, correct issues and confirm that your AIMS works in practice before facing a certification body. At this stage, you should expect nonconformities. This is useful. They give you the insight you need to strengthen your system and avoid problems later. 

Here’s how to prepare for your ISO 42001 internal audit:  

Define your audit scope and criteria 

Map your processes and controls against ISO 42001 requirements. Be clear on what’s being audited and why. 

Gather and organise your evidence 

Make sure all relevant documentation is accessible, up to date, and clearly linked to your processes. Auditors should be able to trace actions back to evidence.  

Review your AI risk management processes 

Check that risks are current, properly assessed and supported by appropriate controls. Outdated or incomplete risk registers are a common issue.  

Check alignment between policy and practice 

Walk through your processes and confirm they match what’s written. If your team does something differently in reality, fix it now.  

Brief your team 

Make sure staff understand their roles and can explain how processes work. Inconsistent answers are a common audit failure point. If necessary, schedule training sessions tailored to individuals’ or teams’ roles.  

Run a mock internal audit 

Simulate the audit process with an in-house team to identify gaps. This is one of the most effective ways to prepare. This can also provide additional evidence of continual improvement.  

Avoid these common ISO 42001 internal audit findings 

Here are some of the issues we most frequently encounter in ISO 42001 internal audits. Check your AIMS now to see if any apply to you:  

  • Weak or incomplete documentation. 
  • Lack of implementation evidence linking policies or assessments to actions. 
  • Gaps in AI risk management (outdated/poorly assessed/not linked to controls). 
  • Poor lifecycle governance across your AI system stages. 
  • Inconsistent understanding across teams (if different people describe processes differently, auditors will rightly question the system’s reliability).  

Tips for passing your ISO 42001 internal audit 

On the other hand, here are a few tips for ensuring you’re fully prepared for your internal audit. These principles, applied correctly, cover the majority of how your AIMS should operate:  

  • Documented intent is important; evidenced action even more so. Auditors need to see what you actually do, not what you plan or hope to do. 
  • Keep your system simple and straightforward. Overcomplicated processes are both harder for your employees to follow and harder to audit. 
  • Ensure organisation-wide consistency when it comes to your AIMS. Everyone should understand and apply the same processes, from senior leadership to workers. 
  • Prioritise high-risk AI systems (such as systems that impact safety, legal decisions or individuals’ rights). This is where your auditors will focus the majority of their attention. 
  • If you or a team member uncovers a small issue, address it immediately. With an AIMS, minor gaps can quickly become nonconformities if left unresolved.  

How internal audits support successful ISO 42001 certification 

An internal audit forms a critical part of your ISO 42001 certification in two ways. 

First, a comprehensive internal audit identifies gaps in your AIMS where you may not be meeting ISO 42001 requirements. Finding these before your Stage 1 and Stage 2 audits gives you the time you need to take corrective action. As such, you’re more likely to pass your certification audit with fewer issues. 

However, secondly, an internal audit demonstrates that your organisation is actively managing and improving its AIMS. As we’ve already discussed, if your internal audit uncovers some issues, don’t ignore it. Take corrective actions and implement additional controls. When your certification audit comes around, this serves as extra evidence of your compliance with the continual improvement requirements under ISO 42001.  

ISO QSL helps you prepare for your ISO 42001 internal audit 

Preparing for an ISO 42001 internal audit may be complex, especially if your organisation is new to AI governance and ISO management systems. It might feel overwhelming. 

This is where ISO QSL supports you. Our ISO consultants can help you build, review and refine your AIMS so it stands up to internal audit and Stage 1 and Stage 2 certification audits. From initial gap analysis through to internal audit support (or conducting the audit on your behalf), we ensure you’re fully prepared. 

Contact our team today to book a free discovery call, where we can discuss your ISO 42001 audit requirements and what we can do for you.