Where organizations are most likely to get caught — and how to close each gap before the audit, not during it
Organizations preparing for an ISO/IEC 42001 certification audit tend to ask the same question: "Where do auditors actually raise nonconformities?" There is no shortage of textbook explanations of the requirements, but very little on the failure patterns that surface once an auditor starts pulling records and interviewing staff. This article sets out the five gaps a certification auditor is most likely to flag, why each one occurs, and what to put in place before audit day.
First, understand what an auditor is verifying
Every finding in a management-system audit traces back to one of two questions:
- Does the documentation exist? The AI policy, the risk assessment, the procedures the standard requires.
- Is it actually operating? Do records and interviews show the organization doing what its documents say it does?
Most nonconformities come from the second question. Documents are the easy part; the gap between what is written and what is practiced is where audits are decided. The five findings below all live in that gap. The ranking reflects how the requirements of ISO/IEC 42001 interact with the habits organizations bring from earlier management systems — it is an audit-practice perspective, not a statistical survey.
1. AI-specific risks missing from the risk assessment
Likelihood: ★★★★★
Many organizations preparing for ISO 42001 already hold ISO 27001, and they reuse their information-security risk methodology as-is. The result is a risk register full of hacking, data leakage, and access-control failures — and nothing that is actually about AI. It reads like an ISO 27001 register with the word "AI" inserted into the title.
An auditor reviewing that register will ask three questions: Where are your bias-related risks? Have you assessed risks arising from the opacity of the model's decisions? Where is the risk of human-oversight failure? If the register has no line items that answer them, that is a nonconformity against the AI risk assessment requirements (Clauses 6.1.2 and 8.2) — the assessment has not addressed the risks the standard exists to manage.
How to close the gap: make sure the risk assessment explicitly covers the intrinsic risk categories of AI systems, including:
- Algorithmic bias and unfair outcomes
- Opacity — decisions that cannot be explained to those affected
- Malfunction driven by degraded data quality
- Failure of human-oversight mechanisms
- AI supply-chain risk from external models and APIs
- Model performance drift over time
ISO/IEC 23894 is the natural companion here — our overview of ISO/IEC 23894 covers AI risk sources in depth. And if your methodology came from ISO 27001, start with where the two standards' risk lenses genuinely differ.
2. An AI policy that exists on paper but was never communicated
Likelihood: ★★★★☆
The AI policy document itself is usually fine — well written, signed by top management. Then the auditor asks an employee outside the project team: "Are you familiar with your company's AI policy?" If the answer is "our what?", the finding writes itself. Clause 5.2 requires the AI policy to be communicated within the organization, and Clause 7.3 requires people doing work under the AIMS to be aware of it.
Auditors verify this through staff interviews, intranet posting history, and attendance records for AI awareness training — and by checking whether the training material actually covers the policy.
How to close the gap: publish the policy on the intranet and keep the posting record, run AI awareness training for all staff and keep attendance evidence, include the policy's key commitments in the training material, and fold AI policy orientation into onboarding.
3. AI objectives that cannot be measured
Likelihood: ★★★★☆
Objective documents are often a collection of aspirations: "improve the safety of AI systems", "strengthen AI governance capability", "pursue responsible AI operations". None of these can be evaluated as achieved or not achieved. Clause 6.2 requires AI objectives to be measurable where practicable — and an auditor will treat a page of unmeasurable aspirations as a planning failure, not a style choice.
Compare a weak objective with a workable one:
- Weak: "Reduce AI bias."
- Workable: "Keep the gender difference in the recruitment model's pass rate within ±3% by December 2026 (currently ±8%, measured quarterly)."
How to close the gap: every AI objective should carry a concrete metric or criterion, a measurement method and frequency, an accountable owner, and a deadline — plus monitoring records showing the objective is actually tracked.
4. External AI suppliers used everywhere, managed nowhere
Likelihood: ★★★★☆
Most organizations today consume AI from outside: model APIs, cloud AI services, AI features embedded in SaaS products. What is often missing is any record that these suppliers are managed. ISO/IEC 42001 expects the organization to address AI-related third-party relationships — Annex A area A.10 is dedicated to third parties, including suppliers — and "we use the enterprise tier" is not a supplier evaluation.
An auditor will typically ask to see the list of external AI services in use, then ask where the supplier assessments are, whether contracts allocate AI-related responsibilities, and whether anyone has ever reviewed the supplier's own AI policy or ethics commitments. Silence on all four is a finding.
How to close the gap: maintain a current inventory of every external AI service, with an evaluation record per supplier covering the supplier's AI governance posture, how it processes your data, service-continuity assurances, and the AI responsibility clauses in the contract.
5. Internal audit results that never reach management review
Likelihood: ★★★☆☆
The internal audit happened. The management review happened. But the minutes of the management review never mention the three nonconformities the internal audit raised — the two processes run in parallel and never touch. Clause 9.3 explicitly lists audit results among the inputs to management review, so the disconnect is itself a nonconformity, and it usually signals a deeper one: leadership is not actually steering the AIMS on evidence.
How to close the gap: management review minutes should summarize the latest internal audit results, the status of corrective actions for each finding, completion plans for anything still open, and any pattern of repeat findings.
Bonus: three audit-day mistakes that cost credibility
- Interviewees who weren't prepared. Auditors question the people who actually operate the AI systems, not just the certification project team. Practitioners should be able to explain the risk assessment process in their own words.
- Presenting outdated documents. A document with no version history, or a version that contradicts the one in the quality folder, turns a routine check into a document-control finding.
- Slow access to records. "That record is with a colleague who's away" — every delayed record erodes the auditor's confidence in the system. Keep all evidence retrievable from one place, immediately.
Pre-audit self-check
- Does the risk assessment include AI-intrinsic risks — bias, opacity, malfunction, oversight failure, supply chain, drift?
- Does each risk have a treatment plan and implementation records?
- Is the AI policy published internally, with the posting record kept?
- Can a randomly selected employee describe the policy's main commitments?
- Does every AI objective have a metric, a measurement method, an owner, and a deadline — with monitoring records?
- Is the external AI service inventory current, with an evaluation record per supplier?
- Do the management review minutes cover internal audit results and corrective-action status?
The bottom line
Organizations rarely fail ISO 42001 audits because they don't know the requirements. They fail because the requirements never made it from the documents into day-to-day operation — and from operation into records. Writing documents is easier than operating them; operating is easier than proving it with evidence. The organizations that walk into an audit with confidence are the ones that closed all three gaps beforehand. Check the five points above now: anything you find before the audit is an internal fix; anything the auditor finds is a nonconformity.
Wondering which of these gaps your organization has? Our free AI governance readiness assessment takes about 10 minutes, requires no document uploads, and shows where you stand against ISO/IEC 42001 before an auditor does.
Written by a certified ISO/IEC 42001 Lead Auditor and principal consultant at ITG insights.
ITG insights specializes in ISO/IEC 42001 and ISO/IEC 20000 certification consulting, risk management, and governance framework design. Consulting and training inquiries: info@ai42001.ai
ai42001.ai is an AI governance platform structured around ISO/IEC 42001.
Related
⚖️ Comparing systems: ISO 42001 vs ISO 27001 — the differences, and how to run them together.
🔧 Already hold ISO 27001? The control-by-control path: extending an ISO 27001 ISMS to ISO 42001.
📘 The standard itself: the ISO/IEC 42001 reference overview.
🗺 The whole portfolio: part of our SC 42 AI Standards Map — the international AI standards portfolio, explained.