The ISO 42001 Internal Audit Checklist: From First Plan to Certification-Ready

Four-phase ISO/IEC 42001 internal audit checklist under Clause 9.2 — plan the audit with scope, criteria, and team; prepare documents, questions, and sampling; audit clause by clause across Clauses 4 to 10; process results into nonconformities, OFIs, and conformity; then run the final pre-certification check

A phase-by-phase checklist for Clause 9.2 — from audit planning to the final pre-certification check

There is a moment every organization preparing for ISO/IEC 42001 certification gets nervous about: "We have to run an internal audit — where do we even start?" The internal audit is how an organization tests its own AI management system before an external auditor does, and one well-run internal audit prevents most of the findings a certification audit would otherwise raise. This article lays out a practical, phase-by-phase checklist you can apply as-is.

What an ISO 42001 internal audit actually is

Clause 9.2 of ISO/IEC 42001 requires internal audits at planned intervals to determine whether the AI management system (AIMS):

  • conforms to the requirements of ISO/IEC 42001 itself, and to the organization's own requirements — its AI policy, procedures, and objectives; and
  • is effectively implemented and maintained.

The second half of that sentence is the part organizations underestimate. An internal audit is not a paperwork check. It verifies that documents match how the organization actually operates: that staff understand the AI policy, that risk treatments are really being carried out, that monitoring happens on the schedule the procedure claims. In a certification audit, the internal audit report is one of the first records requested — and a report that found nothing tends to read less as evidence of a mature system than as evidence of a shallow audit.

Phase 1 — Plan the audit (4–6 weeks before)

Fix the scope and criteria

  • ☐ Confirm the scope of this audit — the full AIMS, specific functions, or specific AI systems
  • ☐ Confirm the audit criteria documents: ISO/IEC 42001, plus the organization's AI policy and procedures
  • ☐ Review the previous internal audit results — check for repeat findings
  • ☐ Review the status of corrective actions from the previous audit

Assemble the audit team

  • ☐ Verify auditor competence (internal auditor training for ISO/IEC 42001 or an equivalent management system discipline)
  • ☐ Ensure auditor independence — no one audits their own work area
  • ☐ Appoint an audit team leader
  • ☐ Assign roles and responsibilities within the team

Independence is worth flagging: it is one of the first things an external auditor is likely to verify about your internal audit, and a developer who audited their own AI system's controls can invalidate the exercise regardless of how thorough it was. (ISO 19011, the generic guidance standard for auditing management systems, is a useful reference for structuring all of this.)

Set the schedule

  • ☐ Draft the audit timetable — time allocated per function and per process
  • ☐ Notify auditees in advance (at least two weeks)
  • ☐ Request the documents the audit will need ahead of time

Phase 2 — Prepare (1–2 weeks before)

Document review

  • ☐ AI policy — current version, approved and signed by top management
  • ☐ AIMS scope statement reviewed
  • ☐ AI risk assessment up to date
  • ☐ AI impact assessments complete for in-scope systems
  • ☐ AI objectives and the plans to achieve them reviewed
  • ☐ Competence and training records available
  • ☐ Internal audit checklist drafted
  • ☐ Supplier evaluation and management records available

If any of these documents are missing outright, pause the audit preparation and fix that first — the ten documents an ISO 42001 certification audit will ask for is the reference list.

Audit questions and sampling

  • ☐ Question list prepared per clause
  • ☐ Interviewees identified and confirmed
  • ☐ Sampling plan set — which records, and how many of each

Phase 3 — The clause-by-clause checklist

Clause 4 — Context of the organization

  • ☐ Are internal and external issues documented?
  • ☐ Are interested parties (customers, regulators, employees, affected individuals) and their requirements identified?
  • ☐ Is the AIMS scope clearly defined?
  • ☐ Are any exclusions from scope properly justified?

Clause 5 — Leadership

  • ☐ Is the AI policy approved and signed by top management?
  • ☐ Has the policy been communicated across the organization (intranet, training, postings)?
  • ☐ Are AIMS roles and responsibilities formally assigned?
  • ☐ Is there evidence of genuine top-management involvement in AI governance?

Clause 6 — Planning

  • ☐ Is AI risk assessment performed at planned intervals?
  • ☐ Does it cover AI-specific risks — bias, opacity, failure of human oversight — not just generic IT risk?
  • ☐ Is the risk treatment plan established and being implemented?
  • ☐ Are AI objectives specific and measurable?
  • ☐ Is progress against those objectives monitored?

Clause 7 — Support

  • ☐ Are adequate resources allocated to operate the AIMS?
  • ☐ Are competence requirements defined for AI-related roles?
  • ☐ Has a competence gap analysis been done, with training delivered against it?
  • ☐ Is AI awareness training delivered to all relevant staff, with records?
  • ☐ Is documented information controlled systematically?
  • ☐ Do documents carry version, approver, and revision history?

Clause 8 — Operation

  • ☐ Are AI governance requirements built into AI system development and procurement?
  • ☐ Is there a supplier evaluation procedure for AI providers, with records maintained?
  • ☐ Are external AI services (model APIs, AI-enabled SaaS) under a defined management procedure?
  • ☐ Has an impact assessment been performed per AI system?
  • ☐ Are human oversight mechanisms defined — and actually operating?
  • ☐ Is AI model monitoring performed regularly, with records?

Clause 9 — Performance evaluation

  • ☐ Are performance indicators defined for the AIMS?
  • ☐ Is monitoring, measurement, and analysis happening on schedule?
  • ☐ Is there an internal audit programme, executed at planned intervals?
  • ☐ Does management review take place regularly, with top management participating?
  • ☐ Are management review minutes recorded and retained?

Clause 10 — Improvement

  • ☐ Is there a procedure for nonconformity and corrective action?
  • ☐ Is root-cause analysis performed when nonconformities occur?
  • ☐ Is the effectiveness of corrective actions verified?
  • ☐ Are continual improvement activities planned and carried out?

Phase 4 — Process the results

Classify what you found

Internal audit findings fall into three categories:

  • Nonconformity (NC) — a requirement of ISO/IEC 42001 or of the organization's own system is not met. Corrective action is mandatory. A major nonconformity is a total absence of a required element or a failure that undermines the system as a whole; a minor nonconformity is an isolated, contained lapse.
  • Opportunity for improvement (OFI) — the requirement is met, but there is a better way. Not mandatory, but worth acting on.
  • Conformity — the requirement is met. Record it; positive evidence matters too.

Drawing the line between an OFI and a genuine nonconformity is its own discipline — external auditors apply specific judgment criteria here, and internal audits benefit from mirroring them.

Close-out checklist

  • ☐ Audit report completed
  • ☐ Corrective action plan per nonconformity — with an owner and a due date
  • ☐ Corrective action progress tracked
  • ☐ Effectiveness of completed corrective actions verified
  • ☐ Audit results reported as an input to management review
  • ☐ Next internal audit scheduled

The seven findings internal audits are most likely to surface

  • ① AI-specific risks missing from the risk assessment. The register covers generic IT risks — but not bias, opacity, or failure of human oversight. (A structured methodology helps: see our five-step AI risk assessment guide.)
  • ② No evidence the AI policy was communicated. The policy exists, but nothing shows it reached staff — no training records, no intranet posting logs.
  • ③ Objectives that can't be measured. "Improve AI safety" with no indicator that could ever confirm achievement.
  • ④ No management records for external AI suppliers. External model APIs and AI-enabled SaaS in active use, with no supplier evaluation on file.
  • ⑤ Top management absent from management review. Reviews run at team-lead level, with no evidence of genuine executive participation.
  • ⑥ Corrective action effectiveness never verified. The fix was implemented — but nothing confirms it actually worked.
  • ⑦ Auditor independence violated. An internal auditor audited their own area of responsibility.

These overlap heavily with the nonconformities most likely to appear in an external certification audit — which is precisely the point. Whatever your internal audit catches, the certification audit doesn't have to.

The final check before the certification audit

Documentation

  • ☐ All required documents current — versions, approvers, dates in place
  • ☐ Operating records available for the period the audit will cover

Internal audit

  • ☐ Internal audit performed and reported
  • ☐ Corrective actions for its findings completed
  • ☐ Effectiveness of those actions verified

Management review

  • ☐ Management review held with internal audit results as an input
  • ☐ Minutes retained, showing top-management participation
  • ☐ Improvement decisions from the review under way

People

  • ☐ Interviewees briefed on the audit schedule
  • ☐ Process owners familiar with the AI policy and their own procedures

The bottom line

An internal audit is a rehearsal for the certification audit — but it is more than that. It is the organization's own mechanism for finding out whether its AI governance actually works, and fixing it where it doesn't. A box-ticking internal audit helps neither the organization nor the certification outcome. Run it with this checklist and genuine curiosity about what's really happening on the ground, and the external audit holds far fewer surprises.

Want a quick read on where your organization stands before you plan that first internal audit? Our free AI governance readiness assessment takes about 10 minutes, requires no document uploads, and shows how prepared you are for ISO/IEC 42001.

 


Related

🔍 What external audits find: the 5 nonconformities most likely to appear in your ISO 42001 audit.

📄 The paper trail: the 10 documents your certification audit will check.

📗 Before you audit risk: a five-step AI risk assessment methodology that holds up in an audit.

🗺 The whole portfolio: part of our SC 42 AI Standards Map — the international AI standards portfolio, explained.