Can the Consultancy That Built Your AIMS Also Audit It?
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
8 min read
Contents
Somebody has built your AI Management System. The Statement of Applicability is written, the policies are approved, the AI system inventory is populated. Clause 9.2 now asks for an internal audit before the certification body arrives, and the obvious question follows: can the people who built it audit it?
The answer most often given is that it is not allowed, and a clause number usually comes attached. The clause number is real. What tends to get lost on the way is which document it sits in, and who that document binds.
The clause everyone reaches for governs your certification body, not your consultant
The prohibition lives in ISO/IEC 17021-1, the standard that accredited certification bodies are assessed against. Accreditation bodies publish their assessment checklists against it, so the requirements are readable without buying the standard. The Southern African Development Community Accreditation Service publishes one, and its clause 5.2 section on impartiality asks the certification body whether it:
- offers or provides management system consultancy, itself or through any part of the same legal entity (5.2.5)
- provides internal audits to its certified customers, or certifies a management system on which it provided internal audits within two years following the end of those internal audits (5.2.6)
- certifies a customer where its relationship with a management system consultancy, or with internal audits, poses an unacceptable threat to its impartiality (5.2.7)
- outsources audits to a management system consultancy organisation (5.2.8)
- markets or links its activities with management system consultancy (5.2.9)
Read the subject of each of those sentences. It is the certification body every time. ISO/IEC 17021-1 does not reach your consultancy, because your consultancy is not the party being accredited. There is no clause in it that says your implementer may not run your internal audit, for the same reason there is no clause in it about your choice of accountant.
The two-year rule is real and it is precise. It just applies to somebody other than the person it is usually quoted at.
This is an easy thing to get wrong, and the people who repeat it are not being careless. The requirements are genuinely strict, they genuinely are about the separation of consultancy from audit, and the folk version gets the spirit right. It compresses one step too far.
The requirement that does reach you is a different one, and it lands on you rather than on your supplier
Clause 9.2 of ISO/IEC 42001 requires the organisation to run an internal audit programme and to keep it objective and impartial. That obligation belongs to you. It is not delegated by hiring someone, and no supplier can discharge it on your behalf by asserting they were objective.
So the question at the certification audit is never whether your consultant was permitted to do the work. It is whether you can demonstrate that the audit was objective. Those are different burdens of proof, and the second one is heavier.
There is also a second-order effect worth understanding, because it is where the two threads meet. Clause 5.2.7 makes your certification body responsible for deciding whether its own relationship with your consultancy, or with your internal audits, is an unacceptable threat to its impartiality. Your arrangements are therefore assessed by somebody with an accreditation to protect. That party has every reason to take a conservative view, and no reason at all to take a generous one.
What a Stage 2 auditor is actually looking at
Not the invoice. They are looking for whether the audit could have reported something the implementer would not want reported.
An internal audit report on a system its own author built has a structural problem that has nothing to do with anyone's integrity. The auditor is being asked to find fault with decisions they made, using judgement they already applied once. Where the implementation was sound, that audit will be correct and it will still be unpersuasive, because the evidence of objectivity is missing rather than the objectivity itself.
The tell is usually the findings. An internal audit that raises nothing, or raises only administrative observations about document control, is the pattern that gets attention. A clause 9.2 audit that has never produced a nonconformity across a first certification cycle is telling the auditor something about the audit programme rather than about the management system. A pre-certification readiness audit answers a different question again, and the two are frequently confused.
Three structures that work, in the order most organisations should consider them
A different firm audits. The cleanest answer and the one that needs no explanation. This is the basis on which Goldline runs ISO 42001 internal audits, and it is why the practice does not audit AI Management Systems it implemented. You lose some efficiency, because the auditor starts without context, and you gain a second practitioner reading your system, which is frequently where the useful findings come from.
The same firm, a different auditor, with the separation documented. Workable, and common. It requires that the auditor had no involvement in the implementation, that the reporting line does not run back through the implementation lead, and that you can evidence both. The burden of proof sits with you, so decide in advance what that evidence looks like rather than assembling it after a question is asked.
Somebody internal who is independent of the AI function. Underrated. An internal auditor from a different part of the business, competent in auditing and independent of the activity, satisfies the requirement and costs nothing. The usual objection is that they will not know ISO 42001 well enough. That is a training problem with a short timeline, not a structural one.
Where this gets genuinely difficult, and where the standard is more forgiving than its reputation
At twenty people there may be nobody who is independent of the AI function, because everybody touches it. This is the case that the confident version of the rule handles badly.
Note that ISO 19011 is titled guidelines for auditing management systems. It is guidance, not a requirements standard, and the independence principle within it is written accordingly. It does not demand the impossible. Where full independence is not achievable, the defensible position is not to pretend otherwise and not to buy an external audit you cannot afford. It is to record why independence was constrained, what was done to reduce the effect, and what an auditor should therefore treat with more scepticism.
That is a weaker position than genuine independence and it should be. It is also an honest one, and certification bodies deal with small organisations constantly. A documented constraint with a compensating measure reads very differently from silence.
What to take from this
If your implementer offers to run your clause 9.2 internal audit, they are not proposing anything prohibited. They are proposing something you will have to justify, at a moment when you would rather be answering questions about your AI systems than about your audit programme.
Decide it early, while it is a scheduling question. It becomes an expensive one only if it is still open when the certification body asks.
If you are earlier than this and still working out which management system you need, ISO 27001 and ISO 42001 govern different things.
Sources
- Southern African Development Community Accreditation Service, SADCAS F 40 (a), assessment checklist against ISO/IEC 17021-1:2015, Issue 6, dated 23 August 2024. Clause 5.2 requirements on impartiality, read 1 September 2026.
- ISO/IEC 42001:2023, clause 9.2, internal audit. ISO/IEC 17021-1:2015. ISO 19011:2026, guidelines for auditing management systems, fourth edition, published 27 May 2026, superseding the withdrawn 2018 edition. These standards are not published free of charge and are not quoted directly here. Where their requirements are described above, the description rests on the accreditation body checklist cited, on the published titles and scopes, or is stated as a characterisation rather than as quotation.
Alfred Obeng
Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.
Related reading
11 min read
Second-Party AI Vendor Audit versus a Supplier Questionnaire
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
A questionnaire is the supplier's account of itself. An audit tests it against evidence. When the second instrument earns its cost, and when it does not.
- AI Governance
- ISO 42001
- Enterprise Procurement
- Supplier Assurance
7 min read
What a Stage 2 Auditor Asks About Clause 9.2
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.
- Internal Audit
- ISO 42001
- Certification
- ISO 27001
12 min read
How to Choose an ISO 42001 Consultant in the UK
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Six things to check before you engage an ISO 42001 consultant, including the independence rule in ISO/IEC 42006 that decides who is allowed to audit what they built.
- ISO 42001
- AI Governance
- Procurement
6 min read
ISO 42001 Internal Audit versus Pre-Certification Readiness Audit
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Bought at the same point, priced similarly, and routinely assumed to be the same thing. One discharges clause 9.2. The other cannot, and the sequencing is where the money leaks.
- Internal Audit
- ISO 42001
- Certification
6 min read
What ISO 19011 Requires of an Internal Auditor
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.
- Internal Audit
- ISO 42001
- ISO 27001
- Certification
6 min read
Readiness Assessment, Internal Audit, Certification Audit: Three Different Things
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.
- Certification
- Internal Audit
- ISO 27001
- ISO 42001
11 min read
ISO 27001 vs ISO 42001: What Each Standard Actually Governs
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The practical difference between an information security management system and an AI management system, where the controls overlap, and which one to implement first.
- ISO 42001
- ISO 27001
- AI Governance
12 min read
ISO 42001 and the EU AI Act: What the Standard Covers and What It Does Not
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Where ISO 42001 supports EU AI Act readiness, which obligations the standard does not reach, and how to sequence a compliance programme against the enforcement timetable.
- AI Governance
- ISO 42001
- EU AI Act
10 min read
ISO 27001 Stage 1 vs Stage 2 audits: what to expect
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The difference between Stage 1 and Stage 2 certification audits, what auditors actually look for, common nonconformities, and how to avoid them.
- ISO 27001
- Audit
- Certification
