ISO 42001 Internal Audit versus Pre-Certification Readiness Audit
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
6 min read
Contents
These two are bought at roughly the same point, cost roughly the same, and are frequently assumed to be the same thing bought under two names. They are not, and the difference is not commercial. One discharges a clause of the standard. The other does not and cannot.
Buying the wrong one does not usually surface until the certification body asks for the clause 9.2 evidence and receives a readiness report instead.
The one-line difference
The internal audit is an obligation. Clause 9.2 of ISO/IEC 42001 requires it, it recurs for as long as you hold the certificate, and it has to be objective.
The pre-certification readiness audit is a rehearsal. Nothing requires it, it happens once before a booked certification audit, and it is advisory work rather than an audit of conformity.
Set against each other
| ISO 42001 internal audit | Pre-certification readiness audit | |
|---|---|---|
| Why it exists | Required by clause 9.2 | Chosen, to reduce the risk of a failed Stage 2 |
| What it tests | Conformity of the AIMS against the standard and your own criteria | Whether you would pass, judged against Stage 1 and Stage 2 criteria |
| Independence | Objectivity and impartiality required by the clause | Advisory, so no independence requirement attaches |
| Can the implementer do it | Possible but you carry the burden of proof | Yes, and often better, because context helps |
| Output | Audit report, nonconformities, into clause 10 and the management review | Findings with severity, and a remediation plan |
| Frequency | Planned intervals, continuing for the life of the certificate | Once, before a booked audit |
| Counts for clause 9.2 | Yes | No |
That last row is the one that costs money when it is got wrong.
Why a readiness audit cannot substitute
Because of what it is for. A readiness audit is designed to tell you what an auditor will find, so its value comes from being informed by the implementation. The person conducting it is trying to help you pass, and the more they know about how the system was built the more useful they are.
A clause 9.2 internal audit is designed to tell your own management the truth about conformity, including where it is uncomfortable. Its value comes from the opposite property.
Those two purposes pull in different directions, which is why one carries an independence requirement and the other does not. Running them as a single exercise gets you an audit that is either a poor rehearsal or a compromised internal audit, and usually the second.
Which you need, and when
Internal audit only. You are certified or close to it, the system has been operating, and the annual obligation is due. This is the recurring case and it is most organisations most years.
Readiness audit only. You have a Stage 2 booked, the internal audit is already done and defensible, and what you want is a second reading before the certification body arrives.
Both, in that order. First certification. The internal audit runs first because clause 9.2 requires it and because a certification body will look for it. The readiness audit runs afterwards, close to the booked date, and one of the things it tests is whether the internal audit itself would survive scrutiny, which is the part organisations rarely check.
Neither yet. Nothing is built. Start with a readiness assessment, which is a third thing again.
On sequencing, which is where the money leaks
The expensive mistake is running the readiness audit first because it feels more urgent, finding gaps, remediating them, then running the internal audit against a system that has just changed. The internal audit then examines a configuration nobody has operated yet, which produces an audit with no findings, which is the pattern that draws attention at Stage 2.
Internal audit first, remediate, let it run, then rehearse. It reads slower and it is not.
What each costs
Goldline publishes both on the pricing page, along with what moves the number. The ISO 42001 internal audit and the pre-certification readiness audit each have their own page setting out scope and what is delivered.
The relevant commercial point is not the difference between the two figures. It is that a failed Stage 2 carries re-audit fees from the certification body and a delay measured in months, which is a larger number than either.
The rule Goldline applies to itself
Goldline does not conduct clause 9.2 internal audits of AI Management Systems it implemented, because an internal audit reporting on the implementer's own work is not an audit. The readiness audit is different, and Goldline will run one on a system it built, because advisory work does not carry the same requirement and the context genuinely helps. Both positions follow from the same distinction this article is about, and the reasoning is set out in full here.
Sources
- ISO/IEC 42001:2023, clause 9.2 internal audit, and clause 10. Not published free of charge and not quoted here.
- Published Goldline prices and durations, goldlineconsultancy.co.uk/pricing, read 1 September 2026.
- Certification body audit fees and re-audit fees are quoted per engagement and are not published by any UKAS-accredited certification body, so no figure is given for them here.
Alfred Obeng
Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.
Related reading
8 min read
Can the Consultancy That Built Your AIMS Also Audit It?
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.
- ISO 42001
- Internal Audit
- Certification
- AI Governance
12 min read
How to Choose an ISO 42001 Consultant in the UK
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Six things to check before you engage an ISO 42001 consultant, including the independence rule in ISO/IEC 42006 that decides who is allowed to audit what they built.
- ISO 42001
- AI Governance
- Procurement
6 min read
Readiness Assessment, Internal Audit, Certification Audit: Three Different Things
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.
- Certification
- Internal Audit
- ISO 27001
- ISO 42001
7 min read
What a Stage 2 Auditor Asks About Clause 9.2
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.
- Internal Audit
- ISO 42001
- Certification
- ISO 27001
6 min read
What ISO 19011 Requires of an Internal Auditor
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.
- Internal Audit
- ISO 42001
- ISO 27001
- Certification
10 min read
ISO 27001 Stage 1 vs Stage 2 audits: what to expect
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The difference between Stage 1 and Stage 2 certification audits, what auditors actually look for, common nonconformities, and how to avoid them.
- ISO 27001
- Audit
- Certification
