Skip to main content
Internal Audit

ISO 42001 Internal Audit versus Pre-Certification Readiness Audit

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

6 min read

Contents
    Internal Audit

    ISO 42001 Internal Audit versus Pre-Certification Readiness Audit

    By Alfred Obeng, Founder, Goldline Consultancy

    ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

    6 min read

    Contents

      These two are bought at roughly the same point, cost roughly the same, and are frequently assumed to be the same thing bought under two names. They are not, and the difference is not commercial. One discharges a clause of the standard. The other does not and cannot.

      Buying the wrong one does not usually surface until the certification body asks for the clause 9.2 evidence and receives a readiness report instead.

      The one-line difference

      The internal audit is an obligation. Clause 9.2 of ISO/IEC 42001 requires it, it recurs for as long as you hold the certificate, and it has to be objective.

      The pre-certification readiness audit is a rehearsal. Nothing requires it, it happens once before a booked certification audit, and it is advisory work rather than an audit of conformity.

      Set against each other

      ISO 42001 internal auditPre-certification readiness audit
      Why it existsRequired by clause 9.2Chosen, to reduce the risk of a failed Stage 2
      What it testsConformity of the AIMS against the standard and your own criteriaWhether you would pass, judged against Stage 1 and Stage 2 criteria
      IndependenceObjectivity and impartiality required by the clauseAdvisory, so no independence requirement attaches
      Can the implementer do itPossible but you carry the burden of proofYes, and often better, because context helps
      OutputAudit report, nonconformities, into clause 10 and the management reviewFindings with severity, and a remediation plan
      FrequencyPlanned intervals, continuing for the life of the certificateOnce, before a booked audit
      Counts for clause 9.2YesNo

      That last row is the one that costs money when it is got wrong.

      Why a readiness audit cannot substitute

      Because of what it is for. A readiness audit is designed to tell you what an auditor will find, so its value comes from being informed by the implementation. The person conducting it is trying to help you pass, and the more they know about how the system was built the more useful they are.

      A clause 9.2 internal audit is designed to tell your own management the truth about conformity, including where it is uncomfortable. Its value comes from the opposite property.

      Those two purposes pull in different directions, which is why one carries an independence requirement and the other does not. Running them as a single exercise gets you an audit that is either a poor rehearsal or a compromised internal audit, and usually the second.

      Which you need, and when

      Internal audit only. You are certified or close to it, the system has been operating, and the annual obligation is due. This is the recurring case and it is most organisations most years.

      Readiness audit only. You have a Stage 2 booked, the internal audit is already done and defensible, and what you want is a second reading before the certification body arrives.

      Both, in that order. First certification. The internal audit runs first because clause 9.2 requires it and because a certification body will look for it. The readiness audit runs afterwards, close to the booked date, and one of the things it tests is whether the internal audit itself would survive scrutiny, which is the part organisations rarely check.

      Neither yet. Nothing is built. Start with a readiness assessment, which is a third thing again.

      On sequencing, which is where the money leaks

      The expensive mistake is running the readiness audit first because it feels more urgent, finding gaps, remediating them, then running the internal audit against a system that has just changed. The internal audit then examines a configuration nobody has operated yet, which produces an audit with no findings, which is the pattern that draws attention at Stage 2.

      Internal audit first, remediate, let it run, then rehearse. It reads slower and it is not.

      What each costs

      Goldline publishes both on the pricing page, along with what moves the number. The ISO 42001 internal audit and the pre-certification readiness audit each have their own page setting out scope and what is delivered.

      The relevant commercial point is not the difference between the two figures. It is that a failed Stage 2 carries re-audit fees from the certification body and a delay measured in months, which is a larger number than either.

      The rule Goldline applies to itself

      Goldline does not conduct clause 9.2 internal audits of AI Management Systems it implemented, because an internal audit reporting on the implementer's own work is not an audit. The readiness audit is different, and Goldline will run one on a system it built, because advisory work does not carry the same requirement and the context genuinely helps. Both positions follow from the same distinction this article is about, and the reasoning is set out in full here.

      Sources

      • ISO/IEC 42001:2023, clause 9.2 internal audit, and clause 10. Not published free of charge and not quoted here.
      • Published Goldline prices and durations, goldlineconsultancy.co.uk/pricing, read 1 September 2026.
      • Certification body audit fees and re-audit fees are quoted per engagement and are not published by any UKAS-accredited certification body, so no figure is given for them here.

      Alfred Obeng

      Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

      Related reading

      ISO 42001

      8 min read

      Can the Consultancy That Built Your AIMS Also Audit It?

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.

      • ISO 42001
      • Internal Audit
      • Certification
      • AI Governance

      12 min read

      How to Choose an ISO 42001 Consultant in the UK

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Six things to check before you engage an ISO 42001 consultant, including the independence rule in ISO/IEC 42006 that decides who is allowed to audit what they built.

      • ISO 42001
      • AI Governance
      • Procurement
      Certification

      6 min read

      Readiness Assessment, Internal Audit, Certification Audit: Three Different Things

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.

      • Certification
      • Internal Audit
      • ISO 27001
      • ISO 42001
      ISO 42001

      7 min read

      What a Stage 2 Auditor Asks About Clause 9.2

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.

      • Internal Audit
      • ISO 42001
      • Certification
      • ISO 27001
      ISO 42001

      6 min read

      What ISO 19011 Requires of an Internal Auditor

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.

      • Internal Audit
      • ISO 42001
      • ISO 27001
      • Certification

      10 min read

      ISO 27001 Stage 1 vs Stage 2 audits: what to expect

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The difference between Stage 1 and Stage 2 certification audits, what auditors actually look for, common nonconformities, and how to avoid them.

      • ISO 27001
      • Audit
      • Certification

      Alfred Obeng

      Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

      Related reading

      ISO 42001

      8 min read

      Can the Consultancy That Built Your AIMS Also Audit It?

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.

      • ISO 42001
      • Internal Audit
      • Certification
      • AI Governance

      12 min read

      How to Choose an ISO 42001 Consultant in the UK

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Six things to check before you engage an ISO 42001 consultant, including the independence rule in ISO/IEC 42006 that decides who is allowed to audit what they built.

      • ISO 42001
      • AI Governance
      • Procurement
      Certification

      6 min read

      Readiness Assessment, Internal Audit, Certification Audit: Three Different Things

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.

      • Certification
      • Internal Audit
      • ISO 27001
      • ISO 42001
      ISO 42001

      7 min read

      What a Stage 2 Auditor Asks About Clause 9.2

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.

      • Internal Audit
      • ISO 42001
      • Certification
      • ISO 27001
      ISO 42001

      6 min read

      What ISO 19011 Requires of an Internal Auditor

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.

      • Internal Audit
      • ISO 42001
      • ISO 27001
      • Certification

      10 min read

      ISO 27001 Stage 1 vs Stage 2 audits: what to expect

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The difference between Stage 1 and Stage 2 certification audits, what auditors actually look for, common nonconformities, and how to avoid them.

      • ISO 27001
      • Audit
      • Certification

      We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.