Skip to main content
Internal Audit

What a Stage 2 Auditor Asks About Clause 9.2

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

7 min read

Contents
    Internal Audit

    What a Stage 2 Auditor Asks About Clause 9.2

    By Alfred Obeng, Founder, Goldline Consultancy

    ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

    7 min read

    Contents

      I hold ISO 42001 and ISO 27001 Lead Auditor credentials, so this is written from the other side of the table rather than as a guess about what auditors do. What follows is not a claim about how every auditor behaves. It is what clause 9.2 requires an organisation to be able to evidence, and therefore what any competent auditor has to satisfy themselves about before they can pass it.

      The order matters, because each question only becomes answerable once the previous one has been.

      1. Does an audit programme exist, or only an audit?

      The clause asks for audits at planned intervals, which means a programme rather than an event. A single audit performed three weeks before Stage 2, covering everything once, is not a programme. It is a rehearsal that has been labelled as one.

      What satisfies this is a document that says what will be audited, when, and across what cycle, written before the audits happened rather than after.

      2. Why those intervals and that coverage?

      The programme has to reflect the importance of the processes concerned and the results of previous audits. That second half is the one most programmes cannot answer, because it requires last year's findings to have influenced this year's plan.

      An audit schedule that covers every clause equally, every year, regardless of where the problems were, is telling an auditor that the programme is administrative rather than risk based. For an AIMS this is sharper than for an ISMS, because the areas that carry the most risk, model change management, training data provenance, human oversight in practice, are usually the newest and the least settled.

      3. What were the audit criteria, precisely?

      "Audited against ISO 42001" is not criteria. It is a title.

      Criteria are the specific clauses, the specific Annex A controls, the specific policies and the specific procedures the auditor tested against, recorded per audit. Where criteria are vague, the findings cannot be traced back to anything, and an auditor cannot tell whether an area was examined and found sound or simply not examined.

      4. Who audited, and how was their objectivity established?

      Not "were they independent", which invites a yes. How was it established, and where is that recorded.

      This is where the audit programme most often thins out. The expected evidence is a record showing who conducted each audit, what their involvement was in the activity audited, and, where full independence was not achievable, what was done about it. A small organisation that records the constraint and the compensating measure is in a materially better position than one that says nothing, because silence reads as an absence of thought rather than an absence of options. The independence question is worth settling before it is asked.

      5. What did the audits find, and what happened next?

      Findings go to relevant management, and nonconformities enter the clause 10 process with correction, cause analysis and verification of effectiveness. The chain has to be complete and it has to be visible.

      The most common break is at the end. A nonconformity is raised, an action is recorded, the action is marked complete, and nothing verifies that it worked. Verification of effectiveness is a separate step and it is routinely skipped.

      6. Did the results reach the management review?

      Clause 9.3 takes internal audit results as an input. An auditor reading a management review that does not discuss the internal audit findings has found a break between two clauses, and it usually means the audit was performed for the certificate rather than for the business.

      7. Can you show the records rather than describe them?

      Documented information retained as evidence of the programme and its results is an explicit requirement. Plans, criteria, evidence examined, findings, reports, distribution, actions, verification. Described from memory, none of it counts.

      The three patterns that draw the most attention

      An audit that found nothing. A clause 9.2 programme that has never raised a nonconformity across a first certification cycle is describing the audit rather than the management system. It is not proof of a problem, and it will be examined more closely than one with findings in it.

      Audits clustered immediately before Stage 2. Intervals planned around the certification date rather than around the business are visible from the dates alone.

      Findings that are all about documents. Where every finding concerns version control, headers or approval dates, the audit examined the documentation and not the operation of the controls. For an AIMS this shows up as an audit that reviewed the AI policy and never asked to see a model change approved, a bias assessment completed, or a human oversight step actually taken.

      The useful way to prepare

      Read your own audit programme as though you did not write it, and at each of the seven questions above ask what you would hand over. Where the honest answer is that you would explain rather than produce something, that is the gap, and it is fixable in advance far more cheaply than it is on the day.

      A pre-certification readiness audit tests exactly this, among other things, and it is a different exercise from the internal audit itself.

      Sources

      • ISO/IEC 42001:2023 and ISO/IEC 27001:2022, clause 9.2 internal audit, clause 9.3 management review, clause 10 nonconformity and corrective action. These standards are not published free of charge and are not quoted here. Their requirements are characterised.
      • ISO 19011:2026, guidelines for auditing management systems, fourth edition, published 27 May 2026, which supersedes the withdrawn 2018 edition. ISO catalogue read 1 September 2026.
      • The practitioner judgements in this article, including the three patterns above, are the author's own from audit practice and are offered as observations rather than as findings about the population of auditors.

      Alfred Obeng

      Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

      Related reading

      ISO 42001

      8 min read

      Can the Consultancy That Built Your AIMS Also Audit It?

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.

      • ISO 42001
      • Internal Audit
      • Certification
      • AI Governance
      ISO 42001

      6 min read

      ISO 42001 Internal Audit versus Pre-Certification Readiness Audit

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Bought at the same point, priced similarly, and routinely assumed to be the same thing. One discharges clause 9.2. The other cannot, and the sequencing is where the money leaks.

      • Internal Audit
      • ISO 42001
      • Certification
      Certification

      6 min read

      Readiness Assessment, Internal Audit, Certification Audit: Three Different Things

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.

      • Certification
      • Internal Audit
      • ISO 27001
      • ISO 42001
      ISO 42001

      6 min read

      What ISO 19011 Requires of an Internal Auditor

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.

      • Internal Audit
      • ISO 42001
      • ISO 27001
      • Certification

      Alfred Obeng

      Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

      Related reading

      ISO 42001

      8 min read

      Can the Consultancy That Built Your AIMS Also Audit It?

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.

      • ISO 42001
      • Internal Audit
      • Certification
      • AI Governance
      ISO 42001

      6 min read

      ISO 42001 Internal Audit versus Pre-Certification Readiness Audit

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Bought at the same point, priced similarly, and routinely assumed to be the same thing. One discharges clause 9.2. The other cannot, and the sequencing is where the money leaks.

      • Internal Audit
      • ISO 42001
      • Certification
      Certification

      6 min read

      Readiness Assessment, Internal Audit, Certification Audit: Three Different Things

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.

      • Certification
      • Internal Audit
      • ISO 27001
      • ISO 42001
      ISO 42001

      6 min read

      What ISO 19011 Requires of an Internal Auditor

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.

      • Internal Audit
      • ISO 42001
      • ISO 27001
      • Certification

      We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.