ASSURE
Both management systems, audited together.
ISO 27001 and ISO 42001 share the same clause structure. Auditing them as one engagement rather than two removes duplicated fieldwork, produces a single coherent report, and costs less than running them separately.
Scoped on the free 45 minute diagnostic
THE ENGAGEMENT
One management system underneath, so one audit.
Organisations holding both certifications usually run two internal audits, at different points in the year, often with different auditors. The result is two reports describing overlapping governance in different language, with findings that do not reconcile and a management review that has to translate between them. That is a consequence of how the services are sold rather than how the standards are built.
Both standards follow the Annex SL harmonised structure, so clauses 4 through 10 cover the same management system architecture. Context, leadership, planning, support, operation, performance evaluation, and improvement are audited once, because there is one management system underneath rather than two. Only the Annex A control sets genuinely differ, and those are tested separately against each Statement of Applicability.
The practical consequence is fewer interviews, one document review, one examination of management review, and one set of findings that shows where a single weakness affects both scopes rather than surfacing twice with no connection drawn between the two.
INDEPENDENCE
Where we audit, and where we do not.
Goldline does not conduct internal audits of management systems it implemented. An internal audit that reports on the implementer's own work is not an audit, and a certification body reviewing your clause 9.2 evidence will see that immediately. In a combined engagement the rule applies to both scopes: if we built either the ISMS or the AIMS, we do not audit it.
That constraint is a strength rather than a limitation. It is the reason a Goldline audit report carries weight with a certification body, and it is why the findings in it can be relied on by your board. Preparation remains available for our own implementation clients, because a Pre-Certification Readiness Audit is a rehearsal rather than an assurance opinion, and the same party should not do both.
THE CREDENTIAL REQUIREMENT
Why almost nobody offers this.
A combined audit requires Lead Auditor competence in both standards held by the same practitioner. Splitting the work between two auditors reintroduces the problem the combined audit exists to solve, because the shared clauses get examined twice by people who did not sit in each other's interviews.
ISO 27001 Lead Auditors are common. ISO 42001 Lead Auditors are not, because the standard was published in December 2023 and the certification pathway is recent. Practitioners holding both are rarer still.
Goldline holds Lead Implementer and Lead Auditor credentials for both ISO 27001 and ISO 42001. That is what makes a genuinely combined audit possible rather than two audits scheduled close together.
DELIVERABLES
What you receive.
Single audit plan covering both scopes, agreed in advance against your ISMS and AIMS boundaries
Shared clause fieldwork conducted once, covering clauses 4 through 10 across both management systems
ISO 27001 Annex A control testing against your Statement of Applicability
ISO 42001 Annex A control testing against your Statement of Applicability
One audit report addressing both scopes, written to certification body evidence standard and structured so each certification body sees what it needs
Single nonconformity log with severity ratings, root cause, and explicit marking of findings that affect both scopes
Corrective action recommendations sequenced across both systems
Evidence pack retained for both surveillance audits
FIT
Who this is for.
- You are certified to both ISO 27001 and ISO 42001.
- You are certified to one and implementing the other, so the audit covers the certified scope and provides a readiness view on the second.
- Your two internal audits currently run separately and produce findings that do not reconcile.
- You are approaching surveillance audits for both certifications within the same window.
This is not for organisations holding only one certification. Where there is a single management system to audit, the single standard internal audit is the right service and the cheaper one.
Nor is it for organisations whose management systems Goldline implemented. We will say so at scoping and recommend an alternative auditor.
WHAT COMES NEXT
Where organisations go from here.
Where only one certification is held, the single standard internal audit covers the clause 9.2 obligation on its own terms, and the combined engagement becomes the right instrument once the second certificate is in place.
ASSURE
ISO 27001 Internal Audit
Independent clause 9.2 internal audit of the ISMS against ISO 27001:2022, delivered by a PECB Lead Auditor.
Explore the ISO 27001 Internal AuditASSURE
ISO 42001 Internal Audit
Independent clause 9.2 internal audit of the AI Management System against ISO 42001, delivered by a PECB Lead Auditor.
Explore the ISO 42001 Internal AuditQUESTIONS
Common questions.
Two internal audits in the diary?
A 45 minute scoping call establishes both management system scopes, your surveillance dates, and the price. No sales pitch. Where independence rules out either scope, we will say so and recommend an alternative.
Prefer email? Write to info@goldlineconsultancy.co.uk.
