Skip to main content

ISO 42001 CLAUSE 9.2

Your ISO 42001 AI management system needs an internal audit that is independent of whoever built it.

Clause 9.2 requires internal audits at planned intervals, conducted by auditors selected to ensure objectivity and impartiality of the audit process. If the people who wrote your AI management system also audit it, that requirement is not met, and it is one of the first things a certification body checks.

Book the Free DiagnosticSame-week availability

Loading the calendar

Open the booking page

Calendar not loading? Open Calendly directly

What happens

PHASE 01

Audit programme and scope

Which AI systems and which parts of the AI management system are being audited, against which clauses and Annex A controls, over what period, and why that programme is risk based.

  • Audit programme
  • Scope statement
  • Audit plan

PHASE 02

Fieldwork

Interviews, document review and evidence sampling against the clauses and the ISO 42001 Annex A controls recorded in your Statement of Applicability.

  • Interview notes
  • Evidence samples
  • Working papers

PHASE 03

Findings

Nonconformities, observations and opportunities for improvement, each written against the clause it fails and each with an owner.

  • Nonconformity reports
  • Findings register
  • Owner and date per finding

PHASE 04

Report and management review input

A report your certification body will accept, and the input clause 9.3 requires for management review.

  • Internal audit report
  • Management review input
  • Corrective action tracker

The impartiality rule, and why it is a feature

Goldline does not sell implementation and internal audit to the same organisation for the same scope. If Goldline built your AI management system, someone else audits it, and we will introduce an independent credentialled auditor or brief a competent person inside your own organisation. That restriction is written into the engagement. It is the reason the audit report holds up.

Who this is for

  • You built the AI management system yourself, or a platform built it, and clause 9.2 is now due.

  • Your certification body has asked for the internal audit report before Stage 1.

  • A previous internal audit was carried out by the people who wrote the policies.

  • Surveillance is due and the audit programme has not run this cycle.

Delivered by a PECB ISO 42001 Lead Auditor and ISO 42001 Lead Implementer, CISSP.

Running an information security management system alongside it? The ISO 27001 clause 9.2 internal audit follows the same structure.

Check your audit position, and size it

Five questions on how your last internal audit was run, then a sizing step that gives a starting figure for the number of AI systems in scope.

01

Who carried out your most recent internal audit of the AI management system?

02

Does a written audit programme cover the whole standard and the applicable ISO 42001 Annex A controls across the certification cycle?

03

Did the last audit produce a written report with findings classified and corrective actions dated?

04

When is your next certification body visit?

05

Was the AI management system implemented with outside help?

Result

Answer the questions and the result updates here as you go.

Three more questions and it gives you a starting figure for the audit and what the programme has to cover.

Book the internal audit scoping call

A free 45 minute diagnostic with the practitioner who would do the work. Bring your scope, your Statement of Applicability and the last audit programme if there is one.

45 minutes, video, with the practitioner who would do the work. No sales pitch.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.