ISO 42001 CLAUSE 9.2
Your ISO 42001 AI management system needs an internal audit that is independent of whoever built it.
Clause 9.2 requires internal audits at planned intervals, conducted by auditors selected to ensure objectivity and impartiality of the audit process. If the people who wrote your AI management system also audit it, that requirement is not met, and it is one of the first things a certification body checks.
Loading the calendar
Open the booking pageCalendar not loading? Open Calendly directly
What happens
PHASE 01
Audit programme and scope
Which AI systems and which parts of the AI management system are being audited, against which clauses and Annex A controls, over what period, and why that programme is risk based.
- Audit programme
- Scope statement
- Audit plan
PHASE 02
Fieldwork
Interviews, document review and evidence sampling against the clauses and the ISO 42001 Annex A controls recorded in your Statement of Applicability.
- Interview notes
- Evidence samples
- Working papers
PHASE 03
Findings
Nonconformities, observations and opportunities for improvement, each written against the clause it fails and each with an owner.
- Nonconformity reports
- Findings register
- Owner and date per finding
PHASE 04
Report and management review input
A report your certification body will accept, and the input clause 9.3 requires for management review.
- Internal audit report
- Management review input
- Corrective action tracker
The impartiality rule, and why it is a feature
Goldline does not sell implementation and internal audit to the same organisation for the same scope. If Goldline built your AI management system, someone else audits it, and we will introduce an independent credentialled auditor or brief a competent person inside your own organisation. That restriction is written into the engagement. It is the reason the audit report holds up.
Who this is for
You built the AI management system yourself, or a platform built it, and clause 9.2 is now due.
Your certification body has asked for the internal audit report before Stage 1.
A previous internal audit was carried out by the people who wrote the policies.
Surveillance is due and the audit programme has not run this cycle.
Delivered by a PECB ISO 42001 Lead Auditor and ISO 42001 Lead Implementer, CISSP.
Running an information security management system alongside it? The ISO 27001 clause 9.2 internal audit follows the same structure.
Check your audit position, and size it
Five questions on how your last internal audit was run, then a sizing step that gives a starting figure for the number of AI systems in scope.
Result
Answer the questions and the result updates here as you go.
Three more questions and it gives you a starting figure for the audit and what the programme has to cover.
Book the internal audit scoping call
A free 45 minute diagnostic with the practitioner who would do the work. Bring your scope, your Statement of Applicability and the last audit programme if there is one.
45 minutes, video, with the practitioner who would do the work. No sales pitch.
