ISO 42001 Internal Audit

ISO 42001 internal audit, run alongside your team as you implement.

Atoro gives AI-enabled companies an independent internal auditor for their AI management system, working with you while you build, so gaps surface and get fixed before the audit that certifies you against the standard the EU AI Act points to.

As the first consultancy in Europe certified to ISO 42001 ourselves, we audit AI management systems the way a certification body will, against how you actually build, train and deploy models.

Built for AI-enabled companies

ISO 42001 internal audit

Independent of your build

Engineer-led

Continuous or one-off

AI management system audit

42001
AUDIT

Independent reviewerAn auditor separate from whoever built your AIMS.

Audit as you implementContinuous review across the build, not a scramble at the end.

AI-specific scopeModel inventory, risk and impact assessments, human oversight, transparency.

Clause 9.2 satisfiedThe mandatory internal audit, done properly and documented.

AI Act awareTested against the obligations your AIMS exists to demonstrate.

What usually triggers the call

  • You’re implementing ISO 42001 and want to know your AIMS will pass certification.
  • The EU AI Act applies and you need to show your controls work.
  • A customer or investor is asking how your AI is governed, and a policy isn’t enough.
  • You need the mandatory internal audit, and it can’t be done by the people who built the system.
  • You’d rather find the gaps now than in front of a certification auditor or a regulator.

02 Recognition

You’re building AI governance. You need to know it will hold up.

Most AI-enabled companies come to us when AI governance has moved from principle to proof, and they want an independent check before it’s tested for real.

AI governance is new ground, and most teams are building the AIMS for the first time. An internal audit is the independent test of whether it actually meets the standard, and under a framework this young, having an experienced auditor check your work early is the difference between confidence and guesswork.

Atoro gives you that auditor, as the first consultancy in Europe certified to ISO 42001, backed by more than 200 compliance and security projects.

03 Proof

Engineering-led AI management system audit

Atoro combines compliance consultants, auditors, engineers, and security specialists with computer science backgrounds, and we were the first consultancy in Europe certified to ISO 42001.

We understand how AI governance works inside the companies building it: model development, training data, the MLOps pipeline, third-party and foundation models, human oversight, and the evidence each control needs. Our audit tests how you actually build and run AI, not a generic checklist.

We hold ISO 42001 ourselves, which means we have been audited against the exact standard we audit you against.

Certified. First. Independent.

ISO 42001 certifiedThe first consultancy in Europe to hold it.

ISO 27001 certifiedThe security foundation an AIMS builds on.

200+ projects deliveredAcross compliance, security, audit, and testing.

Independent by designAuditors separate from any implementation team.

04 System

What an ISO 42001 internal audit actually checks

An AI management system internal audit is an independent test of whether your AIMS meets ISO 42001 and whether the evidence would survive a certification auditor. Because the standard is new, here is exactly what we review.

AI system inventory

Is every AI system you build or use identified, with its purpose and risk classification?

AI risk and impact assessments

Are risks to people, rights and the business assessed and documented, with decision trails?

Human oversight

Are the controls for meaningful human oversight real and operating, not just stated?

Data and model governance

Are training data, model development and third-party models governed and evidenced?

Transparency and AIMS clauses

Are the management-system requirements met: management review, corrective action, and the Clause 9.2 internal audit itself?

Findings and remediation

A clear, prioritised list of what to fix, with time to fix it.

You get an auditor’s verdict on your AI governance before the audit that counts, not a folder of principles.

05 Plan

Two ways to run it

Most teams run the internal audit continuously, alongside the build. Some just need the mandatory audit done once. We do both.

Continuous

Audit as you implement

We review your AIMS across the implementation, so each area is tested as you complete it and problems surface with time to fix them. Under a framework as new as ISO 42001, this early independent check is where most of the value is.

One-off

Standalone internal audit

Already built your AIMS and just need the mandatory independent internal audit? We scope it, run it, and document it to satisfy Clause 9.2, by an auditor independent of whoever built the system.

Either way you get a dedicated lead, a clear schedule, action tracking, and Slack support.

What we need from your team

  • One accountable internal lead.
  • Access to your AI systems documentation and evidence.
  • Time with the product, data science and engineering owners we need to interview.
  • Timely decisions on the findings we raise.

Your team stays involved where it matters. Atoro runs the audit.

06 Price

Clear scope before you commit

An internal audit should not be open-ended.

Before we quote, we scope the work properly: company size, the number and risk of your AI systems, whether you want continuous or one-off, your certification timeline, and the maturity of what you’ve built so far.

Your proposal sets out exactly what is reviewed, who runs it, what your team provides, and how findings are delivered.

Included

Independent lead auditor

Separate from any implementation work.

Included

Technical review

Across models, data, pipelines, oversight, and evidence.

Included

AI risk and impact assessment review

Checked for defensibility before your certification body sees it.

Included

Findings report

With prioritised, practical remediation.

Continuous

Re-check of fixes

Before your certification audit, on continuous engagements.

No vague day-rate dependency. No conflict of interest. No surprises in the audit room.

07 People

The team that runs your audit

An AI management system audit needs more than a checklist. It needs independent judgement, real understanding of how models work, and the discipline to test evidence the way a certification auditor will.

AB

Ayna Boada McNamara

Head of Service Delivery

Ayna keeps the audit on track: clear schedule, useful sessions, and a team that always knows what is needed next.

Role in your project: keeping the audit organised, visible, and moving.

MF

Mahrukh Fatima

AI Governance Manager

Mahrukh leads the technical review, testing your AI governance the way a certification auditor will, across models, data, oversight, and evidence.

Role in your project: independent judgement on whether your AIMS will hold up.

Backed by Atoro’s wider team of compliance consultants, auditors, engineers, and security specialists.

08 FAQ

ISO 42001 internal audit FAQs

What is an ISO 42001 internal audit?

A mandatory requirement of the standard (Clause 9.2): an independent check that your AI management system meets ISO 42001 and operates as documented, carried out before your certification or surveillance audit by someone independent of the area being audited.

Why does AI governance need its own internal audit?

Because AI introduces risks a standard security audit doesn’t cover: model behaviour, training data, human oversight, and impact on people and rights. An ISO 42001 internal audit tests the controls built specifically for those risks.

Does this help with the EU AI Act?

Yes. The AI Act sets the legal obligations; ISO 42001 is how you demonstrate you’re meeting them. An internal audit confirms your AIMS, and the evidence behind it, would stand up when those obligations are tested. Our ISO 42001 and the EU AI Act guide covers the mapping.

What’s “audit as you implement”?

We run the internal audit continuously alongside your implementation, so each area is tested as you finish it and gaps surface with time to fix them. Under a framework this new, finding problems early matters more than ever.

We’ve already built our AIMS, can you just do the audit?

Yes. The standalone internal audit is scoped, run and documented to satisfy Clause 9.2, by an auditor independent of whoever built the system.

Are you independent, and who can perform it?

Our auditors are independent of any implementation team, including our own. If Atoro built your AIMS, a separate Atoro auditor runs the internal audit, the separation a certification body checks for.

How does this relate to our ISO 27001 internal audit?

ISO 42001 builds on the same management-system structure as ISO 27001, so if you hold both, we can run the ISO 27001 internal audit and this one together, testing the AI layer and the security foundation in one coordinated engagement.

What do we get at the end?

A findings report: what passed, what didn’t, and a prioritised, practical list of what to fix, in time to fix it.

What happens after the internal audit?

You move into certification knowing what an independent auditor already found. Atoro can also support the wider cycle through ISO 42001 implementation, TrustOps, and managed governance services.

09 Push

Request ISO 42001 internal audit pricing

Get a scoped view of what an ISO 42001 internal audit would look like for your company. Complete a short scope questionnaire, book a call, or both.

Then we’ll give you a practical path and a clear commercial model.

No generic sales deck. No vague “starting from” proposal. No conflict of interest.

We’ll review

Whether you want continuous or one-off

The AI systems in scope and their risk

Your certification timeline

The maturity of your AIMS so far

Your internal team capacity

Whether ISO 27001 internal audit is also in scope