ISO 42001 Internal Audit: What the Standard Requires

Target queries: “iso 42001 internal audit requirements” · “iso 42001 clause 9.2” · “who audits an AI management system” Last reviewed: 28 August 2026. This page is refreshed quarterly; the next scheduled review is November 2026. Volatile facts are date-stamped where they appear.

The direct answer: ISO/IEC 42001:2023 clause 9.2 requires your organisation to run internal audits of its AI management system (AIMS) at planned intervals, under a documented audit programme, with auditors who are objective, impartial and competent. The clause mirrors ISO 27001’s 9.2 almost word for word, both standards share the ISO Harmonized Structure, so the 9.2.1/9.2.2 skeleton is identical [Tier 1: ISO HS; ISO/IEC 42001 Introduction, ISO OBP]. What differs is the subject matter: the auditor must understand AI systems, your AI risk and impact assessments, and the Annex A controls for AI. That competence is scarce. For most 12–50 person software companies, the real constraint is auditor competence and independence, not the clause itself.

A note on sources: ISO/IEC 42001 is paywalled, ISO’s Online Browsing Platform (OBP) publishes only informative sections [Tier 1: ISO OBP, as of 07-08-2026]. Every clause-9.2 description below is therefore a paraphrase reconstructed from ISO’s Harmonized Structure template and certification-body guidance, verify against the purchased standard before relying on it contractually.

First, a disambiguation: “AI audit” means three different things

Buyers searching “who audits an AI management system” routinely land on the wrong answer because the phrase covers three distinct activities:

  1. Internal audit of an AIMS, the clause 9.2 requirement this page covers, conducted by the organisation itself or by an external party on its behalf (term 3.18, Note 2, ISO OBP [Tier 1]).
  2. Certification audit, the Stage 1/Stage 2 audit an accredited certification body (CB) performs to issue your certificate. The CB can never also be your internal auditor (see below).
  3. Algorithm or model audit, a technical assessment of one model’s behaviour (bias, robustness). Engineering work, not a management-system audit; it does not satisfy clause 9.2.

If a page does not say which of the three it means, treat its advice with caution.

What clause 9.2 actually requires

Clause 9.2 has two sub-clauses. The structure below follows ISO/IEC 27001:2022’s published text, which ISO/IEC 42001:2023 mirrors through the Harmonized Structure (XXX = “AI”) [Tier 1: ISO HS template; Tier 2: High Table, BD Emerson]. Paraphrase, verify against the purchased 42001 before publication or contractual use.

9.2.1 General

The organisation shall conduct internal audits at planned intervals to provide information on whether the AI management system:

  • conforms to the organisation’s own requirements for its AIMS, and to the requirements of ISO/IEC 42001 itself; and
  • is effectively implemented and maintained.

Two points buyers consistently miss:

  • “Planned intervals” is the only frequency rule. There is no fixed annual mandate [Tier 1/2: ISO HS; ISEOB Blue]. Certification practice has converged on at least one full cycle per year, driven by annual surveillance audits, but that is practice, not clause text.
  • Your own documented programme sets the bar. If your procedures say “annually”, skipping a year is a nonconformity against your own requirements. Practitioner sentiment illustrates the confusion: one buyer reports two CBs giving contradictory frequency guidance, with “no evidence in the standard to back up either of these claims” [Tier 3, practitioner sentiment, phrasing only, as of 07-08-2026].

9.2.2 Internal audit programme

The organisation shall plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, taking into account the importance of the processes concerned and the results of previous audits. For each audit it shall:

  • define the audit criteria and scope;
  • select auditors and conduct audits in a way that ensures objectivity and impartiality (in plain terms: the auditor must not audit their own work);
  • ensure results are reported to relevant management; and
  • retain documented information as evidence that the programme ran and what it found.

Enumeration caution (unresolved as of 07-08-2026): ISO/IEC 27001:2022’s published 9.2.2 a) reads “audit criteria and scope”, but secondary sources on ISO/IEC 42001 (e.g. BD Emerson) render it “audit objectives, criteria and scope”. This page follows the 27001 wording, verify the enumeration against the purchased ISO/IEC 42001:2023 before publication; if 42001 includes “objectives”, the FAQ and schema below need the extra noun.

Audit findings feed corrective action (clause 10.2) and management review (clause 9.3, which requires “results of audits” as an input) [Tier 1: ISO HS; Tier 2: ISEOB Blue].

What is different about auditing an AIMS versus an ISMS

The clause wording is the same; the audit content is not. Based on consultancy interpretation [Tier 2: BD Emerson, paraphrase of interpretation, not normative text], an AIMS internal audit should sample artefacts that do not exist in an ISMS:

  • AI system inventory, complete, current, correctly scoped?
  • AI risk assessments and AI System Impact Assessments (AISIA), performed, documented, revisited when systems change?
  • Model and data governance records, model cards, data inventories, training-data lineage, monitoring logs.
  • Change management for models, a retrain or a new foundation-model provider is a material change; does your AIMS catch and assess it?
  • Annex A controls for AI, the AI-specific control set the AIMS operates against.

This is why “our ISO 27001 internal auditor can cover it” is only half true. The audit mechanics transfer; the audit judgement does not, unless the auditor understands AI/ML risk. As of 07-08-2026, no published AIMS-audit-guidance standard equivalent to ISO/IEC 27007 exists, internal AIMS audits fall back to ISO 19011:2018 plus clause 9.2 itself [Tier 1: ISO OBP; unverified negative, recheck the ISO catalogue before publication].

Who can audit an AI management system?

The direct answer: anyone competent, objective and impartial, including your own staff, or an external party engaged on your behalf. No auditor certificate is required.

  • Outsourcing is explicitly contemplated by the standard. Term 3.18 “audit”, Note 2 to entry (verbatim from ISO’s free OBP preview): “An internal audit is conducted by the organisation (3.1) itself, or by an external party on its behalf.” [Tier 1: ISO OBP, as of 07-08-2026]
  • Competence, not certification, is the operative requirement. Clause 7.2 requires demonstrable competence through education, training or experience, with documented evidence [Tier 2: Advisera, clause 7.2 paraphrase, verify against the standard]. No Lead Auditor or Internal Auditor certificate is required by 27001 or 42001.
  • Your certification body can never be your internal auditor. ISO/IEC 27006-1 clause 5.2.2 forbids a CB from providing internal reviews of a client’s system, and European Accreditation confirmed in March 2025 there is no two-year cooling-off fix, the separation is permanent [Tier 1: European Accreditation FAQ]. ISO/IEC 42006:2025 imposes equivalent impartiality regimes on AIMS certification bodies [Tier 1: ISO OBP].
  • Whoever built the system should not audit it. One practitioner reports seeing “a certification body reject an entire internal audit report because the person who built the system also signed off on the audit” [Tier 3, anecdote, unverified, phrasing only]. The tier-1 rule behind the anecdote is 9.2.2’s objectivity-and-impartiality requirement.
  • One thing you cannot outsource: ownership. You can outsource 100% of the audit execution, but ownership of the audit programme and the AIMS stays with you [Tier 3, practitioner formulation, consistent with the standard’s intent].

The real constraint: auditor competence

Because the 42001 internal-audit market is young, the scarce resource is not budget but auditors who combine management-system audit craft with genuine AI/ML literacy. Certification bodies must already evidence AI expertise (machine learning, data analytics) in their auditors under ISO/IEC 42006:2025 [Tier 1: ISO OBP]; no equivalent gate exists for internal auditors, so vetting competence sits with you. Ask any candidate auditor, in-house or external, for: demonstrable ISO 19011-based audit experience; familiarity with AI risk and impact assessment methods; and examples of AIMS-specific findings, not recycled ISMS checklists.

One programme, two standards: integrating your 27001 and 42001 internal audits

The direct answer: because both standards share the Harmonized Structure, most clause-level requirements (context, leadership, planning, support, operation, performance evaluation, improvement) can be audited once against both standards in a single integrated programme, removing most of the duplicated effort (practitioner estimate, not a measured figure).

This is not theoretical. One practitioner describes an employer certified to ISO 9001, 27001 and 42001 running “a consolidated internal audit programme where many audits cover all three standards together where there is overlap… and the template references clauses from all three standards” [Tier 3, practitioner sentiment, phrasing only, as of 07-08-2026]; peers in the same thread endorse mapping common clauses “into a single master framework to avoid triple the work” [Tier 3].

Practical shape of a combined programme:

  1. Shared clauses (4–10): audit once, reference both standards in the working papers.
  2. Standard-specific content: audit the ISMS Annex A controls and the AIMS Annex A controls / AI impact assessments in dedicated sessions with the right competence in the room.
  3. One corrective-action and management-review pipeline for both sets of findings.

If you already hold ISO 27001 and are adding 42001, this is the cheapest credible route. Atoro’s ISO 42001 implementation service is built around exactly this integration, and Mahrukh’s ISO 42001 certification cost guide models the audit-effort saving in the budget.

What happens if you skip it

The direct answer: a wholly absent clause 9.2 programme is treated as a major nonconformity, and a major nonconformity blocks certification or renewal until corrected.

The grading mechanics are tier-1: NQA (a UKAS-accredited CB) defines a major nonconformity as “a failure to fulfil one of the requirements of the standard”, requires responses within 30 days and correction evidence within 90 days, and will not issue or renew certification until a major is resolved; failure risks suspension [Tier 1: NQA, as of 07-08-2026]. Practitioner sources characterise a missing internal audit as a “near-automatic” major [Tier 2: Bachao.ai, practitioner characterisation, stronger than the tier-1 rule; attributed accordingly], and “no arranged internal audits or management reviews” appears among the most common ISO 27001 nonconformities [Tier 2: Cyberday].

This is no longer a hypothetical error. One Reddit thread describes a company that “asked ChatGPT whether they needed an internal audit for second year or not. ChatGPT said no so they didn’t do it”, and hit a major nonconformity at surveillance [Tier 3, practitioner account, details unverified, as of 07-08-2026]. Buyers are asking AI assistants exactly this question; the answer above is the correct one.

A correction: ISO/IEC 42006:2025 is not about your internal audit

A growing source of confusion, as of 07-08-2026: ISO/IEC 42006:2025, published July 2025, sets requirements for bodies providing audit and certification of AI management systems, CB impartiality, certification-auditor competence, audit-time rules [Tier 1: ISO OBP]. It governs the certification bodies that audit you. It does not govern, guide or constrain your clause 9.2 internal audit, and it does not require your internal auditor to hold any particular credential. If a provider tells you “42006 says your internal audit must…”, ask which document they are actually reading.

An honest note on the evidence base

Buyer-side discussion of ISO 42001 internal audits is, as of 07-08-2026, near-nonexistent in public practitioner forums: a search of r/ISO42001 for “internal audit” returned only three threads, none of them buyer questions about clause 9.2 [Tier 3, research finding, R16c]. The ISO 27001 question cascade (“is it mandatory? can we do it ourselves? who can perform it?”) has not yet visibly replicated for 42001. This page is deliberately early to that query space; where buyer phrasing above comes from 27001 discussions, we have said so.

FAQs

1. Is an internal audit mandatory for ISO 42001 certification?

Yes. Clause 9.2.1 is a “shall” requirement: internal audits at planned intervals are mandatory, and certification bodies treat a wholly absent internal-audit programme as a major nonconformity that blocks certification [Tier 1: ISO HS; NQA].

2. What does ISO 42001 clause 9.2 require, in one paragraph?

A documented internal-audit programme (frequency, methods, responsibilities, planning, reporting); defined criteria and scope per audit. Auditors selected for objectivity and impartiality; results reported to relevant management; and documented evidence retained. All weighted by process importance and previous audit results. Paraphrase, verify against the purchased standard (the 9.2.2 a) enumeration, “criteria and scope” vs “objectives, criteria and scope”, is unresolved as of 07-08-2026; see the caution above).

3. Who can perform an ISO 42001 internal audit?

The organisation itself, or an external party on its behalf (term 3.18, Note 2, ISO OBP). The auditor must be competent, objective and impartial, and must not audit their own work. Your certification body is barred from performing it.

4. Can we outsource our ISO 42001 internal audit?

Yes, explicitly. The standard’s own definition of internal audit contemplates an external party conducting it on your behalf. What you cannot outsource is ownership of the audit programme and the AIMS itself.

5. Does the internal auditor need a Lead Auditor certificate?

No. Neither 27001 nor 42001 requires an auditor certificate; clause 7.2 requires demonstrable competence (education, training or experience) with documented evidence. For an AIMS audit, that competence should extend to AI/ML risk.

6. How often do we need to run an internal audit?

The standard says only “at planned intervals”, there is no fixed annual mandate. Certification practice has converged on at least one full cycle per year. This is so because surveillance audits sample internal-audit evidence annually; whatever interval you document, you must keep to it.

7. Can we combine our ISO 27001 and ISO 42001 internal audits?

Yes, and practitioners estimate it removes most of the duplicated effort. Both standards share the ISO Harmonized Structure. Sso shared clauses can be audited once against both, with dedicated sessions for ISMS-specific and AI-specific content. Integrated multi-standard internal-audit programmes are already in use by practitioners.

8. Does ISO/IEC 42006:2025 affect our internal audit?

No. ISO/IEC 42006:2025 sets requirements for the certification bodies that audit and certify AIMS, not for organisations’ internal audits. It is a common and growing confusion; the two documents regulate different parties.