Last reviewed 7 August 2026 by Mahrukh Fatima. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”.
The short answer: anyone competent and independent can perform your ISO 42001 internal audit, your own trained staff, or an external party acting on your behalf. ISO/IEC 42001’s own definition of “audit” states that an internal audit “is conducted by the organisation itself, or by an external party on its behalf” (ISO Online Browsing Platform preview, term 3.18, Note 2, checked 07-08-2026). What the standard will not accept is an auditor who audits their own work, and what accreditation rules will not accept is your certification body doing it for you.
The honest market answer: this is a very small market. As of 07-08-2026, we found only four consultancies worldwide with a dedicated ISO 42001 internal-audit service page, three in Europe, one in the US, and only one in Ireland. Everyone else bundles internal audit inside broader implementation consultancy. We list the four dedicated providers below, describe what AIMS audit competence actually looks like, and untangle the three different things people mean when they say “AI audit”.
Our selection criteria (read these before the list)
Every entry on this list had to meet all of the following:
- Independence. The provider is not a certification body and does not certify the organisations it audits. This matters because it is a hard rule, not a preference: ISO/IEC 27006-1 clause 5.2.2 states that the certification body “shall not provide internal information security reviews of the client’s ISMS subject to certification” and “shall be independent from the body or bodies (including any individuals) which provide the internal ISMS audit” (quoted via European Accreditation’s published FAQ). European Accreditation confirmed in March 2025 that for management-system certification there is no two-year cooling-off workaround, the separation is permanent. The same conflict-of-interest logic applies across ISO management-system standards, ISO 42001 included. This rule applies to Atoro too: we can perform your internal audit, but we cannot then certify you, and no certification body can do both.
- A dedicated ISO 42001 internal-audit offer, a named service you can buy on its own, not an audit folded silently into an implementation package.
- AI-specific competence claims, the provider describes auditing AI artefacts (risk assessments, impact assessments, model and data governance), not just recycled ISO 27001 boilerplate.
- Honestly described. Everything below comes from the providers’ own published pages as of 07-08-2026. We differentiate factually and we do not disparage anyone.
The four dedicated ISO 42001 internal-audit providers (as of 07-08-2026)
Disclosure. This guide is published by Atoro, which is included in the comparison. We apply the stated criteria consistently, link to supporting evidence and identify claims we could not independently verify.
Atoro (Ireland, UK, Europe)
Atoro is the only provider on this list that holds ISO 42001 certification itself (as of 08-08-2026): certificate AIMS-AT-120224, issued by A-LIGN under its ANAB accreditation on 2 December 2024, which made Atoro the first consultancy in Europe certified against the standard. The certificate is published, and the team that passed that audit is the team that performs yours. In a market where most “AI audit” offers are adapted ISO 27001 checklists, that difference is the product: an auditor who operates a live, certified AI management system knows where impact assessments go thin, which Annex A controls get probed, and what Stage 2 sampling feels like from the receiving end.
The service is a dedicated ISO 42001 internal-audit offer, run continuously (“audit as you implement”) or as a standalone engagement, scoped across model inventory, AI risk and impact assessments, human oversight, and data and model governance. Audits run inside Drata, a combined ISO 27001 + ISO 42001 audit covers both systems in one pass, and a senior engineer in your time zone leads the work. Internal-audit engagements are kept independent from Atoro’s implementation teams, so the same firm can never mark its own homework. Pricing is fixed after scoping and published at atoro.io/pricing, which almost nobody else in this market does. Across security and compliance, Atoro has delivered more than 200 certifications. See Atoro’s ISO 42001 internal audit service.
- Best for: Scaling software and AI companies with enterprise customers, that want local presence and an engineer-led audit of a live AI management system rather than a checklist review.
URM Consulting (UK)
A UK consultancy with a dedicated ISO 42001 internal-audit page, positioned on a 20-year ISO track record and more than 400 supported certifications without a failed project (provider’s own claim). URM offers a flexible range from planning a full multi-year internal-audit programme through to conducting individual audits, and emphasises knowledge transfer so client teams build their own audit capability over time. Suits UK organisations that want an established, generalist ISO practice with a long delivery history.
Assent Risk Management (UK)
A UK risk-management consultancy with a dedicated ISO 42001 internal-audit page and the strongest published FAQ set we found on this topic, covering competence, impartiality and whether you can do the audit yourself. Assent runs risk-based programmes aiming to cover the whole system annually where possible and every clause within the three-year cycle, checked against ISO 19011 auditing guidance. It is also the only provider we found publishing indicative pricing: roughly £1,600 for a basic two-day remote audit (provider’s own figure, as of 07-08-2026).
Cycore (US, remote delivery)
A US security-compliance firm with dedicated ISO 42001 and ISO 27001 internal-audit pages, delivering remotely. Cycore quotes a two-to-three-week fixed-cost engagement, works inside GRC platforms such as Vanta, Drata, Secureframe and Thoropass, offers a combined 27001 + 42001 internal audit, and argues explicitly that traditional auditors fall short on AI systems (provider’s own positioning). Suits North American software companies already running their compliance programme in a GRC platform.
First, check you’re buying the right kind of “AI audit”
“AI audit” currently means at least three different things, and buyers regularly get sold the wrong one:
- Internal AIMS audit (clause 9.2), what this page is about. A mandatory, planned-interval audit of your AI management system, performed by you or for you, feeding your management review. Clause 9.2 of ISO 42001 mirrors clause 9.2 of ISO 27001, both are built on the same ISO Harmonized Structure, requiring audits at planned intervals, a defined audit programme, objective and impartial auditors, results reported to management, and documented evidence retained (see the full breakdown in our guide to ISO 42001 internal audit requirements).
- Certification audit, the Stage 1 / Stage 2 audit performed by an accredited certification body, which results in your certificate. This must be independent from whoever did your internal audit, per the ISO/IEC 27006-1 rule above.
- Algorithm audit, a technical examination of a specific model or AI system (bias, performance, explainability), often linked to EU AI Act conformity work. A different service, different skills, different deliverable.
A practitioner note on confusion levels: forum threads show buyers conflating all three, and one forum anecdote describes a company skipping its second-year internal audit after an AI chatbot told them it was optional, then hitting a major nonconformity at surveillance.
What competence actually looks like for an AIMS internal audit
No, your internal auditor does not legally need a Lead Auditor certificate. Nothing in ISO/IEC 42001 or ISO/IEC 27001 requires it; the operative requirement is competence, clause 7.2 requires the organisation to determine necessary competence, ensure people are competent “on the basis of appropriate education, training, or experience”, and retain documented evidence. ISO/IEC 27007 frames this as auditor competence guidance, not certification.
Because no AIMS-specific audit-guidance standard (an “ISO/IEC 27007 for AI”) has been published as of 07-08-2026, an AIMS internal audit falls back on ISO 19011 plus clause 9.2 itself. In practice, a competent AIMS internal audit should sample AI-specific artefacts, not just management-system paperwork:
- AI risk assessments and AI System Impact Assessments, performed, current, and actually informing decisions.
- AI system and model inventory, complete, with owners, purposes and lifecycle status.
- Annex A controls, the AI-specific control set, implemented and evidenced, not just mapped on paper.
- Data and model governance records, training-data provenance, model documentation, monitoring and human-oversight logs.
This is where the “AI audit” skill gap shows up: an auditor fluent in ISO 27001 clause mechanics but unfamiliar with AI artefacts will produce a technically compliant and practically useless audit. When vetting providers, ask what AI artefacts they sample and who on the audit team has AI/ML risk experience.
What happens if you skip the internal audit
Certification bodies treat a failure to fulfil a requirement of the standard as a major nonconformity. NQA’s published grading rules require responses within 30 days and objective evidence of correction for majors within 90 days, and state that “certification will not be issued, reissued or revised” until a major’s correction is accepted; an unresolved major at surveillance risks suspension. Practitioners describe a wholly absent internal-audit trail as a “near-automatic major nonconformity” at Stage 2. Skipping the internal audit also feeds directly into cost: skipping can mean paying for the audit twice, once now, once at surveillance remediation, see our breakdown of ISO 42001 certification cost.
One honest note on frequency: the standard says “planned intervals”, not “annually”. Practitioners report certification bodies giving contradictory guidance on how much must be audited each year, and certification practice has converged on at least one full internal-audit cycle per year as the safe default.
Frequently asked questions
1. Who can perform an ISO 42001 internal audit?
Anyone competent and independent of the work being audited, your own staff, or an external party acting on your behalf. ISO/IEC 42001’s definition of “audit” (term 3.18, Note 2, ISO OBP preview) explicitly contemplates an external party conducting the internal audit.
2. Is internal audit mandatory for ISO 42001 certification?
Yes. Internal audits at planned intervals are a normative requirement of the standard, and certification auditors sample your audit programme, reports and evidence as a matter of course.
3. Can we do our own ISO 42001 internal audit in-house?
Yes, if you have someone competent who did not build or operate the controls being audited. In the small software companies Atoro typically works with, that independence is often impossible in-house, which is why outsourcing is a recognised route.
4. Can our certification body perform our internal audit?
No. ISO/IEC 27006-1 clause 5.2.2 forbids a certification body from providing internal audits of systems it certifies, and European Accreditation confirmed in March 2025 there is no two-year cooling-off mitigation. The separation is permanent, and the same conflict-of-interest principle applies across ISO management-system standards.
5. How often do we need an ISO 42001 internal audit?
The standard says “at planned intervals”, there is no fixed annual mandate. In practice, certification bodies expect at least one full cycle per year, aligned to annual surveillance and the clause 9.3 management review, which requires audit results as an input.
6. Does an internal auditor need a certificate or formal qualification?
No certificate is required. The standard requires demonstrable competence (clause 7.2) and impartiality. For AIMS audits, that competence should extend to AI artefacts, risk and impact assessments, model inventories and Annex A controls.
7. What is the difference between an internal audit, a certification audit and an algorithm audit?
An internal audit (clause 9.2) checks your management system and feeds management review. A certification audit is performed by an accredited certification body and results in your certificate. An algorithm audit examines a specific model’s behaviour. The first two must be independent of each other; the third is a different service entirely.
8. How much does an outsourced ISO 42001 internal audit cost?
Published pricing is rare in this market as of 07-08-2026: the only indicative competitor figure on a dedicated page is Assent’s ~£1,600 for a basic two-day remote audit (provider’s own figure). Atoro prices internal audits as a fixed fee agreed after scoping, with published anchors at atoro.io/pricing, so you know the number before any agreement.