All insights
AI security & compliance5 min read

ISO 42001 internal audit and certification readiness

How to run ISO 42001 internal audit and management review under clauses 9 and 10, handle nonconformities, and prepare for Stage 1 and Stage 2 certification audits.

By FORTE/CYBERx AdvisoryReviewed by FORTE/CYBERx Advisory10 August 2026

What clauses 9 and 10 require

Clause 9 covers monitoring, measurement, analysis and evaluation, internal audit and management review. Clause 10 covers continual improvement and nonconformity and corrective action. Together they are the feedback loop that makes an AI management system a system rather than a snapshot.

Certification bodies weight these clauses heavily, because they reveal whether governance operates or merely exists. An organisation with modest controls and a working audit and review cycle is in better shape than one with elaborate documentation and no evidence of use.

Requirements for the bodies performing these audits are set out in ISO/IEC 42006, which is why certification bodies increasingly ask AI-specific competence questions rather than reusing an ISO 27001 script.

Deciding what to monitor and measure

Clause 9.1 requires the organisation to determine what needs monitoring and measuring, the methods, when it occurs and when results are evaluated. Choose metrics that would change a decision.

Useful measures for an AI management system: proportion of in-scope systems with a current impact assessment, time from AI change request to decision, number of systems operating without a named owner, human review coverage in the high-impact class, verification test pass rate by system, supplier model-change notices reviewed within the target window, and AI incidents by category with time to containment.

Record the method and the evaluation cadence alongside each measure. A metric with no stated method invites an auditor to test how the number was produced.

Running an internal audit that finds things

Clause 9.2 requires internal audits at planned intervals, conducted by auditors who are objective and impartial. In a small organisation impartiality usually means someone from outside the function being audited, or an external party — the person who built the AI governance programme cannot audit it.

Plan the programme by risk, not by clause order. Audit the highest-impact AI system end to end: read the impact assessment, check it matches the deployed configuration, sample the logs, interview the business owner, verify the human review actually occurs, and confirm the supplier obligations were checked.

Use ISO 19011 as the method reference. Sample real records rather than accepting descriptions of process, and write findings against evidence with the clause or control cited. An internal audit that finds nothing in a first-year AI management system is not reassuring; it is a finding about the audit.

Management review as a decision meeting

Clause 9.3 sets a mandated input list: status of actions from previous reviews, changes in internal and external issues, performance information including nonconformities, monitoring results, audit results, fulfilment of objectives, interested-party feedback, risk assessment status and opportunities for improvement.

Outputs must include decisions on improvement opportunities and any need to change the management system, including resources. Record the decisions, not just the discussion. "Noted" is not an output.

Fold the review into an existing executive or risk committee at a set cadence, with a standing paper. Half of the value is that the executive sees AI risk regularly enough to notice a trend.

Nonconformity and corrective action

Clause 10.2 requires the organisation to react to a nonconformity, evaluate the need to eliminate its cause, implement action, review effectiveness and retain evidence of both the nonconformity and the action taken.

The step organisations skip is cause analysis. "Impact assessment was missing" has a correction — write it — and a cause, which is usually that the deployment gate does not require it or that nobody owns the gate. Correct both, or the finding recurs at the next audit with the certification body watching.

Track effectiveness with a date. A corrective action closed the day it was implemented has not been shown to work.

Apply this to your organisation

Want this assessed against your environment?

Send us the specifics and a senior advisor will respond within one business day.

Native secure submission. Your details are never sold or shared.

What Stage 1 and Stage 2 audits actually test

Stage 1 is a readiness and design review. The auditor examines scope, the AI policy, the risk and impact assessment process, the Statement of Applicability, documented information and internal audit planning, and confirms the organisation is ready to be audited against operation. Common Stage 1 outcomes are scope ambiguity, a SoA with unjustified exclusions, and an internal audit programme that has not yet run.

Stage 2 tests operation. The auditor samples evidence over a period — typically at least two to three months of records — and traces individual AI systems from inventory through impact assessment, design documentation, verification, deployment approval, monitoring and review.

Expect interviews beyond the compliance team. Business owners, engineers and the executive sponsor will be asked what they do, and their answers must match the documented process.

Building the evidence pack before the auditor asks

Assemble an index that maps each clause and each applicable Annex A control to its evidence location. That single artefact shortens an audit more than any other preparation.

The pack should hold: scope statement and context, AI policy and approval record, role assignments, AI system inventory, risk criteria and register, impact assessments, Statement of Applicability, lifecycle artefacts per system, data provenance and quality records, supplier assessments, awareness and competence records, monitoring results, internal audit reports, management review minutes, nonconformity and corrective action records, and incident records.

Sanity-check consistency. The most damaging audit finding is not a missing document; it is two documents that disagree about which systems are in scope.

A realistic readiness timeline

For an organisation with an operating ISO 27001 management system, six to nine months to Stage 2 is realistic: two to three months to establish scope, risk and Annex A implementation, three months of operating evidence, then internal audit, management review and correction before the certification audit.

Without an existing management system, allow nine to twelve months, and expect the data provenance and lifecycle controls to consume most of the effort.

Do not book the Stage 2 audit until the internal audit has run and its findings are closed or credibly in progress. Certification bodies read an internal audit programme that ran the week before Stage 2 exactly as it appears.

After certification: keeping the loop running

Surveillance audits recur annually and recertification every three years, but the operational discipline is the internal one: audits on a planned interval, management review on cadence, corrective actions closed with evidence of effectiveness, and the inventory kept current as AI use expands.

Set the triggers that pull the system forward between cycles — a new AI system, a model or supplier change, an incident, or a change in regulatory expectation. A management system that only moves at audit time will be found out at the next one.

Sources and further reading

This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.

Related reading

Start a useful conversation

Talk to a senior advisor

Tell us the decision, constraint or opportunity. A senior operator responds within one business day.

Native secure submission. No embedded HubSpot branding.