Why Internal Audits Matter in an AI Management System
ISO 42001 is the international standard for AI Management Systems (AIMS). Published in 2023, it gives organisations a structured way to govern artificial intelligence responsibly. Like every modern ISO standard built on the harmonised structure, it includes a performance evaluation section in Clause 9. And sitting right at the centre of that section is Clause 9.2, which covers internal audit requirements.
On this page
If you are responsible for managing or auditing an AIMS, Clause 9.2 is not an optional extra. It is the mechanism through which your organisation checks whether the management system is actually working. An AI management system without a functioning internal audit programme is just a collection of documents. Internal audits are what turn those documents into evidence of genuine conformity and continual improvement.
This article walks through what Clause 9.2 of ISO 42001 requires, how it differs from similar clauses in other standards, what auditors look for when they examine your internal audit process, and the most common problems organisations run into when implementing it for the first time.
The Structure of Clause 9.2 in ISO 42001
ISO 42001 follows the harmonised structure, which means its Clause 9.2 shares the same basic architecture as Clause 9.2 in ISO 9001, ISO 14001, ISO 45001, and ISO 27001. If you have audited against any of those standards, the bones of the requirement will be familiar. But the AI context introduces some specific considerations that change how you apply the clause in practice.
Clause 9.2 is divided into two subclauses in ISO 42001, consistent with the structure introduced across the harmonised standards family.
Clause 9.2.1: General Requirements
This subclause requires the organisation to conduct internal audits at planned intervals to provide information on whether the AIMS conforms to the organisation's own requirements and the requirements of the standard, and whether it is effectively implemented and maintained.
There are several important words in that sentence. Planned intervals means you cannot audit reactively or randomly. You need a programme. Conforms to the organisation's own requirements means you audit against your own policies, procedures, and objectives, not just the standard. Effectively implemented and maintained means you are checking whether people are actually doing what the system says, not just whether the documents exist.
Clause 9.2.2: The Internal Audit Programme
This subclause deals with how the audit programme is planned, managed, and maintained. The organisation must plan, establish, implement, and maintain an audit programme. That programme must take into account the importance of the processes concerned, changes affecting the organisation, and the results of previous audits.
The programme must also define the audit criteria and scope for each audit, select auditors who ensure objectivity and impartiality, and ensure that results are reported to relevant management. Documented information must be retained as evidence of the programme and the audit results.
Exemplar Global Recognised Training ProviderRTP No. 310970What Makes ISO 42001 Clause 9.2 Different From Other Standards
The text of Clause 9.2 in ISO 42001 is largely consistent with other harmonised standards. The real differences emerge when you think about what you are auditing and what the AI context demands.
The Scope of What You Are Auditing
In a quality management system, internal audits typically cover processes like design, production, customer communication, and supplier management. In an AIMS, the audit scope extends to AI-specific elements that most auditors have not previously encountered. These include the AI risk assessment and treatment process, the AI impact assessment, the Statement of Applicability for AI controls, the data governance processes that feed AI systems, and the operational controls applied to specific AI systems in use.
This is not trivial. An internal auditor working in an AIMS needs to understand what an AI system actually does inside the organisation, what risks it poses, and whether the controls in Annex A of ISO 42001 have been applied appropriately. That requires a level of technical literacy that goes beyond what most quality or environmental auditors bring to the job.
The Role of the AI System Impact Assessment
ISO 42001 introduces the concept of an AI system impact assessment, which has no direct equivalent in ISO 9001 or ISO 14001. The impact assessment evaluates the potential effects of an AI system on individuals, communities, and broader society. It is a required operational control under Clause 8.4, and it must be repeated at planned intervals.
When you conduct an internal audit of an AIMS, you will need to check whether impact assessments have been completed for the AI systems in scope, whether they are current, and whether the outputs have been used to inform risk treatment decisions. This is a genuinely new audit territory, and it is one of the areas where organisations most commonly fall short in their first internal audits.
The AI Role Distinction
ISO 42001 distinguishes between organisations that develop AI systems, organisations that deploy AI systems developed by others, and organisations that do both. Your internal audit scope and criteria need to reflect which role your organisation plays. An organisation that is purely a deployer of third-party AI tools has a different set of controls to verify than an organisation that develops its own AI models. Auditors need to understand this distinction before they plan the audit.
Planning the Internal Audit Programme Under Clause 9.2.2
A well-structured audit programme is the foundation of an effective internal audit function. Here is what Clause 9.2.2 actually requires you to think through.
Risk-Based Scheduling
The clause requires the programme to take into account the importance of the processes concerned and the results of previous audits. In practice, this means your audit schedule should not treat every process equally. Higher-risk AI systems, processes with a history of nonconformities, and areas that have undergone significant change should be audited more frequently or with greater depth.
For example, if your organisation uses an AI-based decision-making tool in a high-stakes context such as recruitment screening, credit assessment, or medical triage, that system warrants more intensive audit attention than a low-risk AI tool used for internal scheduling. Your audit programme should reflect that difference explicitly.
Defining Audit Criteria and Scope
Every audit in the programme needs defined criteria and scope. Criteria are the benchmarks against which you audit. For an AIMS, these typically include the requirements of ISO 42001 itself, the organisation's AI policy, the AI risk treatment plan, the Statement of Applicability, and any relevant internal procedures. Scope defines the boundary of what is included in a particular audit, such as a specific AI system, a particular department, or a defined set of clauses.
Getting this right at the planning stage saves significant time during the audit itself. Auditors who arrive without clear criteria tend to wander, and audits without defined scope tend to either miss critical areas or consume far more time than planned.
Auditor Selection and Independence
Clause 9.2.2 requires that auditors are selected to ensure objectivity and impartiality. This means auditors must not audit their own work. In a small organisation where one person is responsible for both implementing and auditing the AIMS, this creates a genuine challenge. The most common solution is to use external auditors for at least part of the programme, or to cross-train staff so that different people can audit different parts of the system.
In the AI context, auditor selection is complicated by the need for technical competence. An auditor who does not understand how machine learning models work, what training data means, or how algorithmic bias arises will struggle to conduct a meaningful audit of an AI risk assessment. Organisations implementing ISO 42001 need to think carefully about whether their internal auditors have the right competence, and invest in training where gaps exist. This is one area where formal ISO 42001 auditor training pays for itself quickly.
Documented Information
The clause requires the organisation to retain documented information as evidence of the audit programme and the audit results. This is not just about keeping a record of findings. It includes the audit programme itself, individual audit plans, audit checklists or notes, audit reports, and records of any corrective actions raised. All of this needs to be maintained in a way that can be retrieved and presented to a certification auditor when the time comes.
What Certification Auditors Look for When They Examine Clause 9.2
When an external auditor reviews your internal audit process during a certification or surveillance audit, they are not just checking whether audits happened. They are looking at the quality and rigour of the entire audit programme. Here is what they typically examine.
Does the Programme Cover the Whole System?
The audit programme must cover all processes and requirements of the AIMS. A common finding is that organisations audit the easy parts of the system, such as document control and training records, but avoid the harder AI-specific elements like impact assessments, data governance, and Annex A controls. A certification auditor will look at your programme and check whether it is genuinely comprehensive.
Is the Schedule Being Followed?
It is not enough to have a programme on paper. The organisation must demonstrate that audits are being conducted as planned. If the schedule says quarterly audits but the records show audits happening once a year, that is a nonconformity. Auditors will look at the dates on audit reports and compare them against the programme.
Are Findings Being Actioned?
Clause 9.2 connects directly to Clause 10.2, which covers nonconformity and corrective action. A certification auditor will trace audit findings through to corrective action records to verify that issues identified in internal audits are being addressed. An internal audit programme that raises findings but never closes them is a red flag. It suggests the programme is being run as a compliance exercise rather than a genuine improvement mechanism.
Is There Evidence of Auditor Competence?
Auditors will look for evidence that the people conducting internal audits have the necessary competence. This typically means training records, qualifications, or documented experience. For ISO 42001, this is particularly important given the technical nature of AI governance. If your internal auditors have no documented training in AI management system auditing, that is likely to attract attention.
Common Nonconformities Against Clause 9.2 in ISO 42001
Based on what we see in practice, here are the most frequent problems organisations encounter when implementing Clause 9.2 for an AIMS.
- No defined audit programme: The organisation conducts audits but has no documented programme that sets out the schedule, scope, and criteria. Individual audits are planned ad hoc rather than as part of a structured programme.
- AI-specific elements excluded from scope: The audit programme covers general management system processes but does not include AI risk assessments, impact assessments, or Annex A controls. This leaves the most distinctive and highest-risk parts of the AIMS unaudited.
- Auditor independence not maintained: The person responsible for implementing the AIMS is also conducting the internal audits. There is no separation between the implementer and the auditor roles.
- Audit results not reported to management: Findings are documented but not formally reported to top management or the relevant process owners. The link between internal audit results and management review inputs is missing.
- Corrective actions not followed up: Nonconformities raised in internal audits are recorded but never verified as closed. The audit programme has no follow-up mechanism.
- Documented information incomplete: Audit reports exist but audit plans, checklists, and working notes are not retained. When a certification auditor asks for evidence of how the audit was conducted, there is nothing to show.
Practical Tips for Auditing Clause 9.2 Conformity
Whether you are conducting an internal audit of your own AIMS or reviewing another organisation's system, here are practical approaches that work in the field.
Start With the Programme Document
Ask to see the documented audit programme at the outset. Review it for coverage, frequency, and risk-based scheduling. Check whether it explicitly includes AI-specific processes. If the programme does not mention impact assessments, data governance, or Annex A controls, you have found a gap before you have even started looking at individual audits.
Sample Across the AI System Lifecycle
When you look at individual audit records, sample across different stages of the AI system lifecycle. Check whether audits have covered the planning and design stage, the operational use stage, and the monitoring and review stage. An audit programme that only looks at documentation and never examines how AI systems are actually being used in practice is not meeting the intent of the clause.
Trace a Finding End to End
Select one finding from a previous internal audit and trace it through the system. Look for the original audit report, the corrective action request, the root cause analysis, the corrective action taken, and the verification of effectiveness. If you cannot trace a finding from identification to closure, the corrective action process is not functioning as required.
Interview the Internal Auditors
Speak directly with the people who conduct internal audits. Ask them how they plan an audit, what criteria they use, and how they handle situations where they find a potential nonconformity. Their answers will tell you quickly whether the audit programme is being run with genuine rigour or whether it is a paper exercise. Ask specifically whether they have received any training in AI management system auditing and what that training covered.
For those looking to build their own competence in this area, becoming an ISO 42001 AI management system auditor requires a combination of auditing skills and AI governance knowledge that most professionals are still developing.
Exemplar Global Recognised Training ProviderRTP No. 310970Connecting Clause 9.2 to the Rest of the Management System
Internal audits do not exist in isolation. They feed into several other parts of the AIMS and the results should be visible throughout the system.
The outputs of internal audits are mandatory inputs to management review under Clause 9.3. If your management review records do not include a summary of internal audit results and trends, the management review is incomplete. Equally, audit findings that reveal systemic issues should be feeding into the risk assessment process, potentially triggering updates to the AI risk register or the impact assessment records.
The connection between Clause 9.2 and Clause 10.2 on corrective action is particularly important. Every nonconformity raised in an internal audit should trigger a corrective action process. The corrective action should include root cause analysis, not just a fix for the immediate problem. And the effectiveness of the corrective action should be verified, typically through a follow-up audit or review.
Understanding how these clauses connect is essential for anyone building or auditing an AIMS. If you want to see how similar requirements work across other standards, the ISMS internal audit requirements under Clause 9.2 of ISO 27001 follow the same structural logic and offer useful comparison points.
Building Internal Auditor Competence for ISO 42001
One of the most significant challenges for organisations implementing ISO 42001 is finding internal auditors who have both auditing skills and sufficient understanding of AI governance to conduct meaningful audits. These two skill sets rarely come packaged together.
Auditors who are experienced in ISO 9001 or ISO 14001 will find that their core auditing skills transfer well. The principles of planning, evidence gathering, interviewing, and reporting are the same regardless of which standard you are auditing against. What they will need to develop is familiarity with AI-specific concepts: what an AI impact assessment involves, how to evaluate data governance processes, what the Annex A controls in ISO 42001 are designed to achieve, and how to assess whether an organisation's AI risk assessment is genuinely rigorous.
Conversely, technology professionals who understand AI systems well often lack the audit methodology skills to conduct structured, evidence-based audits. They may be excellent at evaluating whether an AI model is technically sound but less confident at interviewing process owners, sampling records, or writing nonconformity reports that will stand up to scrutiny.
The most effective internal auditors for an AIMS are those who have invested in formal training that covers both dimensions. If you are looking to develop that capability, the ISO 42001 internal audit checklist is a practical starting point for understanding what evidence to gather across each clause of the standard.
Audit Workshop offers ISO 42001 training at Internal Auditor and Lead Auditor levels, designed specifically for practitioners who need to understand both the auditing methodology and the AI governance context. The training is built around real audit scenarios rather than theoretical frameworks, which means you leave with skills you can apply immediately rather than knowledge you need to figure out how to use.













