What an ISO/IEC 42001 audit is looking for
The auditor seeks sufficient audit evidence to determine whether the AIMS is implemented and consistent with applicable requirements.
What the organisation says it does
Defined policies, procedures, criteria, responsibilities and controls.
What it actually does
Processes, decisions, reviews, assessments and approvals carried out.
What it can demonstrate
Records and evidence that verify those activities. Alignment across all three creates traceability; inconsistency reveals a gap.
The scope of the management system
The auditor needs to understand which processes, units, products, services, locations and AI systems are covered, external interfaces, and exclusions with their rationale.
Scope must reflect reality and align with the AI inventory, responsibilities and observed activities.
Context and interested parties
The AIMS should reflect strategy, activity, AI use, regulation, technology, suppliers, customers, workers, affected people and authorities.
A generic context matrix is not enough. Uses affecting people should appear consistently in context, risks, controls and interested-party analysis.
Leadership, policy and responsibilities
ISO/IEC 42001 requires leadership, resources, objectives, reporting, authority and clear roles and responsibilities.
Interviews help establish whether people understand the responsibilities assigned to them. A revealing question is: Which AI-related decision is yours to make?
AI-related risks and opportunities
The auditor may review the AI risk management method, criteria, participants, treatment, controls, residual risk, acceptance and monitoring.
Sampling may follow one chain: system → risk → assessment → control → owner → evidence → monitoring.
Objectives and planning
Objectives should align with policy, have owners and resources, be measurable where appropriate, and be monitored.
“Use AI responsibly” is an intention. “Assess every new AI system before use” produces auditable evidence.
Competence, training and awareness
The auditor may review roles, experience, training needs, records and awareness. The question is not merely whether someone attended a course, but whether their competence matches their responsibility.
Procurement, human oversight and internal audit require different competence.
Controls and operation
The audit tests whether controls over policies, roles, data, suppliers, development, acquisition, testing, oversight, monitoring, change and incidents are implemented.
Audits use sampling; the auditor does not review every system or record. A few perfect examples do not demonstrate systematic operation.
Inventory, documentation and traceability
The inventory can connect purpose, owner, provider, classification, risks, impact assessment, controls, evidence, reviews and incidents.
Following one system from owner to controls and records turns dispersed information into verifiable traceability.
What evidence an auditor actually looks for
Audit evidence may include approved policies, inventories, assessments, decisions, contracts, supplier reviews, tests, monitoring, incidents, corrective actions, training, minutes, internal audits and management review.
A file is not automatically sufficient evidence. The auditor considers authenticity, consistency, currency, traceability and relevance, alongside interviews and observation.

How an ISO 42001 audit works
Planning
Scope, criteria, areas, participants and agenda are defined.
Information review
The audit team understands the AIMS and prepares the work.
Interviews and sampling
People are interviewed and systems, records, risks and controls selected.
Verification
Defined arrangements are compared with implementation.
Findings and closing
Results and next steps are communicated.
Certification audits also follow certification-scheme and certification-body rules. ISO/IEC 42006:2025 sets additional requirements for bodies auditing and certifying AIMS against ISO/IEC 42001.
Internal audit and management review
Internal audit checks conformity, implementation, deviations and opportunities; it is not a superficial rehearsal for external audit.
Management review considers performance, changes, resources, risks, audit results, objectives and improvement. The two processes provide evidence of AIMS maturity before certification audit.
Nonconformities, observations and improvement
A nonconformity requires analysis of what happened, root cause, similar situations, correction, corrective action and effectiveness.
The objective is not to hide the issue under new paperwork. Observations and improvement opportunities may also be raised without constituting nonconformity. Continual improvement remains part of the system.
What an organisation should not expect from an auditor
An auditor should not design the AIMS they will audit or decide which risks the organisation accepts. Their role is to evaluate audit evidence against audit criteria.
An audit does not mean reviewing every line of code, validating every model, guaranteeing no incidents, replacing legal analysis or automatically certifying AI Act compliance. ISO 42001 and the AI Act remain distinct.
How to prepare without turning the audit into a paperwork exercise
The useful question is not “Which documents will they request?” but Can we demonstrate that the system works?
Review scope, inventory, responsibilities, risks, controls, objectives, competence, suppliers, incidents, evidence, internal audit, management review and corrective actions.
Then select one system and reconstruct who approved it, why, the risks assessed, controls, owners, evidence, changes and next review. This links AI governance, an applied AI use policy and the practical process for implementing ISO/IEC 42001.
An auditor is not looking for perfect documents: they are looking for a system that works
Impeccable policies can coexist with an immature AIMS; simple documentation can support excellent traceability.
The decisive question is: Can the organisation demonstrate that it governs AI in the way it has defined?
When processes, people and evidence tell a coherent story, the system begins to speak for itself.
References
- ISO/IEC 42001:2023 — Artificial intelligence management system.
- ISO/IEC 42006:2025 — Requirements for bodies providing audit and certification of artificial intelligence management systems.
- ISO 19011:2018 — Guidelines for auditing management systems.
- ISO/IEC 17021-1 — Requirements for bodies providing audit and certification of management systems.
- ISO/IEC 23894:2023 — Guidance on AI-related risk management.
Would your AIMS be ready for an audit?
Before thinking about certification, it is useful to understand whether scope, risks, controls, responsibilities and evidence are genuinely connected.
Start the diagnostic →
Céntrika’s diagnostic can help identify your starting point and the main governance gaps.
