Hael
Book a meeting
ISO/IEC 42001 · Internal audit

ISO 42001 - Internal Audit Consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Clause 9.2 requires an internal audit before certification and at planned intervals afterwards, in practice annually.
  • Your certification body cannot perform it. That is a structural rule, not a preference.
  • The auditor must be objective and impartial, which normally rules out anyone who built the system.
  • Most small and mid-sized organisations have nobody who qualifies, so it is usually outsourced.
  • Outsourced internal audits typically cost £4,000 to £12,000 per cycle and take one to two weeks.

What Clause 9.2 requires

ISO/IEC 42001 Clause 9.2 requires internal audits of the AI management system at planned intervals, to check that it conforms to your own requirements and to the standard, and that it is effectively implemented and maintained. In practice that means one before certification and one every year afterwards for as long as you hold the certificate.

The requirement is unusual among compliance obligations because the answer to "who can do this" is a rule rather than an opinion, and for most organisations that rule ends in a decision to bring someone in.

Who cannot do it

Your certification body. Under ISO/IEC 17021, the body that certifies you cannot provide internal audit services for the same management system. Asking is not worth the call.

The person who built the system. The standard requires the audit programme to ensure objectivity and impartiality. Someone auditing documentation they wrote themselves does not satisfy that in substance, and a surveillance auditor will notice.

Anyone with responsibility for the area being audited. A head of engineering auditing engineering controls has an obvious conflict, even where the intention is honest.

Who can

Anyone competent and independent. That can be an internal person from a different function, an internal audit team where one exists, or an external firm.

Competence matters as much as independence. The auditor needs to understand management system auditing, which is a specific discipline, and enough about AI to test whether the impact assessments and lifecycle controls are real rather than nominal.

In practice, the combination of independence and competence is why most organisations under a few hundred people outsource it. There is often exactly one person who understands the AI management system, and they built it.

What a good internal audit produces

OutputWhat it should contain
Audit planScope, criteria, method, and which clauses and controls are covered this cycle
Evidence recordWhat was sampled, from which period, and what it showed
FindingsNonconformities classified as major or minor, each written so it can be closed
ObservationsThings that conform now but will not survive the next change
Report to managementClear enough for the management review to make decisions from
Follow-upVerification that corrective actions were actually completed

A finding has to name the requirement, describe the evidence, and state why the evidence does not meet the requirement. Anything vaguer cannot be closed and will simply reappear.

The audit that finds nothing

An internal audit reporting no findings at all, in a first-year management system, is usually a signal rather than a result.

Management systems in their first year almost always have something: an impact assessment that was not repeated when a system changed, a control operating without a retained record, a supplier review that slipped, a document version nobody updated. Finding those is the point. Closing them before the certification body arrives is the value.

An audit designed to reassure produces a comfortable report and a surprise at Stage 2.

Cost and timing

ItemTypical range
Outsourced internal audit, small to mid-sized organisation£4,000 to £12,000 per cycle
Duration1 to 2 weeks including reporting
FrequencyBefore certification, then annually
Combined with ISO 27001 internal auditUsually cheaper than two separate audits

Where you hold both ISO 27001 and ISO 42001, running one integrated internal audit across both management systems is normally less expensive than commissioning two, and Annex D of ISO/IEC 42001 supports treating the systems together.

Why this is the part that recurs

Implementation happens once. Certification happens once, then recertification at year three. The internal audit happens every single year, for as long as the certificate is held, and the requirement does not soften as the system matures.

That makes it the most durable relationship in ISO 42001 work and the one worth choosing carefully. An auditor who knows your system from last year is faster and finds more, provided they remain independent of building it.

Our internal audit service covers this, and where we have implemented the system we use a separate practitioner for the audit so independence is real rather than asserted.

How it fits with management review

Clause 9.3 requires management review, and the internal audit results are one of its required inputs. The sequence matters: audit, then review, then certification audit.

Leadership has to actually consider the findings and record decisions. A management review that rubber-stamps a report is itself a finding, and it is one that certification bodies raise regularly. Our existing guide on internal audit and management review covers the mechanics in more detail.

What to do next

Answer one question: is there anyone in your organisation who understands the AI management system, has audit competence, and did not build it? If the answer is no, plan for an external audit rather than discovering the problem six weeks before Stage 1.

Our free readiness diagnostic gives a first view, and the ISO/IEC 42001 service page sets out how the annual cycle runs.

References

FAQ

Does ISO 42001 require an internal audit?

Yes. Clause 9.2 requires internal audits at planned intervals, which in practice means before certification and annually afterwards.

Can our certification body do our internal audit?

No. ISO/IEC 17021 prevents it, because the body cannot audit a system it also helped assure internally.

Can the person who built the system audit it?

Not while satisfying the objectivity and impartiality requirement in substance. A surveillance auditor will test this.

How much does an outsourced internal audit cost?

Typically £4,000 to £12,000 per cycle for a small to mid-sized organisation, taking one to two weeks.

Can we combine it with our ISO 27001 internal audit?

Yes, and it is usually cheaper. Annex D of ISO/IEC 42001 supports treating the management systems together.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We run ISO/IEC 42001 internal audits, including for organisations whose management system we did not build, and where we did build it we use a separate practitioner so independence is real. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO/IEC 42001, free.

Answer a short set of questions and see what ISO/IEC 42001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO/IEC 42001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO/IEC 42001.

Or speak to us about your deadline. Book a meeting.