A certification audit for ISO 42001 stands or falls on demonstrability. Not on good intentions, not on an impressive policy document, but on evidence that the AI management system actually works. We are regularly asked to run a readiness assessment shortly before an audit, and we keep seeing the same gaps. This article is a concrete checklist per phase: from scope to evidence, with the questions an auditor asks and the mistakes that make readiness fall apart.
What audit readiness really means
Audit readiness is not the same as having a complete management system. It means you can demonstrate, for every part of the standard, that you designed it, implemented it and that it works in practice. The difference is in that last word. An auditor tests the standard along three lines: do agreements exist (policy and procedures), have they been implemented (evidence of execution), and do they demonstrably work over a period. For an initial certification the emphasis is on the first two, but without any operational history you will not get there. An AIMS set up last week has proven nothing yet.
Phase 1: scope and context
The audit starts with the scope of the AI management system. The auditor wants to know which AI systems fall within scope and why that boundary is correct. The biggest mistake here is a scope that does not match reality. If the AI inventory names three systems but the marketing department uses a tool with lead scoring that appears nowhere, the credibility of the entire system collapses.
Make sure you have: a current AI inventory gathered more broadly than just from IT, a substantiated scope definition, and an analysis of context and stakeholders. Be honest about what AI is in the sense of the standard; hidden AI functionality in purchased software counts.
Phase 2: leadership, policy and roles
The auditor tests whether management genuinely owns the AIMS. Expect questions to leadership, not only to the compliance officer. Is there an AI policy that fits the organization and is not generic template text? Are roles, responsibilities and authorities assigned, including who is ultimately accountable for AI governance?
Make sure you have: an established and communicated AI policy, a roles and responsibilities matrix, and demonstrable management involvement (for example minutes in which AI governance was addressed). A classic finding: policy that has been established but that employees do not know. Sampling questions to people on the floor is a standard auditor technique.
Phase 3: risk assessment and impact assessment
This is the heart of the standard and immediately the place where readiness most often falls short. ISO 42001 requires an AI risk assessment and, linked to it, an assessment of the impact of AI systems on individuals and society. The auditor checks whether the method was applied consistently, whether risks are named concretely and whether appropriate measures are linked to them.
Make sure you have: a documented risk methodology, completed risk assessments per system, impact assessments for the systems that require them, and a clear link between identified risks and the chosen controls. The common mistake is a risk register full of vague risks that all land on medium, without scenarios and without traceable measures.
Phase 4: the statement of applicability and controls
Like ISO 27001, ISO 42001 works with an annex full of control objectives and controls, and with a statement of applicability in which you justify per control whether it applies and how it has been implemented. The auditor walks through this statement and asks for evidence on a sample.
Make sure you have: a complete statement of applicability with substantiated inclusions and exclusions, and for each implemented control evidence that it works. Exclusions are permitted but must be sound; striking out a control because you find it inconvenient is not a valid justification.
Phase 5: evidence and operational practice
This is where readiness separates from hope. The auditor does not ask whether you do something; they ask you to show that you do it. Think of: records of AI incidents and their handling, monitoring results of AI systems, log files, records of vendor assessments, evidence of human oversight where prescribed, and reports of the internal audit and the management review.
Make sure you have: an internal audit that touched the full scope and whose findings were followed up, at least one management review that covered the mandatory topics, and a file in which you can quickly show evidence per control. Without a completed internal audit and management review an organization is generally not certifiable; these are hard requirements from clause 9.
A parallel with technical assurance
Anyone who has commissioned a technical assessment before, such as a web application penetration test, recognizes the pattern. There too: the report is the beginning, not the end. A finding is only closed once you have implemented the remediation and a retest confirms the fix. ISO 42001 works the same way. You do not close an identified nonconformity with a promise, but with evidence that the root cause has been removed. This evidence-driven attitude is exactly what an auditor looks for in any domain, whether it concerns AI governance or a patched vulnerability.
Self-test: ten questions in the mirror
Before you call in a certification body, answer honestly: is the AI inventory complete and current? Does the scope match reality? Does management know its own role in the AIMS? Has a consistent risk methodology been applied? Have impact assessments been done where needed? Is the statement of applicability complete and substantiated? Can you show evidence per control within a few minutes? Is there at least one AI incident or monitoring case you can show? Is the internal audit completed and followed up? Has the management review taken place? Two noes mean postponing the audit is cheaper than aborting it.
Conclusion
Audit readiness for ISO 42001 is not about producing documents but about being able to demonstrate that the system is alive. The organizations that pass a certification audit smoothly have their inventory in order, have made their risks concrete, have substantiated their controls and, above all, have a file in which evidence is within reach. A readiness assessment beforehand, carried out by someone who reads the standard through an auditor's eyes, is usually the cheapest insurance against a failed audit.
Secure Audit carries out readiness assessments for ISO 42001 and guides organizations toward a certifiable AI management system. Contact us for a no-obligation conversation.
Frequently asked questions
What is the difference between audit readiness and being certified?+
Readiness means you are ready to enter the certification audit with confidence: all parts of the standard are implemented and backed by evidence. Certification is the result after an independent certification body has tested and approved it. Readiness is the preparation, certification the outcome.
Does the internal audit really have to be completed before the certification audit?+
Yes. Clause 9 of ISO 42001 requires an internal audit and a management review. Without a completed internal audit, followed-up findings and a conducted management review, an organization is generally not certifiable. These are not formalities but hard requirements.
How long must an AIMS have been running before it is certifiable?+
There is no legally prescribed minimum, but the system must have some operational history so there is evidence that controls actually work. In practice this usually means several months of operation, including at least one internal audit round and a management review.
What is the most common reason organizations turn out not to be ready?+
Lack of evidence. Policies and procedures exist, but there is no record demonstrating they are followed in practice. The risk assessment is often too vague and the link to concrete controls is missing.
Does a readiness assessment beforehand actually help?+
Yes, provided it is carried out by someone who reads the standard the way an auditor does. A readiness assessment finds the gaps while there is still time to close them, and avoids the cost and reputational damage of an aborted or failed certification audit.
Need help with compliance?
Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.
Explore Compliance ServicesAbout the author
Partner | IT Auditor