ISO/IEC 42001 Internal Audit
Independent AIMS audit, with less audit stress.
An independent internal audit of your AI management system — testing your AI system inventory, risk and impact assessments, human oversight and accountability so responsible-AI governance holds up to scrutiny.
What you gain
Assurance your team can use.
Defensible findings
Conclusions linked to the criteria and evidence examined.
Clear priorities
Know what matters first and what can wait.
Less disruption
Evidence is reviewed before follow-up begins.
Minimum prerequisites
What needs to be in place.
The system does not need to be perfect, but there must be enough in place to audit.
Defined AIMS scope
A documented boundary identifying the organisational context, relevant AI systems and interested parties.
AI system inventory
A record of the AI systems and use cases in scope, including third-party and supplier AI you rely on.
AI risk and impact assessment
Documented AI risk and impact assessment records covering the systems and use cases in scope.
Statement of Applicability
A current record of applicable controls, implementation status and justified exclusions.
Operating evidence
Evidence that governance, oversight and monitoring controls operate in practice, not only policies describing intent.
Audit coverage
Built around your AI systems and their oversight.
The audit can cover clauses 4–10, applicable Annex A controls, AI governance and accountability, risk and impact processes, human oversight, third-party AI use and monitoring against specifically agreed organisational criteria.
Samples, demonstrations or focused interviews are used where documents do not establish how arrangements operate.
Typical evidence
- AIMS scope, organisational context and AI system inventory
- AI risk and impact assessment records
- Statement of Applicability and selected control evidence
- Human oversight and accountability arrangements
- Supplier and third-party AI governance records
- Monitoring, review and improvement records
Delivery
From scope to report in four steps.
The standard engagement is remote-first and uses a controlled evidence workspace.
Scope
Confirm criteria, boundaries, timetable, responsibilities and handling.
Collect
Complete the questionnaire and upload requested evidence once.
Clarify
Respond only to focused gaps, conflicts or verification requests.
Report
Receive professionally reviewed findings, limitations and priorities.
What this is
An independent AIMS audit.
- An internal audit against agreed ISO/IEC 42001 criteria
- Assessment of AIMS requirements, AI governance and applicable controls
- Document review, operating evidence, sampling and targeted verification
- A final report setting out findings and agreed priorities
It is not certification, not an automated document score and not implementation disguised as audit.
Good fit / Not a fit
Is an ISO/IEC 42001 internal audit right for you?
FAQ
ISO/IEC 42001 internal audit questions.
Common questions before you start the fit check.
Is this an audit or implementation support?
It is an independent internal audit. We assess your AI management system against the agreed criteria; we do not design or implement the AIMS or the AI systems being audited.
Can it be done remotely?
Yes. The standard engagement is remote-first and evidence-led, with targeted clarification, samples or demonstrations only where documents do not show how a control operates.
What evidence is needed?
Typically the AIMS scope, AI system inventory, AI risk and impact assessments, the Statement of Applicability, and evidence that governance, oversight and monitoring controls operate. Nothing is shared until after acceptance, through a secure workspace.
Do we need everything ready first?
The AIMS does not need to be perfect, but there must be enough in place to audit. Where the inventory, risk assessments or SoA are only partly in place, those areas are reported as gaps rather than conformance findings.
What happens after the fit check?
You submit a single Request engagement form with your result. If TRUSTYCYBER accepts the engagement, you receive confirmed scope, terms, a payment link and access to the evidence workspace.
Is this suitable before certification?
Yes. A pre-certification internal audit is framed to surface what would fail a certification audit, so you can close it first. Certification itself remains with an accredited body.
What happens if TRUSTYCYBER does not accept the engagement?
No evidence is requested and no payment is taken. Where part of your scope may still fit, or another provider is better placed, we say so.
A narrower, system-level check
Need system-level AI assurance verification?
ISO/IEC 42001 internal audit tests the AI management system. Some organisations also need to verify the assurance supporting a particular AI system, agent or AI-enabled workflow.
Learn about AI Assurance VerificationAI Assurance Verification tests
- Whether supporting evidence is current
- Whether evidence is scoped to the system actually in use
- Responsibility allocations across relevant parties
- Provider evidence, evaluation records and configuration exports
- Operational and agent access evidence, where applicable
Ready to test the fit for ISO/IEC 42001?
Tell us about your AI management system, scope and timing before sharing evidence.
