ISO/IEC 42001 Internal Audit

Independent AIMS audit, with less audit stress.

An independent internal audit of your AI management system — testing your AI system inventory, risk and impact assessments, human oversight and accountability so responsible-AI governance holds up to scrutiny.

ISO/IEC 27001 Lead Auditor
ISO/IEC 42001 Lead Auditor
JASANZ Technical Expert & Assessor
ASD IRAP Assessor

What you gain

Assurance your team can use.

Defensible findings

Conclusions linked to the criteria and evidence examined.

Clear priorities

Know what matters first and what can wait.

Less disruption

Evidence is reviewed before follow-up begins.

Minimum prerequisites

What needs to be in place.

The system does not need to be perfect, but there must be enough in place to audit.

Defined AIMS scope

A documented boundary identifying the organisational context, relevant AI systems and interested parties.

AI system inventory

A record of the AI systems and use cases in scope, including third-party and supplier AI you rely on.

AI risk and impact assessment

Documented AI risk and impact assessment records covering the systems and use cases in scope.

Statement of Applicability

A current record of applicable controls, implementation status and justified exclusions.

Operating evidence

Evidence that governance, oversight and monitoring controls operate in practice, not only policies describing intent.

Audit coverage

Built around your AI systems and their oversight.

The audit can cover clauses 4–10, applicable Annex A controls, AI governance and accountability, risk and impact processes, human oversight, third-party AI use and monitoring against specifically agreed organisational criteria.

Remote-first does not mean document-only.

Samples, demonstrations or focused interviews are used where documents do not establish how arrangements operate.

Typical evidence

  • AIMS scope, organisational context and AI system inventory
  • AI risk and impact assessment records
  • Statement of Applicability and selected control evidence
  • Human oversight and accountability arrangements
  • Supplier and third-party AI governance records
  • Monitoring, review and improvement records

Delivery

From scope to report in four steps.

The standard engagement is remote-first and uses a controlled evidence workspace.

Scope

Confirm criteria, boundaries, timetable, responsibilities and handling.

Collect

Complete the questionnaire and upload requested evidence once.

Clarify

Respond only to focused gaps, conflicts or verification requests.

Report

Receive professionally reviewed findings, limitations and priorities.

What this is

An independent AIMS audit.

  • An internal audit against agreed ISO/IEC 42001 criteria
  • Assessment of AIMS requirements, AI governance and applicable controls
  • Document review, operating evidence, sampling and targeted verification
  • A final report setting out findings and agreed priorities
What it is not

It is not certification, not an automated document score and not implementation disguised as audit.

Good fit / Not a fit

Is an ISO/IEC 42001 internal audit right for you?

Good fit
Maturity
Your AIMS and AI governance are established or substantially established
What you want
Independent assurance over AI risk, impact and oversight controls
Evidence
AI risk, impact and oversight records are mostly digital
Delivery
A remote-first review suits the scope
Not a fit
Maturity
AI governance is not built yet
What you want
Help building the AIMS or fixing AI systems
Evidence
Physical site inspection is central to the work
Delivery
Classified handling must be agreed before any engagement

FAQ

ISO/IEC 42001 internal audit questions.

Common questions before you start the fit check.

Is this an audit or implementation support?

It is an independent internal audit. We assess your AI management system against the agreed criteria; we do not design or implement the AIMS or the AI systems being audited.

Can it be done remotely?

Yes. The standard engagement is remote-first and evidence-led, with targeted clarification, samples or demonstrations only where documents do not show how a control operates.

What evidence is needed?

Typically the AIMS scope, AI system inventory, AI risk and impact assessments, the Statement of Applicability, and evidence that governance, oversight and monitoring controls operate. Nothing is shared until after acceptance, through a secure workspace.

Do we need everything ready first?

The AIMS does not need to be perfect, but there must be enough in place to audit. Where the inventory, risk assessments or SoA are only partly in place, those areas are reported as gaps rather than conformance findings.

What happens after the fit check?

You submit a single Request engagement form with your result. If TRUSTYCYBER accepts the engagement, you receive confirmed scope, terms, a payment link and access to the evidence workspace.

Is this suitable before certification?

Yes. A pre-certification internal audit is framed to surface what would fail a certification audit, so you can close it first. Certification itself remains with an accredited body.

What happens if TRUSTYCYBER does not accept the engagement?

No evidence is requested and no payment is taken. Where part of your scope may still fit, or another provider is better placed, we say so.

A narrower, system-level check

Need system-level AI assurance verification?

ISO/IEC 42001 internal audit tests the AI management system. Some organisations also need to verify the assurance supporting a particular AI system, agent or AI-enabled workflow.

Learn about AI Assurance Verification

AI Assurance Verification tests

  • Whether supporting evidence is current
  • Whether evidence is scoped to the system actually in use
  • Responsibility allocations across relevant parties
  • Provider evidence, evaluation records and configuration exports
  • Operational and agent access evidence, where applicable

Ready to test the fit for ISO/IEC 42001?

Tell us about your AI management system, scope and timing before sharing evidence.

Check your fit →