ISO 42001 internal audit with ISMS Copilot
Run the clause 9.2 internal audit of your AI management system and its Annex A controls.
AIMS clause 9.2 audit support
Build a clause 9.2 audit programme for the AI management system across clauses 4 to 10
Sample the Annex A AI controls and their Annex B implementation guidance
Review AI system impact assessments for completeness and rigour
Check the AI policy, objectives, and roles against documented practice
Draft nonconformities tied to specific ISO 42001 clauses and controls
Prepare audit records for the AIMS management review
Internal audit of an AI management system
ISO 42001 clause 9.2 requires internal audits of the AI management system at planned intervals against both the standard and your own AIMS requirements. ISMS Copilot helps you scope a programme that covers clauses 4 to 10 and samples the Annex A AI controls, using the Annex B implementation guidance to judge whether a control is genuinely operating. A distinctive ISO 42001 demand is the AI system impact assessment: the AI helps you review whether assessments cover affected individuals and societal effects, not just the organisation, and whether they were revisited as systems changed. It drafts nonconformities against specific clauses and controls. Your lead auditor still decides materiality and signs the AIMS audit conclusion.
Explore the ISO 42001 Toolkit →Why teams use it for ISO 42001 internal audits
- Annex A AI control sampling judged against Annex B guidance
- AI system impact assessments reviewed for individual and societal scope
- Clause 9.2 programme covering the full AIMS scope
Frequently Asked Questions
Does it audit the ISO 42001 Annex A controls?
Yes. ISMS Copilot helps you sample the Annex A AI controls and uses the Annex B implementation guidance to assess whether each sampled control is actually operating, not merely documented.
How does it handle AI system impact assessments?
It helps the auditor review whether impact assessments address effects on individuals and society, not only the organisation, and whether they were updated as AI systems evolved during the audit period.
Can it issue ISO 42001 certification?
No. ISMS Copilot prepares the clause 9.2 audit programme and working papers. A certification body issues certification; your internal auditor owns the audit conclusion.
Ready to streamline your compliance work?
Built for speed, accuracy, and audit-ready output.
