ISO 42001 internal audit

Clause 9.2 makes internal audit a condition of ISO 42001 certification. BD Emerson audits your AI management system against clauses 4 through 10 and your Statement of Applicability, and writes findings the way certification bodies sample them.
Talk to an auditor
Definition

What is an ISO 42001 internal audit?

An ISO 42001 internal audit is the Clause 9.2 check that your AI management system conforms to ISO/IEC 42001:2023 and to your own requirements, and that it is effectively implemented and maintained. The standard makes it a condition of certification, it must be objective and impartial, and most AI teams have no one independent enough to run it. BD Emerson performs the internal audit as a standalone engagement: clauses 4 through 10, the Annex A controls selected in your Statement of Applicability, nonconformities classified major and minor, and corrective action verification, documented the way certification bodies sample it at Stage 2 and at every surveillance visit. The engagement is part of BD Emerson's internal audit services.

Services

What we audit

AI policy and governance
AI risk assessment
AI system impact assessments
AI lifecycle documentation
Annex A controls and third parties
Management review and corrective action

AI policy and governance

We test the AI policy against Clause 5.2, confirm roles and responsibilities are assigned and understood, and check that the Clause 4 context and scope still match how your organization actually uses AI. Competence and awareness records under Clause 7 are sampled for the people who build and operate AI systems.

AI risk assessment

Clause 6.1.2 requires a defined AI risk assessment method applied at planned intervals. We test whether the method exists, whether it was followed, whether results tie to your stated risk criteria, and whether treatment decisions trace to the controls selected in your Statement of Applicability.

AI system impact assessments

We verify each in-scope AI system has an impact assessment under Clause 6.1.4, and that it considers consequences for the individuals and societies the system touches, not only the business. Thin assessments that skip affected groups are among the most common findings we raise.

AI lifecycle documentation

We sample lifecycle records across Clause 8 operations: data provenance, model documentation, deployment approvals, and monitoring records. The test is whether the documented lifecycle matches what engineering actually did, system by system.

Annex A controls and third parties

Every control selected in your Statement of Applicability is tested against its Annex A control objective. Supplier and third-party AI controls are included: what you buy, embed, or fine-tune is tested with the same evidence standard as what you build.

Management review and corrective action

We audit management review inputs and outputs under Clause 9.3 and the corrective action loop under Clause 10: whether nonconformities get root causes, owners, and closure evidence. When you fix a finding, we verify the correction actually closed it.

Our approach

Our approach

01

Risk-based audit program

The audit program spans your certification cycle and weights the clauses and controls where AI risk actually sits. Criteria and scope are defined for each audit, and auditors are independent of the activity they test.

02

Timed to the certification cycle

Before certification, we complete the internal audit 6 to 10 weeks ahead of Stage 2 so corrective actions can close before the registrar arrives. After certification, we audit at least annually, covering every clause and applicable control before recertification.

03

Findings in the standard's language

Nonconformities cite the specific clause or Annex A control they fail, are classified major or minor, and carry the evidence we sampled. The report goes to top management and feeds the management review.

04

Evidence over assertion

Interviews orient the work; records decide it. We sample evidence from your environment and test what happened, not what the procedure says should happen.

contact us

Schedule an ISO 42001 internal audit

Tell us your Stage 2 date or your next surveillance window and the size of your Statement of Applicability. An auditor will come back with scope, timing, and a quote.

Our Advantage

Why BD Emerson for this audit

We know the standard in practice

Almost no firm audits AI management systems yet. BD Emerson works in ISO 42001 every week, so our auditors know what a conforming risk assessment, impact assessment, and lifecycle record look like, and what a certification body will question.

Independence you can evidence

Our audit practice is separate from BD Emerson's consulting and technology practices. If BD Emerson consultants implemented your AIMS, a different team performs the internal audit, and where independence cannot be preserved we decline the engagement. The same rule governs all of our audit services.

Not a certification body

BD Emerson does not issue ISO certificates. An accredited registrar performs Stage 1 and Stage 2, then surveillance and recertification, and samples internal audit evidence at each visit. Our reports are written to hold up under exactly that sampling.

How We Work

How the internal audit runs

Ten steps from audit program to verified closure, documented so the certification body can sample any of them:
Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

Does ISO 42001 require an internal audit?

Can the consultants who built our AIMS audit it?

Can the ISO 42001 internal audit be combined with ISO 27001?

How long does the internal audit take and what does it cost?

What does the certification body look for in internal audit evidence?

What happens if you find a major nonconformity?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners