ISO 42001 · 7 min read

What should be in place before an ISO 42001 certification audit?

Published 4 October 2026 · last updated 4 October 2026

By Acuity AI Advisory, owner and operator of AI Register Ireland.

Before an ISO 42001 certification audit, you need a defined AI management system and evidence that people actually use it. The preparation includes deciding its scope, assigning responsibility, assessing AI risks and impacts, and reviewing how the arrangements work. Buying a register or approving a policy is only part of that work.

If you are still deciding whether certification is worth the effort, start with Acuity’s advice on whether ISO 42001 certification is worth it for your business. This article addresses the next question: what would credible preparation look like?

Define what you want assessed

ISO/IEC 42001 covers an organisation’s AI management system. It can apply to organisations developing, supplying or using AI. The scope therefore needs to explain which parts of your business and which AI activities are included. ISO’s description of the standard is a useful starting point.

A supplier of an AI document service should be able to explain whether the scope includes product development, customer implementation and ongoing support. An organisation adopting third-party tools faces a different set of responsibilities. Both need to understand the dependencies they retain when a vendor supplies the model or infrastructure.

Our advice is to settle this boundary before commissioning large amounts of documentation. Ask whether the proposed scope corresponds to what a customer would reasonably think your certificate covers. A narrow scope may be appropriate, but your sales explanation must stay within it.

Make the responsibilities workable

NSAI’s preparation guidance includes leadership, responsibilities, policies, risk and impact assessments, and operating controls. Those arrangements need to fit the business you run.

For example, somebody may own the AI risk assessment while another person controls the product release. How does an unresolved risk affect the release decision? Who can approve an exception, and who can stop the service? These are practical questions to resolve before the audit, even if the same person holds several roles in a small company.

Staff also need enough knowledge to perform their assigned work. We would look for evidence of competence in the task, such as a reviewer recognising an unreliable answer and following the escalation process. Attendance at a general AI presentation gives a narrower picture.

Connect a decision to the evidence behind it

It helps to trace one real AI use from approval through operation. The illustration below is invented for this article. It shows the kind of connection to look for; it is not an audit checklist or a complete set of required records.

Illustration: an AI service that drafts catalogue descriptions
  1. 01 / Agreed use

    Draft descriptions from approved product information. A staff member approves publication.

  2. 02 / Identified concern

    The draft may invent a specification that the product does not meet.

  3. 03 / Operating evidence

    Retain the source, the reviewed draft and a record of material corrections for selected checks.

  4. 04 / Review decision

    If unsupported specifications recur, investigate the cause and reconsider the permitted use.

Original fictional illustration. No client records or measured results.

The useful evidence would explain what happened when a draft contained an unsupported claim. Was it caught before publication? Did the reviewer have access to the source? Did repeated errors lead to a change? A policy promising human review cannot answer those questions by itself.

An AI register can connect the use, its owner and review date to the relevant records. Some evidence may remain in your existing ticketing, document or development systems. Reliable references and appropriate access can be more useful than copying everything into a new tool. See our ISO 42001 reference guide for the register’s supporting role.

Use internal review to find what needs fixing

The management system includes internal audit and management review. Internal audit should examine whether the arrangements meet the applicable requirements and work as intended, with appropriate objectivity. Management review gives leadership a basis for decisions about the system and its improvement.

Keep the findings and resulting decisions understandable. If a review identifies a weak approval process, a revised policy alone may leave the underlying problem untouched. Record what changed, who owns the action and how you checked the change was effective.

Our practical recommendation is to allow time for that learning before the certification assessment. Do not manufacture a spotless history. Genuine findings, followed by considered action, give a clearer account of how the organisation manages problems.

Know what Stage 1 and Stage 2 are for

NSAI describes Stage 1 as a readiness assessment covering documentation, scope, management commitment and initial control design. Stage 2 evaluates implementation, effectiveness and conformity. Agree the detailed evidence expectations and timing with your chosen certification body.

There is no useful universal promise that every company can prepare in a fixed number of weeks. Existing management practices, the proposed scope and unresolved gaps all affect the work. Certification also involves continuing assessment: NSAI describes surveillance, typically annually, and recertification every three years.

Buying software does not certify your organisation. Acuity’s advice does not issue a certificate either. The certification body makes that decision independently. For accredited certification, check that the body’s accreditation covers ISO/IEC 42001 and the relevant scope.

Unsure whether your evidence is strong enough?

Acuity can help you examine the proposed scope and the evidence behind your current arrangements, then identify the work that would make preparation worthwhile. That conversation may conclude that you should prepare gradually or defer certification.

Acuity’s advice is led by Ger Perdisatt, who holds an ISO/IEC 42001 Lead Auditor qualification. Read about Ger’s background.

Sources and scope

Sources checked on 4 October 2026: ISO’s standard overview; NSAI’s ISO 42001 preparation and certification process; and BSI’s implementation presentation for the management-system structure, including internal audit and management review.

This is an original explanation and practical editorial advice, not a reproduction of the standard or a complete conformity assessment. Use a licensed copy of the applicable standard for the full requirements. The fictional example contains no client material. Implementation resources and training packs are supplied privately under an agreed commercial engagement.