The chain the auditor pulls
ISO 42001 audits walk a consistent spine: pick a system from your AI inventory, follow it to its risk and impact assessments, to the Annex A controls your SoA says address them, to evidence those controls operate (evaluation results before deployment, oversight decisions with names and dates, monitoring output, event logs), and finally to an incident or a change and how the system responded. Before the audit, run that trace yourself on your two highest-stakes systems and your last model swap; every break you repair is a finding removed.
The evidence set to have ready
- Complete AI inventory with owners and your role per system, including embedded vendor AI and internal tools. Incomplete inventories are the most common Stage 1 finding in the young standard's history.
- Impact assessments with teeth: named harms, named affected parties, mapped controls, and at least the capacity to show a constrained or declined use. Principle-recital assessments fail interviews within minutes.
- Lifecycle evidence: pre-deployment evaluation results, versioning, documented oversight points and their actual use, drift and misuse monitoring, and event logging.
- Data management records: provenance, quality steps, and rights for the data behind in-scope systems.
- Supplier files for model providers: contracts with responsibilities, due diligence, and evidence you monitor provider changes that alter your systems' behavior.
- Internal audit and management review covering the AIMS, completed with findings tracked; both are mandatory before certification.
Stage 1 in a young standard
Use Stage 1 aggressively: with auditor experience of the standard still uneven across the market, the readiness review is where you and the audit team calibrate expectations about depth and evidence. Ask what they will sample at Stage 2, close every Stage 1 observation with evidence, and open Stage 2 by walking through those closures. In a standard this new, demonstrated responsiveness buys more credibility than polish.
The disqualifying mistake
Do not stage governance you do not run: freshly minted impact assessments with identical dates, oversight roles invented for audit week, monitoring dashboards nobody has logged into. AI-literate auditors read repository timestamps and access logs like everyone else reads calendars. Run the system for real, however lean; a small honest AIMS certifies, a large decorative one does not, and the buyers driving this market can tell the difference from the audit report either way.