Why “connected” evidence matters more in AIMS audits than in most management systems ?
Auditors moving into ISO/IEC 42001 conformity work from a background in ISO 9001, ISO 27001, or ISO 14001 will recognise the underlying Plan-Do-Check-Act structure immediately: internal audit under clause 9.2, management review under clause 9.3, and nonconformity and corrective action under clause 10.2 follow the same High Level Structure shared across modern ISO management system standards (Audit Workshop, ISO 42001 Clause 10.2 guidance). What differs with an Artificial Intelligence Management System (AIMS) is the pace and opacity of the thing being governed. Models get retrained, data pipelines get updated, and third-party components get patched on cycles that can be far shorter than a typical annual audit programme, so evidence collected in isolation at a single point in time tends to go stale faster than it does in a conventional IT or quality management system. The practical implication for auditors is that findings need to be traceable across these three clauses as a connected chain, not treated as three separate compliance boxes to tick during a single visit.
Clause 9.2: internal audit sets the evidentiary baseline
Clause 9.2 requires the organisation to conduct internal audits at planned intervals to determine whether the AIMS conforms to the organisation’s own requirements and to the requirements of ISO/IEC 42001 itself, and whether it is effectively implemented and maintained (Drel, “Preparing for an ISO 42001 internal audit”). In practice this means an audit programme with defined scope, criteria, methods, responsibilities, and reporting lines, covering AI risks, controls, processes, records, role assignments, and prior corrective actions across the AIMS (BrightDefense, ISO 42001 Internal Audit Guide). One structural point that catches organisations off guard: the internal audit required by 9.2 cannot be performed by the certification body itself; it must be a genuinely internal (or independently contracted internal) function distinct from the external certification audit (Hael, “ISO 42001 Internal Audit Consultants”). As an AIMS auditor, your first evidence-gathering task is therefore to verify that this internal audit function actually exists, has been executed against a documented programme, and produced findings, before you even reach the management review stage, because clause 9.3 explicitly requires internal audit results as a review input.
For each internal audit finding, the connected trail you should expect to see includes: the audit criteria applied (which clause, which internal policy, which specific control), the objective evidence examined (not just an assertion that a control “exists”), the finding statement itself, and a reference forward to where that finding was subsequently reported into management review or logged as a nonconformity. A finding that terminates at “documented and closed” without a visible link to either of those two downstream processes is a red flag worth pursuing, because clause 9.2 evidence that never surfaces in management review inputs effectively defeats the purpose of the audit.
Clause 9.3: management review is where audit evidence becomes governance decision
Clause 9.3 splits into three parts that are worth separating cleanly when you are formulating findings. Clause 9.3.1 requires top management to review the AIMS at planned intervals to confirm it remains suitable, adequate, and effective. Clause 9.3.2 specifies the topics that review must consider. Clause 9.3.3 requires that the review produce documented results: decisions and actions related to continual improvement opportunities and to any need for changes to the AIMS, including resource needs (SecureAudit, “Management review AIMS: ISO 42001 clause 9.3 in practice”). Two errors show up repeatedly in practice and are worth checking for specifically. First, some organisations treat management review as a meeting that happened rather than a review that considered specific, enumerated inputs; the required inputs include prior action items, changes in internal and external context, AIMS performance data, and internal audit results, and all of these should be traceable in the review’s own record, not simply assumed to have been discussed (Watchdog Security, “ISO 42001 Clause 9.3 Management Review Requirements”; Zen AI Governance, “Management Review Inputs Your ISO 42001 Auditor Will…”). Second, review outputs are frequently recorded as vague sentiment (“AIMS performing well”) rather than as the specific decisions and resourced actions clause 9.3.3 actually requires. As an auditor, when you sample a management review record, trace at least one output decision forward to see whether it produced a tangible action, an assigned owner, and a completion date; if it stops at the meeting minutes, that is a legitimate basis for a finding.
Clause 10.2: corrective action closes the loop, if the evidence actually closes it
Clause 10.2 requires that when a nonconformity occurs, the organisation reacts to it, takes action to control and correct it, deals with the consequences, evaluates whether similar nonconformities exist or could occur elsewhere, determines root cause, and implements action needed, then reviews the effectiveness of any corrective action taken and updates risks and opportunities as necessary (ISO/IEC 42001:2023 clause 10.2 text, via WD Cert). The clause follows the same six-step logical sequence found across ISO 9001, ISO 14001, and ISO 45001: react, correct, investigate, fix, and verify that the fix actually worked (Audit Workshop, ISO 42001 Clause 10.2 guidance). The most commonly cited nonconformity in this clause across certification bodies is not the absence of a corrective action process on paper, but a failure to verify that a corrective action was actually effective, or a failure to document root cause analysis rigorously enough to distinguish a genuine root cause from a restatement of the symptom (GlobalCert International, “Common ISO 42001 Nonconformities”). Auditors should specifically ask to see the effectiveness verification step, ideally evidenced by a subsequent audit cycle or monitoring data showing the original nonconformity has not recurred, rather than accepting a closure record that simply states the corrective action was “implemented.”
Evidence triangulation: reading the three clauses as one narrative
The practical skill that separates a defensible AIMS audit from a superficial one is triangulation across these three clauses rather than sampling each in isolation. A well-run AIMS should let you trace a single thread: an internal audit finding under 9.2, feeding into a management review discussion and decision under 9.3, resulting in a logged nonconformity and corrective action under 10.2, with an effectiveness check that references back to the original finding. When you can walk that thread end to end for a sample of findings, you have strong assurance the system is operating as an integrated management system rather than three disconnected compliance activities performed to satisfy separate clause numbers. When the thread breaks, for example a management review references “several audit findings” without specificity, or a corrective action record has no visible link to the internal audit that originally surfaced the issue, that break is itself the finding, often more informative than any single control gap you might otherwise report.
Formulating concise, defensible findings
Findings should state the clause reference, the specific requirement not met, the objective evidence observed, and why that evidence fails to satisfy the requirement, in that order and without editorializing about severity in the finding statement itself (severity classification belongs in a separate field or a follow-up discussion, not baked into the finding’s factual description). Avoid finding language that describes a general impression (“AI risk management appears immature”) in favour of language tied to a specific clause and a specific piece of evidence (“Clause 9.3.2 input on internal audit results was not present in the management review record dated [date]; the meeting record referenced only budget items”). This discipline pays off doubly: it gives the auditee an unambiguous basis for corrective action, and it gives you, as the auditor, a defensible record if the finding is later challenged or if a subsequent surveillance audit needs to verify whether the same gap has recurred.
Verifying corrective action closure on the next audit cycle
Finally, remember that clause 10.2 conformity is only provable over time. A finding closed too quickly, without a follow-up audit cycle confirming the corrective action’s effectiveness, is not fully verified; it is simply not yet due for re-examination. Build your audit programme so that prior-cycle corrective actions are explicitly re-sampled at the next internal or surveillance audit, and treat the presence (or absence) of that re-sampling discipline as itself a signal of how mature the organisation’s AIMS governance really is.
