
An ISO 42001 audit sounds intimidating until you know what it actually involves, and then it just sounds like a lot of preparation. For a small business owner who has never been through a certification audit of any kind, the word “audit” tends to conjure images of an inspector combing through every file in the building. The reality is more structured and more predictable than that. This post walks through what a real ISO/IEC 42001 audit actually looks like, in two distinct stages, what the auditor is genuinely checking for at each one, and what it means when something doesn’t pass the first time.
The audit happens in two separate stages, not one
ISO 42001 certification audits are always split into two stages, run by an accredited certification body, not by Lead Comply or any software vendor. The gap between them typically runs four to twelve weeks, which is meant to be used for closing gaps the first stage turns up, not for starting from scratch (source: Trustible’s guide to the ISO 42001 two-stage audit).
Stage 1: does the paperwork actually exist and hold together
Stage 1 is a documentation and readiness review. The auditor is confirming that the foundational pieces exist and are internally consistent, an AI policy and scope statement, a risk assessment methodology, a Statement of Applicability (the document that says which Annex A controls apply and why), and clearly defined roles. According to the same guidance, the gaps that actually show up most often at this stage aren’t missing policies, they’re incomplete AI use case inventories, inconsistent ownership records, and AI systems that were never logged in the first place.
Stage 2: does the business actually run what the paperwork describes
Stage 2 is where the auditor tests whether the business genuinely operates the system its documentation describes, not just whether the documentation reads well. This means staff interviews, watching how a process actually runs in practice, checking audit trails and timestamped records, reviewing completed AI risk and impact assessments, and looking at management review records to confirm leadership is actually engaging with the system, not just signing off on a template once a year.
What auditors are genuinely looking for at each stage
Across both stages, four things come up consistently:
- The AI system inventory. Every AI tool in use needs to be logged, including third-party AI services and AI features embedded inside other software, not just the obvious standalone tools.
- The risk assessment. A generic IT risk methodology copied across without addressing AI-specific risks, like bias in outputs or the ability to explain a decision, is one of the most common gaps auditors flag.
- Annex A control evidence. Whichever controls the Statement of Applicability says apply need actual evidence behind them, not just a policy statement claiming the control is in place.
- Management review records. Evidence that leadership actually reviews the AI management system periodically, not a single sign-off treated as a box-ticking exercise.
What a “nonconformity” actually means, and why it isn’t a failed audit
A nonconformity is simply a finding that something didn’t meet a requirement of the standard. It comes in two forms (source: Glocert’s guide to common ISO 42001 nonconformities):
- A minor nonconformity is a single observed lapse that doesn’t point to a systemic failure. A business can still be certified with minor findings, provided it commits to a genuine corrective action plan and can show evidence the fix actually worked.
- A major nonconformity is a complete absence of a required element, or something serious enough to raise real doubt about whether the AI management system works at all. Major findings need to be resolved before certification is granted.
For context, the same source notes that three to six minor findings is typical for a first-time ISO 42001 certification, given how new the standard is for most businesses. A handful of minor nonconformities on a first audit isn’t a red flag, it’s the normal outcome of implementing a genuinely new management system for the first time.
The bottom line
An ISO 42001 audit isn’t a single dramatic inspection, it’s a structured, two-stage process: first confirming the paperwork exists and holds together, then confirming the business actually does what that paperwork describes. Most first-time audits turn up a handful of minor findings, and that’s a normal, expected part of the process, not a sign of failure. The businesses that get through it smoothly are the ones that treat the inventory, the risk assessment, and the management review records as genuinely lived practices well before the auditor ever walks in.
Sources
Trustible — How ISO 42001 Certification Works: The Two-Stage Audit
Glocert — Common ISO 42001 Nonconformities & How to Fix Them