Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What evidence does ISO 42001 require for an audit?

Last verified

ISO 42001 auditors sample documented information and records showing the AIMS operates — not just policies. Map clauses and Annex A controls to artifacts and owners. Not legal advice.

Evidence requirements, last verified 10 September 2026 against ISO/IEC 42001:2023 documented-information clauses and Annex A/B. Mandatory vs recommended distinguished. Not legal advice.

Evidence-mapping table

Clause/control → artifact → owner (illustrative; tailor to YOUR SoA)
Clause / controlArtifactTypical ownerKind of text
Clause 5 — AI policyApproved AI policy, communication recordExecutive sponsorMandatory documented information
Clause 6 — SoAStatement of Applicability with justificationsAIMS managerMandatory documented information
Annex A — impact assessmentAI system impact assessment reportsRisk / product ownerMandatory if applicable
Annex A — lifecycleDesign reviews, test logs, deployment recordsEngineering leadMandatory if applicable
Annex A — dataData lineage, quality checks, provenanceData governance leadMandatory if applicable
Clause 9 — internal auditAudit programme, findings, follow-upInternal audit / complianceMandatory documented information
Clause 9 — management reviewReview minutes, decisions, actionsExecutive teamMandatory documented information
Clause 10 — CAPANC register, root-cause analysis, closure proofAIMS managerMandatory documented information

What to do now

  • Build an evidence register with owner, refresh cadence, and sample period per control.
  • Link AI risk register entries to Annex A controls they support.
  • Run a dry-run sample before Stage 2 — same depth the CB will use.

Checklist

  • ☐ Every SoA control has at least one living artifact?
  • ☐ Samples cover the surveillance period, not only audit week?
  • ☐ CAPA and management review minutes are signed and dated?

Where this shows up in ShipReady Metrics

Control-mapped evidence collection, human evidence review, and met-verdict overlay produce timestamped compliance artifacts. The obligation map marks iso_42001 in-scope — that mark is not a certificate. The 24-framework crosswalk maps density honestly. Tooling supports audit prep; it does not replace the CB.

Frequently asked questions