Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What evidence does ISO 42001 require for an audit?
Last verifiedISO 42001 auditors sample documented information and records showing the AIMS operates — not just policies. Map clauses and Annex A controls to artifacts and owners. Not legal advice.
Evidence requirements, last verified 10 September 2026 against ISO/IEC 42001:2023 documented-information clauses and Annex A/B. Mandatory vs recommended distinguished. Not legal advice.
Evidence-mapping table
| Clause / control | Artifact | Typical owner | Kind of text |
|---|---|---|---|
| Clause 5 — AI policy | Approved AI policy, communication record | Executive sponsor | Mandatory documented information |
| Clause 6 — SoA | Statement of Applicability with justifications | AIMS manager | Mandatory documented information |
| Annex A — impact assessment | AI system impact assessment reports | Risk / product owner | Mandatory if applicable |
| Annex A — lifecycle | Design reviews, test logs, deployment records | Engineering lead | Mandatory if applicable |
| Annex A — data | Data lineage, quality checks, provenance | Data governance lead | Mandatory if applicable |
| Clause 9 — internal audit | Audit programme, findings, follow-up | Internal audit / compliance | Mandatory documented information |
| Clause 9 — management review | Review minutes, decisions, actions | Executive team | Mandatory documented information |
| Clause 10 — CAPA | NC register, root-cause analysis, closure proof | AIMS manager | Mandatory documented information |
Mandatory documented information vs recommended records
- Mandatory: clauses 4–10 specify documented information the standard requires — absence is a major NC risk.
- Recommended: Annex B guidance and ISO/IEC 42005 may suggest additional records that strengthen the audit story.
- Operation over time: auditors sample months of logs, tickets, and review cycles — a policy alone is insufficient.
What to do now
- Build an evidence register with owner, refresh cadence, and sample period per control.
- Link AI risk register entries to Annex A controls they support.
- Run a dry-run sample before Stage 2 — same depth the CB will use.
Checklist
- ☐ Every SoA control has at least one living artifact?
- ☐ Samples cover the surveillance period, not only audit week?
- ☐ CAPA and management review minutes are signed and dated?
Where this shows up in ShipReady Metrics
Control-mapped evidence collection, human evidence review, and met-verdict overlay produce timestamped compliance artifacts. The obligation map marks iso_42001 in-scope — that mark is not a certificate. The 24-framework crosswalk maps density honestly. Tooling supports audit prep; it does not replace the CB.