Services
ISO/IEC 42001 Internal Audit Service
Independent internal audit of the AIMS (ISO/IEC 42001 Clause 9.2) and of high-risk AI systems against the AI Act — rotational programme, impartial fieldwork, CAPA, and reports to management.
The service
Independent internal audit covering two layers: the AI management system under ISO/IEC 42001 Clause 9.2, and the high-risk AI systems themselves against EU AI Act obligations. We work to an agreed Audit Plan on a rotational basis and report to management — we are not the team that designed the controls we then audit.
Fieldwork can run in the AIMS internal-audit module (multi-stage engagement, impartiality record, CAPA spawn, hub sync) and, where needed, on the AI Audit Solution used for Act-level verification of high-risk systems.
What we audit
- Management system (Clause 9.2) — audit programme, impartiality, sampled processes across clauses 4–10 and Annex A, management-review inputs, and continual improvement.
- High-risk AI systems — verification mapped to AI Act articles, GDPR where personal data is in play, and harmonised standards including EN 18286, structured around three pillars: proportionality and foundational controls; rights, transparency, and oversight; governance, risk, security, and sustainability.
- Evidence and gaps — traceability from each audit task to the required document and objective evidence; real-time coverage and gap identification.
How an engagement runs
- Plan — agree scope, systems, impartiality, and the rotational programme with management.
- Fieldwork — four-stage AIMS audit workflow and/or Act-level tasks with auditor, reviewer, and approver roles; providers and suppliers can contribute technical description where needed.
- Findings and CAPA — nonconformities spawn corrective actions in the AIMS CAPA register; we track them to closure.
- Report — management report, audit findings, and, where in scope, Annex IV-oriented technical-documentation and audit-report packs for later conformity assessment.
Who uses it
- Internal auditors and quality managers who need AI-competent, independent resource
- Compliance, legal, and risk functions preparing for certification or authority scrutiny
- Organisations that already run AIMS or QMS as a Service and need Clause 9.2 independence
The audit platform is described in the AI Audit Solution brochure. AIMS Clause 9.2 sits inside AIMS as a Service.