Back to Insights
AI Governance

ISO 42001 Audit Process: What to Expect

Inside the ISO 42001 AI management system audit. Stage 1 vs Stage 2, evidence, common gaps, and how Saudi organisations get certified the first time.

By Al Rashdan
5 min read
#ISO 42001 certification#AI audit process#ISO 42001 certification cost#certification bodies Gulf#AI governance audit

ISO 42001 certification isn't a pass/fail exam, it's a structured process that, when approached correctly, should have no surprises. Here's what actually happens and how to prepare.

01

Choosing a Certification Body

Not all certification bodies are equal. Consider: Accreditation: Ensure the body is accredited by a recognized national accreditation body (e.g., UKAS, DAkkS, JAS-ANZ). AI expertise: ISO 42001 is new. Confirm auditors have AI/ML competence, not just generic ISO experience. Regional presence: Gulf-based auditors understand local context and reduce travel costs. Certification bodies active in Gulf:
  • BSI Group
  • Bureau Veritas
  • DNV
  • TÜV Rheinland
  • SGS
  • LRQA
Selection criteria:
1

Request auditor CVs and AI experience

2

Compare pricing (audit days, travel, surveillance)

3

Check client references

4

Understand certification timeline

5

Review audit methodology

02

The Certification Timeline

Contract signed → Stage 1 Audit → Gap remediation → Stage 2 Audit → Certification decision
     ↓                ↓                  ↓                ↓                   ↓
  Week 0           Week 4            Week 6-8         Week 10-12          Week 14
Stage 1

Audit: Documentation Review

1.

AIMS scope and boundaries

2.

AI Policy and objectives

3.

Risk assessment methodology and results

4.

Documentation completeness

5.

Resource allocation

6.

Internal audit and management review evidence

7.

All mandatory documentation exists

8.

Documents are version-controlled and approved

9.

Scope is clearly defined and appropriate

10.

Risk assessment covers all in-scope AI systems

11.

Evidence of management commitment

12.

Proceed to Stage 2 as planned

13.

Proceed with minor observations to address

14.

Delay Stage 2 for significant gaps (requires remediation)

Stage 2

Audit: On-Site Assessment

1.

Control implementation and effectiveness

2.

Staff competence and awareness

3.

Operational procedures in action

4.

Records and evidence of ongoing operation

5.

Corrective action effectiveness

6.

Continual improvement evidence

7.

**Interviews:** Technical staff, management, AI system users

8.

**Document review:** Policies, procedures, records, logs

9.

**Observation:** Processes in action, working environment

10.

**Sampling:** Selection of AI systems for detailed review

11.

Their role in AI governance

12.

Key policies and procedures

13.

Recent activities and decisions

14.

How to answer honestly without volunteering problems

15.

Walk me through how you assess bias in your models

16.

How do you document model changes?

17.

What triggers a model retraining?

18.

How do you ensure data quality?

19.

How do you prioritize AI investments?

20.

What AI risks concern you most?

21.

How is AI governance performance reported?

22.

What improvements have you made since implementation?

23.

How do you know when to escalate AI decisions?

24.

What training have you received?

25.

How do you report AI system issues?

26.

Have you encountered AI errors? How were they handled?

05

Audit Findings Classification

Major nonconformity: Failure that significantly impacts AIMS effectiveness
01

Example

No risk assessment conducted for high-risk AI system
02

Impact

Must be resolved before certification
03

Example

Training records missing for one team member
04

Impact

Must have corrective action plan; verification at surveillance
05

Example

Risk register could include more detail
06

Impact

No formal action required
07

Example

Consider automating monitoring reports
08

Impact

Discretionary

06

Corrective Action Requirements

For nonconformities, you must:
1

Acknowledge

Accept the finding

2

Root cause

Identify why it occurred

3

Correction

Fix the immediate issue

4

Corrective action

Prevent recurrence

5

Evidence

Prove actions were effective

07

Certification Decision

After Stage 2, the certification body reviews:
01

Audit report and findings

02

Evidence of corrective actions (for majors)

03

Auditor recommendation

04

Certification granted

05

Certification pending corrective actions

06

Certification denied (rare with proper preparation)

08

Post-Certification: Surveillance Audits

Certification isn't the end, it's the beginning of ongoing compliance. Surveillance schedule:
01

Year 1

Surveillance audit (partial scope)
02

Year 2

Surveillance audit (different areas)
03

Year 3

Recertification audit (full scope)
04

Changes since last audit

05

Corrective action verification

06

Sample of controls

07

Continual improvement evidence

09

Cost Breakdown

Cost Element

Stage 1 audit

Range (USD)

$3,000-8,000

Notes

1-2 days

Cost Element

Stage 2 audit

Range (USD)

$8,000-25,000

Notes

3-5 days

Cost Element

Travel expenses

Range (USD)

$2,000-5,000

Notes

If international auditors

Cost Element

Annual surveillance

Range (USD)

$4,000-10,000

Notes

Per year

Cost Element

Recertification (Year 3)

Range (USD)

$6,000-15,000

Notes

Full audit

Total 3-year cost: $25,000-75,000 (audit fees only)

Note: Consultancy, internal effort, and tool costs are additional.

10

Maintaining Certification

To avoid certification suspension or withdrawal:
1

Complete surveillance audits on schedule

2

Address nonconformities within timelines

3

Report significant changes to certification body

4

Maintain AIMS operation continuously

5

Prepare for recertification in year 3

11

References

  • ISO/IEC 42001 Certification Process
  • IAF Mandatory Document for Certification
  • BSI Group Certification Services

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Frequently asked questions

Find answers to common questions about our services

Share this article

Related Reading

More insights from the Allo Technologies practice

AI Governance

AI Governance ROI: Business Case for Executives

AI governance investments yield measurable returns through risk reduction, market access, and competitive advantage. Build your business case here.

Read more
AI Governance

AI Governance for Saudi Organizations: ISO 42001, SDAIA, and Responsible AI

A practical AI governance roadmap for Saudi boards and CIOs: ISO 42001 AIMS, SDAIA Ethics Principles, and Vision 2030 alignment.

Read more
AI Governance

AI Risk Assessment: Gulf-Specific Use Cases

AI risks vary by industry and region. Healthcare, finance, and smart cities in the Gulf face unique challenges requiring tailored assessment approaches.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%