DoAIRight
ISO/IEC 42001

ISO 42001 Certification Process: Stage 1 & Stage 2 Audits

PUBLISHED 05 AUG 2026

Achieving ISO/IEC 42001 certification requires a formal, two-stage audit process conducted by an accredited independent certification body operating under the ISO/IEC 42006 framework. In Stage 1, human auditors review your documentation, system architecture, and organizational readiness to ensure your AI Management System (AIMS) meets foundational requirements. In Stage 2, auditors evaluate operational effectiveness by inspecting live AI workflows, assessing risk controls, and interviewing stakeholders. Passing both stages proves that your organization responsibly governs AI across its entire lifecycle.

Understanding the ISO 42001 Audit Framework

ISO/IEC 42001:2023 sets the international standard for managing artificial intelligence systems responsibly. However, software tools and internal assessments cannot grant official certification. Formal ISO 42001 certification is awarded exclusively by an accredited certification body after independent human auditors evaluate your organization.

The certification pathway is structured into two distinct audit phases—Stage 1 and Stage 2—designed to confirm that your AIMS is both comprehensively designed and actively operating in accordance with standard requirements.

Stage 1 Audit: Documentation and Readiness Review

The Stage 1 audit acts as a diagnostic check. The auditor's goal is to determine whether your framework design satisfies ISO/IEC 42001 requirements and if your organization is adequately prepared to proceed to the intensive Stage 2 evaluation.

During Stage 1, auditors focus on core structural and policy elements, including:

  • Context and Scope (Clause 4): Verifying that you have defined your organization’s role in the AI ecosystem (e.g., developer, provider, or user) and explicitly set the boundaries of your AIMS.
  • Leadership and Governance (Clause 5 & Annex A.2): Reviewing top management's commitment, accountability, and approved AI policies.
  • Planning and Impact Assessment Methodology (Clause 6 & Annex A.5): Checking if you have established mechanisms to identify AI risks and assess impacts on individuals, groups, and society.
  • Internal Assessments (Clause 9): Confirming that you have completed an internal audit (Clause 9.2) and a management review (Clause 9.3).

If the auditor finds significant gaps in your documentation or governance framework during Stage 1, they will highlight areas needing correction before scheduling Stage 2.

Stage 2 Audit: Operational Effectiveness and Control Execution

Where Stage 1 asks "Is the system properly designed?", Stage 2 asks "Is the system working in practice?" Stage 2 typically occurs several weeks or months after Stage 1, allowing time to address any preliminary findings.

During Stage 2, auditors evaluate whether your operational processes comply with Clause 8 (Operation) and implement relevant controls from Annex A. Auditors will inspect evidence and interview personnel across several key domains:

  • AI System Life Cycle (Annex A.6): Verifying responsible design, development, verification, validation, and deployment practices.
  • Data Governance for AI (Annex A.7): Ensuring data quality, bias mitigation, acquisition ethics, and data protection controls are actively maintained.
  • Resources and Third-Party Risk (Annex A.4 & Annex A.10): Auditing hardware, computing resources, AI talent management, and vendor oversight.
  • System Use and Transparency (Annex A.8 & Annex A.9): Confirming that disclosures, user documentation, and intended-use policies are strictly enforced.
  • Continuous Improvement (Clause 10): Reviewing incident handling, non-conformity records, and updates to risk assessments based on changing real-world conditions.

Following Stage 2, the auditor compiles a report detailing any non-conformities. Minor non-conformities require corrective action plans, while major non-conformities must be resolved before the certification body can issue the official ISO/IEC 42001 certificate.

Preparing for a Smooth Audit Process

Navigating Stage 1 and Stage 2 audits successfully requires rigorous preparation long before external auditors arrive. Organizations should systematically map their operational workflows, build comprehensive risk registries, and establish clear evidence trails across all AI systems.

Platforms like DoAIRight help organizations streamline this preparation. By utilizing DoAIRight's free readiness assessment tool, teams can identify compliance gaps, organize evidence across all ISO 42001 clauses and Annex A domains, and achieve full certification readiness before engaging an accredited auditor.

Frequently asked

How long does the ISO 42001 certification audit take?

The duration depends on your organization's size, complexity, and scope of AI deployment. Stage 1 usually lasts 1 to 3 days, while Stage 2 typically takes 3 to 10 days of active auditing.

Can DoAIRight issue my official ISO 42001 certificate?

No. Official certificates can only be granted by an accredited third-party certification body following human audits under ISO/IEC 42006. DoAIRight provides tools and assessments to help prepare your organization to become certification-ready.

What happens if auditors find non-conformities during Stage 2?

For minor non-conformities, you will be given a set period (usually 30–90 days) to submit a corrective action plan. Major non-conformities must be fully remediated and re-audited before certification can be granted.

How long should we wait between Stage 1 and Stage 2 audits?

Typically, organizations schedule Stage 2 between 1 and 3 months after Stage 1. This provides sufficient time to remediate any documentation or procedural gaps identified during the initial review.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score