
Blog Post
Preparing for an ISO 42001 Audit Rather Than Reading About It
October 8, 2026
Plenty of material explains what ISO/IEC 42001 contains. Clause by clause, control by control, with a checklist of documents to prepare. The standard itself is a management system specification rather than a control catalogue, and the distinction is where audit preparation goes wrong.
The checklists share one omission. Some of the required evidence can be written next week and some cannot exist at all unless something already happened, and the second category sets the certification timeline rather than the writing effort.
What Order Does the Auditor Work In?
A deliberate sequence, because each artifact constrains the next.
Scope and context first, establishing the boundary of which systems are covered. Then the inventory and classification, listing systems with their intended purposes and risk positions. Then the core policies. Then the risk and impact assessments. Then the statement of applicability, showing which controls were selected and why. Operational records last.
Which Is Why Independent Preparation Fails
Scope determines the inventory population, the inventory determines what the risk assessment has to cover, the risk assessment determines which controls the statement of applicability should select, and that determines which operational records ought to exist. Documents prepared in parallel by different people produce a set that does not reconcile, and the auditor follows the chain precisely to find where.
What Separates the Two Stages?
Design against operation, and they ask for different kinds of thing.

The first stage reviews whether the framework, scope and policies are documented, and its output is a list of shortfalls, with severe ones preventing progress to the second stage. The second stage asks whether the organization operates the way the documents describe, requesting logs, version histories, oversight records and a walkthrough of a recent risk treatment.
Which Stage Can Be Prepared For?
The first, almost entirely. Policies, scope statements, process maps and role definitions are writing tasks with a deadline. The second stage asks for records of things that happened, and no amount of preparation creates a history.
Which Evidence Cannot Be Produced Retrospectively?
Anything that is a record of an event rather than a description of an intention.
- Management review records: A meeting either took place on a date with an agenda and attendees, or it did not.
- Internal audit records: An internal audit either happened, with findings and a scope, or it did not.
- Corrective action records: A finding raised, actioned and verified closed, with dates in that order.
Human oversight records complete the set, meaning the log of a person reviewing an output at the time they reviewed it. Each of these is a byproduct of operating a management system, and a record that holds more than the current state is what distinguishes one from a reconstruction.
What Sets the Timeline?
One completed cycle, which is the constraint most planning misses.

A management system standard expects the plan, do, check and act loop to have turned at least once. So an internal audit has to have been conducted and a management review held, and a management review that reviews nothing is not a management review. An organization deciding in January to certify cannot compress that into February.
What Shortens It Legitimately?
Discovering that parts of the cycle were already running under other names. Existing security reviews, change approvals and incident retrospectives frequently contain the substance of what the standard asks for, dated and attributable. Mapping what exists before writing anything new is the fastest available route.
Where Does Retrospective Writing Show?
In the statement of applicability, which is the document that reveals the order things were done in.
It has to record which controls were selected or excluded and why. Derived properly, the reasoning traces back to specific risks in the risk assessment. Written to match the controls an organization already had, it reads as a list of justifications rather than a set of conclusions, and an auditor comparing the two documents can see which came first.
What Does the Comparison Look For?
Risks in the assessment with no corresponding control, and controls in the statement with no corresponding risk. The second is the tell, since a control selected for no stated reason was selected because it was already there, which reusing evidence across frameworks makes tempting and visible.
What Is the Walkthrough Testing?
Whether a real instance exists, which is a different question from whether a process is documented.
Being asked to walk through a recent risk treatment means naming one, then showing identification, assessment, the decision and its reasoning, implementation and verification, with dates in sequence. An organization that has documented a treatment process and never treated a risk has nothing to walk.
Which One Should You Choose?
A completed one rather than an impressive one. A modest risk fully closed with dates in the right order demonstrates the system works, and a significant risk half-treated demonstrates the opposite while looking more serious.
What Does the Scope Decision Cost Later?
More than anything else in the first stage, because every subsequent artifact inherits it.
A narrow scope covering two AI systems produces a small inventory, a short risk assessment and a manageable evidence set. A broad scope covering everything produces the opposite, and the certificate says which. So the decision is a trade between certification effort and what the certificate is worth to whoever asks for it.
Which Way Does the Trade Run?
Toward narrow first and broadening at recertification, because a certificate covering a defined scope is achievable and a certificate covering nothing is not. A customer asking whether you are certified will also ask what the scope was, so a narrow scope has to be one that answers their question rather than one that was merely easy.
What Makes a Scope Defensible?
A boundary somebody outside can understand and verify. Business unit, system or use case all work, stated in terms that map to something real. A scope defined by which systems happened to have good documentation is not a boundary, and a use case inventory is what makes the alternative statable.
What Should Be Established?
Three things, and the first determines whether a target date is realistic at all.
Whether an internal audit and a management review have occurred, since without both there is no completed cycle and no certification regardless of documentation quality. Which existing records already constitute oversight, corrective action and review evidence under other names. Then which risk treatment you would walk an auditor through, chosen now rather than found on the day. AI compliance readiness assessed per requirement shows which of the three columns each item sits in, and producing evidence on somebody else's timeline is the capability the second stage tests.
The Cycle Sets the Date, Not the Writing
An auditor works in a fixed sequence because each artifact constrains the next, so scope determines the inventory, the inventory determines the risk assessment, the assessment determines the statement of applicability, and that determines which operational records should exist. Documents prepared in parallel produce a set that does not reconcile, and the chain is followed precisely to find where. The first stage is a writing exercise and the second asks for records of events, which cannot be created afterward, so a management review, an internal audit and a closed corrective action all have to have happened. Retrospective work is most visible in the statement of applicability, where a control selected with no corresponding risk was selected because it was already there. Kovrr's AI compliance readiness shows which requirements existing records already answer.
To see which certification requirements your existing records already satisfy, book a demo mapped to your own estate.
ISO 42001 Audit FAQs
Speak to an ExpertWhat order does an ISO 42001 auditor request evidence in?
Scope and context first, establishing which systems are covered. Then the inventory and classification listing systems with their intended purposes and risk positions, then the core policies, then the risk and impact assessments, then the statement of applicability showing which controls were selected and why, with operational records last. The sequence is deliberate because each artifact constrains the next.
What is the difference between an ISO 42001 stage 1 and stage 2 audit?
The first stage reviews whether the framework, scope and policies are documented, and its output is a list of shortfalls, with severe ones preventing progress to the second stage. The second stage asks whether the organization operates the way the documents describe, requesting logs, version histories, oversight records and a walkthrough of a recent risk treatment. The first is a writing exercise and the second is not.
Which ISO 42001 evidence cannot be produced retrospectively?
Anything that records an event rather than describing an intention. Management review records, since a meeting either took place on a date with an agenda and attendees or did not. Internal audit records, with findings and a scope. Corrective action records showing a finding raised, actioned and verified closed with dates in that order. And human oversight records, meaning the log of a person reviewing an output at the time.
Do you need a management review before ISO 42001 certification?
Yes, and it is what sets the timeline. A management system standard expects the plan, do, check and act loop to have turned at least once, so an internal audit has to have been conducted and a management review held, and a management review that reviews nothing is not one. An organization deciding in January to certify cannot compress that into February regardless of documentation effort.
What is a Statement of Applicability in ISO 42001?
The document recording which controls were selected or excluded and why. Derived properly, the reasoning traces back to specific risks in the risk assessment, while one written to match the controls an organization already had reads as a list of justifications rather than conclusions. An auditor comparing the two documents looks for controls in the statement with no corresponding risk, which is the tell that it was written backward.
Which risk treatment should you present in an ISO 42001 audit?
A completed one rather than an impressive one. The walkthrough requires naming an instance, then showing identification, assessment, the decision and its reasoning, implementation and verification with dates in sequence. A modest risk fully closed with dates in the right order demonstrates the system works, while a significant risk half-treated demonstrates the opposite while looking more serious.




