Why eight, and why these eight
ISO/IEC 42001 has seven clauses of requirements and thirty-eight Annex A controls. A Stage 1 reviewer does not open all of them. They open the documents that reveal whether a management system genuinely exists, because a system with these eight in order tends to have the rest, and a system missing them tends not to.
What follows is each of the eight, what an auditor is looking for, and the reason it most commonly fails. Two of them — the last two — are the ones you cannot fix quickly, so read those first if you are short of time.
What good looks like: a short document saying which parts of the organisation, which AI systems and which locations are inside the management system, and which are outside, with the reasoning.
Why it fails: the scope is drawn to include everything, because that felt safer, and the organisation cannot then evidence control over all of it. A narrow, defensible scope beats a broad, aspirational one every time.
What good looks like: approved at top-management level, dated, versioned, communicated, and specific enough that a member of staff could tell from it whether a particular use is permitted.
Why it fails: it is a statement of values rather than a rule. “We use AI ethically and responsibly” is not a policy; it is a sentiment, and it gives an auditor nothing to test against.
What good looks like: a documented methodology, and a risk assessment actually produced using it, covering risks to the organisation and risks to the people the AI affects.
Why it fails: only the first half. A register of commercial and operational risk to the business, with nothing about the people decisions are made about — which is the part ISO/IEC 42001 exists to address.
What good looks like: all thirty-eight Annex A controls listed, each marked applicable or not, each with a justification, and each applicable one linked to how it is implemented.
Why it fails: exclusions with no reasoning. Clause 6.1.3 asks for justification for inclusions and exclusions, and this is the single most frequently raised Stage 1 finding.
What good looks like: a documented procedure aligned with ISO/IEC 42005, and at least one completed assessment for a real system, covering who is affected, what harm is possible, and what mitigates it.
Why it fails: the procedure exists and has never been run. A process with no output is a plan, not a control.
What good looks like: a maintained list of AI systems in scope, including third-party and embedded ones, with an owner, a purpose and a risk classification each.
Why it fails: it lists what was procured as AI and misses what arrived as a feature in an existing product. Most organisations under-count their estate, and an auditor who finds one omission will assume there are others.
What good looks like: a planned programme, at least one internal audit carried out against the AIMS, findings raised, and corrective actions tracked to closure.
Why it fails: it has not happened yet. This is dated evidence — it cannot be produced retrospectively, and it is one of the two items that genuinely sets your earliest possible certification date.
What good looks like: minuted evidence that top management reviewed the AIMS against the inputs Clause 9.3 lists, and made decisions — about resources, about changes, about risks accepted.
Why it fails: the review happened as an agenda item with no minutes, or it happened and no decision was recorded. A review that changed nothing and documented nothing did not happen as far as the standard is concerned.
The sequencing that saves months
Items 7 and 8 are dated evidence and everything else is not. That single fact should drive your plan. If you start the internal audit programme and the management review cycle early — even against an incomplete management system — you are accumulating the evidence that sets your earliest realistic certification date while you finish the documents.
The common and expensive alternative is to perfect the documents first, then discover that the two dated items now stand between you and an audit by another two quarters.
A note on what “Open” means
An honest assessment of these eight usually returns a mix, and that is the normal starting position rather than a bad result. What matters is the difference between Open and Unknown. Open means you know the gap. Unknown means nobody could tell you whether the document exists.
In a Stage 1 review those produce the same outcome. Establishing which of your eight are merely unknown is usually the cheapest work on the whole list, and it is where we would start.
This article is general information, not legal advice, and not an audit. Stage 1 and Stage 2 certification audits are performed only by certification bodies accredited under ISO/IEC 42006. VisionXY7 Ltd prepares organisations for those audits and reviews their systems independently; it does not perform them.