Home Solutions Insights Case Studies About Book Discovery Call
Governance7 min read

The Eight Things an Auditor Asks For at Stage 1

Dr. Mahdi Seify
Dr. Mahdi Seify
Founder & CAIO, VisionXY7 Ltd · Published 14 September 2026

PhD, AI-Driven Business Analytics · ISO/IEC 27001 Lead Auditor and Lead Implementer. Written from delivery, not from a summary of the standard.

In short: Stage 1 is not a technical inspection. It is an auditor reading your documents and deciding whether there is a management system here worth examining properly at Stage 2. Eight items carry most of that decision. Every one of them is something you can prepare in advance, and two of them — internal audit and management review — cannot be produced at short notice at all, because their evidence is dated.

Why eight, and why these eight

ISO/IEC 42001 has seven clauses of requirements and thirty-eight Annex A controls. A Stage 1 reviewer does not open all of them. They open the documents that reveal whether a management system genuinely exists, because a system with these eight in order tends to have the rest, and a system missing them tends not to.

What follows is each of the eight, what an auditor is looking for, and the reason it most commonly fails. Two of them — the last two — are the ones you cannot fix quickly, so read those first if you are short of time.

1 · The AIMS scope statement

What good looks like: a short document saying which parts of the organisation, which AI systems and which locations are inside the management system, and which are outside, with the reasoning.
Why it fails: the scope is drawn to include everything, because that felt safer, and the organisation cannot then evidence control over all of it. A narrow, defensible scope beats a broad, aspirational one every time.

2 · The AI policy

What good looks like: approved at top-management level, dated, versioned, communicated, and specific enough that a member of staff could tell from it whether a particular use is permitted.
Why it fails: it is a statement of values rather than a rule. “We use AI ethically and responsibly” is not a policy; it is a sentiment, and it gives an auditor nothing to test against.

3 · The AI risk assessment

What good looks like: a documented methodology, and a risk assessment actually produced using it, covering risks to the organisation and risks to the people the AI affects.
Why it fails: only the first half. A register of commercial and operational risk to the business, with nothing about the people decisions are made about — which is the part ISO/IEC 42001 exists to address.

4 · The Statement of Applicability

What good looks like: all thirty-eight Annex A controls listed, each marked applicable or not, each with a justification, and each applicable one linked to how it is implemented.
Why it fails: exclusions with no reasoning. Clause 6.1.3 asks for justification for inclusions and exclusions, and this is the single most frequently raised Stage 1 finding.

5 · The AI system impact assessment

What good looks like: a documented procedure aligned with ISO/IEC 42005, and at least one completed assessment for a real system, covering who is affected, what harm is possible, and what mitigates it.
Why it fails: the procedure exists and has never been run. A process with no output is a plan, not a control.

6 · The AI system inventory

What good looks like: a maintained list of AI systems in scope, including third-party and embedded ones, with an owner, a purpose and a risk classification each.
Why it fails: it lists what was procured as AI and misses what arrived as a feature in an existing product. Most organisations under-count their estate, and an auditor who finds one omission will assume there are others.

7 · The internal audit programme

What good looks like: a planned programme, at least one internal audit carried out against the AIMS, findings raised, and corrective actions tracked to closure.
Why it fails: it has not happened yet. This is dated evidence — it cannot be produced retrospectively, and it is one of the two items that genuinely sets your earliest possible certification date.

8 · Management review

What good looks like: minuted evidence that top management reviewed the AIMS against the inputs Clause 9.3 lists, and made decisions — about resources, about changes, about risks accepted.
Why it fails: the review happened as an agenda item with no minutes, or it happened and no decision was recorded. A review that changed nothing and documented nothing did not happen as far as the standard is concerned.

The sequencing that saves months

Items 7 and 8 are dated evidence and everything else is not. That single fact should drive your plan. If you start the internal audit programme and the management review cycle early — even against an incomplete management system — you are accumulating the evidence that sets your earliest realistic certification date while you finish the documents.

The common and expensive alternative is to perfect the documents first, then discover that the two dated items now stand between you and an audit by another two quarters.

A note on what “Open” means

An honest assessment of these eight usually returns a mix, and that is the normal starting position rather than a bad result. What matters is the difference between Open and Unknown. Open means you know the gap. Unknown means nobody could tell you whether the document exists.

In a Stage 1 review those produce the same outcome. Establishing which of your eight are merely unknown is usually the cheapest work on the whole list, and it is where we would start.

This article is general information, not legal advice, and not an audit. Stage 1 and Stage 2 certification audits are performed only by certification bodies accredited under ISO/IEC 42006. VisionXY7 Ltd prepares organisations for those audits and reviews their systems independently; it does not perform them.

The service behind this article
ISO/IEC 42001 Audit Readiness

The free Quick Check reports all eight of these as Met, Partial, Open or Unknown in about eight minutes, on what you tell it. The Gap Review examines the evidence behind each one.

See the assessment →

Frequently Asked

What actually happens at Stage 1?

An auditor from an accredited certification body reviews your documented management system, usually remotely, and forms a view on whether you are ready for Stage 2. The output is a report listing findings and, commonly, areas of concern to resolve before Stage 2. It is genuinely possible to be told you are not ready, and being told that early is cheaper than being told it late.

Can we pass Stage 1 with documents alone?

Mostly, yes — that is what Stage 1 examines. But two of the eight, internal audit and management review, are evidence that an activity took place on a date. You cannot write those the week before. This is the main reason a realistic run-up to certification is measured in months rather than weeks.

What is the most common Stage 1 failure?

A Statement of Applicability that lists the thirty-eight controls with a column marked “yes” and no justification, particularly for exclusions. Clause 6.1.3 asks for reasoning, and “not applicable” without a reason is the finding auditors raise most often.

Do we need all eight before we start?

No. You need to know which ones you have. That is the point of assessing first: the eight are not equally expensive to close, and knowing that a scope statement is a morning's work while an internal audit programme is a quarter changes how you sequence the work and what you tell your board about timing.

Does VisionXY7 perform the Stage 1 audit?

No. Stage 1 and Stage 2 audits are performed only by certification bodies accredited under ISO/IEC 42006. VisionXY7 prepares organisations for that audit and reviews their systems independently beforehand, using ISO/IEC 27001 Lead Auditor methodology. The separation is deliberate and it is what makes the certification worth anything.

Which Of The Eight
Could You Produce Today?

The free Quick Check answers exactly that in about eight minutes — each of the eight reported as Met, Partial, Open or Unknown, with the requirement stated first and your position second. On screen immediately, no account required.

Start the free Quick Check