Skip to main content

Standard

Management Review Inputs Your ISO 42001 Auditor Will Ask For

A practitioner's guide to ISO/IEC 42001 clause 9.3: what the management review must consider, why top management (not the governance lead or DPO) owns it, the evidence a certification body will sample, the AI-specific inputs generic templates omit, and where the record usually breaks.

Management Review Inputs Your ISO 42001 Auditor Will Ask For

The request usually arrives attached to an audit plan. Six weeks before the Stage 2 assessment, the certification body sends its agenda and one line reads: "Clause 9.3 — management review — top management, 45 minutes." It reaches whoever holds the AI governance file, with a note asking for "the management review pack". What exists is a deck shown once to a technology steering group and no record that anyone decided anything.

Clause 9.3 of ISO/IEC 42001 is among the shortest clauses in the standard and the easiest to fail, because it is where an auditor can test in a single interview whether the AI management system governs anything or merely documents it.

What the clause actually asks for

Clause 9.3 comes in three parts. Top management must review the AI management system at planned intervals to confirm it remains suitable, adequate and effective. The second part lists the inputs the review must consider. The third requires results — decisions on improvement and on any need to change the system — with documented information retained as evidence.

Two things are routinely misread. The standard says planned intervals, not annually: you choose the frequency, but must have planned it and be able to explain why it suits the rate of change in your AI portfolio. And the listed inputs are a floor, not a template. A review that recites the list and says nothing specific about your own AI systems satisfies the letter and fails the intent.

Who is responsible

Top management owns the review. Not the AI governance lead, not the DPO, not internal audit. The standard places the duty on those with authority to allocate resources and change direction. The governance function prepares the pack and drafts the agenda; top management performs the review and makes the decisions. The auditor's real question is whether the people in the room could commit resource — and whether they did.

Two boundaries matter. First, the certification body audits your management system and decides whether to issue or maintain a certificate; it does not run your review, cannot pre-approve your input list, and impartiality rules bar it from consulting on the system it certifies. The certificate belongs to your organisation and covers the scope you defined, not any individual model. Second, your DPO, where you have one, advises and independently monitors. Putting the DPO in the chair to decide on risk treatment they are meant to monitor creates the conflict of interest data protection law exists to prevent. They should attend, report and challenge — not own the outcome.

The inputs an auditor will sample

InputEvidence that satisfiesWhere it usually goes wrong
Status of actions from previous reviewsAction log with owner, due date, status, closure evidenceFirst-cycle organisations have none — record that, rather than back-dating a meeting
Changes in external and internal issuesDated context register update naming specific changes: regulatory timelines, new model suppliers, reorganisationA paragraph on "the fast-moving AI landscape" attached to no decision
Changes in interested parties' expectationsUpdated register showing the source of each change: contract terms, regulator statements, workforce concernsOnly external parties considered; employees and end users omitted
Trends in nonconformities and corrective actionsThe nonconformity log plus commentary on what the pattern showsA log with no trend analysis, or only internal audit findings
Monitoring and measurement resultsDefined measures with results across at least two periodsMeasuring project delivery, not how AI systems behave in use
Internal audit resultsAudit programme, reports and finding status covering clauses and applicable Annex A controlsProgramme covers clauses only, skipping applicable Annex A controls
Fulfilment of AI objectivesObjectives with measures, targets and actual resultsObjectives written as activities ("roll out training"), not outcomes
Opportunities for continual improvementImprovement register with source, decision and ownerImprovements listed, never converted into owned actions

ISO 42001 does not prescribe which AI metrics you must monitor. You determine that when planning measurement, and the auditor assesses whether your choices are defensible rather than comparing them to a fixed list.

The AI-specific inputs generic templates miss

Most templates in circulation were written for quality or information security systems and adapted by find-and-replace, producing a review that could be about anything. These are the inputs that make it recognisably an AI management review:

  • Results of AI system impact assessments, and re-assessments for any system whose purpose, user population or deployment context has changed
  • Status of the risk treatment plan, including any Annex A control marked applicable in the Statement of Applicability but not yet implemented, with date and owner
  • AI incidents, near-misses and complaints about AI outputs — including those resolved informally by the service desk and never logged
  • Supplier performance: model version changes imposed on you, terms changes, sub-processor changes, and any deterioration you detected
  • Data governance: provenance, quality, retention, and any use of personal data in training, fine-tuning or evaluation, with the lawful basis confirmed
  • Competence and resourcing against the AI roles you have assigned, including vacancies and single points of dependency
  • Unsanctioned AI use discovered since the last review, and what was done about it
  • Any change to the AIMS scope: units added, systems retired, systems brought into scope

Outputs are decisions, not minutes

This is where most first-cycle reviews are found wanting. The clause requires results: decisions on improvement opportunities and on any need to change the management system, including resources. A record saying the committee "noted" the report is not a result. Each decision should name what was decided, who owns it, by when, and what resource was committed. Retain the minutes, the attendance list and the version of the pack considered.

Expect the auditor to pick one decision and trace it forward — to a budget line, a changed procedure, a corrective action record, a revised Statement of Applicability. If the thread breaks, the finding is not about paperwork; it is evidence that the review did not drive the system.

Limits, and when to take advice

ISO 42001 certifies a management system. It is not a technical certification of a model, and no audit conclusion states that your AI systems are accurate, safe or lawful. Treat any vendor claim to the contrary with suspicion.

Certification bodies set their own audit programmes, sampling and grading of findings within their scheme rules, so how much operating evidence they expect before Stage 2 varies. Ask yours directly, and confirm the accreditation status and scope of what they are offering — accredited ISO 42001 certification is still maturing in several markets.

Keep the regulatory boundary clean. ISO 42001 is not a harmonised standard under the EU AI Act, and certification does not create a presumption of conformity with it; supporting standards work, including CEN-CENELEC JTC 21's, and various implementing acts and guidance remain in development. If your organisation is a deployer of a third-party high-risk AI system, the AI Act's quality management system obligation sits with the provider, not you, and your review must not be presented as discharging it. Deployer obligations are separate. Nor does a certificate affect enforcement: the AI Act's ceilings of up to 7% of global annual turnover for prohibited practices and up to 3% for most other obligations, and up to 4% under UK and EU data protection law, sit outside the certification scheme.

Take specialist legal advice where you cannot confidently determine provider or deployer status, where personal data is used in training or evaluation, where the review would record a decision to keep operating a system with a known unresolved harm, or where a decision may trigger a reporting duty. Those are not management system questions, and the review is the wrong place to meet them first.

  • ISO 42001
  • management review
  • certification audit
  • internal audit
  • AI governance

More guides

Start Free AI Compliance Review