Internal audit and management review
Lesson 4 of 5 in Lead Implementer Track: Building an AIMS from Mandate to Certificate.
Internal audit is the implementer’s rehearsal space: every embarrassing discovery it makes is one the certification body will not make first. Build the programme risk-based — the impact assessment process and lifecycle controls of your highest-risk systems get audited more often than the document-control procedure — with defined criteria and scope per audit, and results that reach management with names attached. The method of auditing is the Lead Auditor track’s territory (ISO 19011 discipline lives there); the implementer’s problem is different: staffing an independent audit in an organisation of twenty people.
The rule is absolute — nobody audits their own work — but small organisations have options the rule permits: cross-functional audits (the quality manager audits the AI governance processes; the governance lead audits engineering’s control execution), contracted internal audit (an external professional performs it under your programme — internal audit means your audit, not your employee), or reciprocal arrangements within a group. What never works: the AIMS builder auditing the AIMS. An internal audit of a first-year system that reports ‘no nonconformities’ does not reassure a certification auditor — it tells them the audit was decorative, and they sharpen accordingly.
Small-org staffing: can this person audit the risk-assessment process?
Interactive decision tree — outcomes:
- Blocked: self-review
Objectivity and impartiality (clause 9.2) rule this out categorically — the person who built the process cannot find its flaws credibly, however honest. Find another auditor; there is no mitigation for auditing your own work.
- Blocked: unmanaged conflict
Independence is behavioural, not just organisational: an auditor whose findings route through — and whose appraisal belongs to — the auditee will soften them. Restructure the reporting of findings, or pick someone else.
- Fit to audit
Independent of the work, structurally shielded, competent to judge the evidence. Document the selection reasoning in the audit programme — certification auditors read who audited what, and why that was credible.
- Contract it — legitimately
A bought-in internal audit is fully conformant: it runs under your clause 9.2 programme, against your criteria, reporting to your management. Pair your future auditors with the contractor so the competence transfers.
- Not yet — train first
An incompetent audit is worse than a late one: it produces false assurance and teaches the organisation that audits are theatre. Delay, train a cross-functional auditor, and adjust the certification timeline honestly.
Corrective-action discipline is where implementations reveal their character. The clause 10.2 anatomy (correction → root cause → corrective action → effectiveness check) was drilled in the aims-42001 module; the implementer’s disciplines are three. Ask ‘why’ until you hit a process, not a person — ‘the analyst forgot’ is never a root cause; ‘no trigger exists that fires the reassessment when the change log updates’ is. Check breadth immediately: the same weakness usually lives in three other places, and finding them yourself is cheap while an auditor finding them is a pattern-of-minors major. Date the effectiveness check when you open the action, not when someone remembers — an action without a scheduled verification is a promise, and promise logs are what surveillance audits feast on.
Management review steers only if you build it to. Construct the agenda directly from the clause 9.3 required inputs; circulate short decision memos beforehand (‘monitoring shows X; options A/B; recommendation B; cost’) so the meeting decides rather than absorbs; and end every input with one of three verbs — decide, delegate, or accept — minuted with owners and dates. A review that produces no decisions is a status meeting wearing a clause number, and auditors read the minutes for exactly that.
Then comes the call the whole track has built toward: the readiness decision. Go to Stage 1 when — and only when — the evidence arithmetic works: three to six months of dated operating records; a full internal audit cycle covering every clause and the SoA-applicable controls, with corrective actions closed; a management review held, with outputs; no open internal majors; and an SoA that still matches reality. Each criterion maps to a classic Stage 1 killer from the certification module — which is the point: the readiness review is Stage 1, performed by you, for free.
Key terms: internal audit, management review, corrective action, root cause analysis
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.