After sitting through multiple ISO 42001 audits, as both a standards drafter and an auditor, I keep seeing the same gaps. Having AI policy documents is not the same as running an AI management system. Risk and impact are not the same register. And even I got one thing wrong when we built the standard. Here are five field lessons from real ISO/IEC 42001 audits: what auditors actually look for, the scope trap that catches almost every organization, and why treating AI oversight as a checkpoint instead of a mindset will fail your audit.

Lesson 01 — Having documents is not the same as having a system

Documents are mandatory: AI policy, risk methodology, statement of applicability. But the auditor goes beyond paperwork. They want proof you’ve used these policies, not the policy itself. Real assessments. Real meetings. Real logs. Real decisions, with dates and names attached.

Lesson 02 — Risk and impact are two different things

I see the same issue on almost every project. Teams build one giant spreadsheet labeled “AI risk and impact register” and call it done.

Risk is what could go wrong for the company. Impact is what could go wrong for the people affected by the AI.

ISO 42001 asks for both, in separate documents.

Lesson 03 — You have more AI than you think

In Stage 2, the auditor asks to see the actual AI applications. Most clients aren’t ready. They list the models they built internally, and forget the AI inside their CRM, HR tools, support chatbots, vendor platforms, and browser plug-ins. AI is everywhere now. Find all of it before the auditor does.

Lesson 04 — Checking the output is not enough

Ask about oversight, and people point to sign-off forms. Ask “who decided what data trained the model?” and the room goes quiet.

Oversight isn’t a checkpoint at the end. It’s a mindset across the entire life of the AI system: before, during, after launch, and every month after that.

Lesson 05 — ISO 27001 is not a shortcut

This is the most painful lesson, and I helped cause it. When we built 42001, we mirrored 27001 to ease adoption. Instead, it became a copy-paste habit.

27001 is about keeping data safe. 42001 is about that, plus fairness, accuracy, explainability, human oversight, and model drift.

Use 27001 as a base. Don’t clone it.

The field checklist: what I tell my clients now

  • Start your audit prep as early as possible.
  • Run the system for real. Don’t just write documents.
  • Make two registers: one for risk, one for impact.
  • Find all the AI you’re using, even the small stuff from vendors.
  • Build oversight into every step of the lifecycle.
  • Don’t copy your ISO 27001 controls. Start fresh.

Is your AI governance real, or only on paper?

The audit is hard, but it’s fair. It tests one thing: whether your AI governance is real, or only on paper.

Have you been through a 42001 audit yet? What surprised you most?