Back to Insights
AI Governance10 min read11 August 2026

AI Audit: What Enterprise Leaders Should Actually Ask For

AI audit has moved from a niche practice to a board-level expectation. ISO/IEC 42006 gave auditors a formal accreditation standard in July 2025, KPMG became the first Big Four firm to earn ISO 42001 certification in November 2025, and EU AI Act enforcement architecture activated on 2 August 2026. Here is what enterprise leaders should ask for when they commission — or prepare for — an AI audit.

AA

Agraj Agranayak

Founder & CEO, Imagine Works · About · LinkedIn

Key Takeaways

  • **Three distinct audits are now expected of enterprise AI programmes** — an internal audit against the organisation's own AI policy, a third-party certification audit against **ISO/IEC 42001:2023** (the AI management system standard published December 2023), and, for EU-market high-risk AI systems, a **conformity assessment** under the EU AI Act. Confusing them is the most common scoping error.
  • **ISO/IEC 42006:2025** — published 7 July 2025 by ISO/IEC JTC 1/SC 42 — defines what a competent ISO 42001 audit looks like. It layers AI-specific requirements on top of ISO/IEC 17021-1 and applies specifically to management-system audit, not algorithm audit or EU AI Act product conformity. Accredited certification bodies as of mid-2026 include **Schellman, A-LIGN, BSI, Coalfire, TÜV SÜD, TÜV Nord Poland, and AENOR**.
  • **KPMG became the first Big Four firm to achieve ISO 42001 certification on 18 November 2025**, issued by Schellman Compliance. Deloitte, PwC and EY are all in flight. Gartner's public forecast is that **71% of large enterprises will plan ISO 42001 alignment by 2027** — the audit market is now real, and the question for most boards is not whether to be audited but by whom and to what standard.
  • An AI audit is **not the same as an AI red team engagement**. Audit assesses whether documented controls exist and operate as designed — evidence, policies, records, sign-offs, testing artefacts. Red teaming actively attacks the system to find undocumented failure modes. A serious governance programme needs both, and audit findings typically *require* red-team evidence as one of the artefacts under review.
  • For enterprise deployers of AI (not providers), the most urgent audit question in 2026 is **not whether you can pass ISO 42001** but **whether you can evidence Article 4 AI-literacy compliance** — the obligation that entered into force on 2 February 2025 and whose enforcement architecture activated across EU sectoral regulators on 2 August 2026, with fines under Article 99 of up to **€15 million or 3% of global turnover**.

Twelve months ago, "AI audit" mostly meant an internal-audit function running a light-touch review of what the data-science team was doing. Today it is a distinct discipline with its own international standard (ISO/IEC 42001), its own auditor-accreditation standard (ISO/IEC 42006), a live Big Four practice area, and — for EU-market high-risk AI systems — a legally-required conformity assessment under the EU AI Act. This guide sets out what enterprise leaders should actually ask for when they commission or prepare for one.

What "AI Audit" Actually Means in 2026

The phrase covers at least three distinct engagements, and treating them as one is the most common scoping mistake:

  • Internal AI audit — the second- or third-line-of-defence function inside the enterprise reviews whether the organisation's own AI policy, controls, and decisions are being followed. Typically owned by internal audit, sometimes co-owned with risk or compliance. No external certificate is issued; the deliverable is a report to the audit committee.
  • Third-party certification audit against ISO/IEC 42001:2023 — an accredited certification body audits the organisation's AI Management System (AIMS) against the international standard and, if the system meets requirements, issues a certificate valid for a three-year cycle with annual surveillance audits. This is the AI equivalent of ISO 27001 certification and is becoming the default question in enterprise procurement.
  • EU AI Act conformity assessment — for AI systems classified as high-risk under Annex III of the Act, the provider must complete a conformity assessment (self-assessment for most categories, notified-body assessment for a subset) before placing the system on the EU market. This is a product/system assessment, not a management-system audit, and it is a legal precondition for the CE marking.

A serious AI governance programme in 2026 needs all three, or at least a clear plan for each. Enterprise deployers of third-party AI (rather than providers) will typically need internal audit plus ISO 42001 certification; the conformity assessment sits with the provider they buy from — but deployers have their own Article 26 obligations to verify it has been done.

What Changed With ISO/IEC 42006 in July 2025

Until mid-2025, ISO 42001 was live but there was no formal standard for what "a competent auditor" of an AI management system looked like. Any certification body could self-declare its methodology, which meant the value of an ISO 42001 certificate depended heavily on which body issued it.

ISO/IEC 42006:2025 — published 7 July 2025 — fixed this. It sits on top of ISO/IEC 17021-1 (the baseline management-system audit standard) and adds AI-specific requirements: audit teams must demonstrate collective competency across all ISO 42001 Annex A controls (individual auditors need not each be AI experts), audit duration must reflect the number and complexity of AI systems in scope, and the audit must specifically cover the AI-lifecycle stages the organisation is engaged in.

As of mid-2026 the certification bodies with verifiable ISO 42006 accreditation include Schellman (ANAB-accredited September 2024), A-LIGN (early recipient), BSI (UKAS January 2026; RvA December 2024), Coalfire (ANAB-accredited July 2025), TÜV SÜD, TÜV Nord Poland, and AENOR (Spain). Enterprise buyers should ask any prospective certification body which accreditation they hold and when it was granted.

Why Big Four Certifications Matter

On 18 November 2025, KPMG US announced ISO 42001 certification issued by Schellman Compliance, making it the first of the Big Four to certify its own AI management systems against the standard. Deloitte, PwC and EY have all published governance-framework materials and are moving through their own certification programmes.

This matters for two reasons. First, it signals that ISO 42001 is now the credible convergence point for enterprise AI governance — the Big Four rarely certify themselves against a standard they consider unserious. Second, it changes the audit-supplier market: KPMG can now genuinely say it audits AI management systems in an organisation that has passed the same audit itself. Public commercial forecasts — including Gartner's widely-cited 71% of large enterprises will plan ISO 42001 alignment by 2027 — indicate this is not a passing certification fashion.

The named orgs that hold ISO 42001 certification as of mid-2026 span cloud (AWS), professional services (KPMG International), clinical trials (Clario), synthetic media (Synthesia), BPO (Teleperformance), and multiple mid-market technology providers (Unique AG, TTMS, GMV). This is a broader spread than ISO 27001 saw at the same maturity point.

What an ISO 42001 Certification Audit Actually Covers

Enterprise leaders often assume ISO 42001 is an "AI ethics" audit. It is not. It is a management-system audit — the auditor is checking whether the enterprise has decided what its AI policy is, whether it has implemented the controls that policy requires, whether it operates those controls as designed, and whether it measures and improves them. The Annex A controls span:

  • Organisational context and leadership — Is there a documented AI policy? Does executive leadership own it? Are roles clear?
  • Planning — Is there an AI risk-assessment process? Is there an AI system inventory? Are impact assessments done on high-risk uses?
  • Support — Are staff trained? Is there a controlled documentation set? Is there a supplier-management process for third-party AI?
  • Operation — Are AI systems developed and operated according to the documented process? Are decisions and overrides logged?
  • Performance evaluation — Is monitoring in place? Are incidents captured? Are internal audits happening?
  • Improvement — Is there a corrective-action process? Are lessons from incidents fed back into the policy?

The auditor evaluates evidence, not opinions. "We take AI safety seriously" is not evidence. A dated risk register, signed approvals for high-risk deployments, exception logs, training completion records, incident-response artefacts, and monitoring dashboards are.

AI Audit vs AI Red Teaming vs AI Conformity Assessment

These three terms are used interchangeably in loose conversation. They should not be.

  • AI audit (ISO 42001-style) assesses whether documented controls exist and operate as designed. It is a management-system review.
  • AI red teaming actively attacks the system to find undocumented failure modes, adversarial vulnerabilities, and responsible-AI harms. It is a testing activity. Our companion piece on AI red teaming for enterprise leaders covers the discipline in detail.
  • EU AI Act conformity assessment is a system-level product review against the Act's Annex III high-risk requirements. It is a legal precondition for CE marking.

A mature programme uses the three together: red-team evidence and conformity-assessment records are inputs to the ISO 42001 audit, which itself is evidence an EU enforcement authority may examine when investigating whether the organisation met its Article 26 deployer obligations.

Where Enterprise Programmes Get Stuck

  • Scope creep at Stage 1. ISO 42001 audits split into Stage 1 (documentation review) and Stage 2 (evidence review). Organisations that treat Stage 1 as an inventory exercise across every AI-adjacent system typically over-scope and never reach Stage 2. Draw a defensible boundary — a specific AI-lifecycle scope for the first cycle, with a plan to widen it over the three-year cycle.
  • Confusing self-attestation with certification. A signed executive attestation is not an audit. Neither is a Big Four consulting engagement that produces a readiness report — that is preparation. Only an accredited certification body under ISO 42006 can issue an ISO 42001 certificate.
  • Under-investing in evidence infrastructure. Auditors sample. If the audit programme discovers that the enterprise has an AI policy but cannot demonstrate consistently-captured approval records or exception logs across the sampled systems, the finding is a major nonconformity. Evidence-capture design decisions belong at the start of the programme, not the audit week.
  • Auditor selection driven by price. ISO 42001 audits, at present maturity, vary widely in rigour between accredited bodies. A cheap audit that no external stakeholder recognises is worse than no audit. Ask for accreditation body, ISO 42006 accreditation date, and named prior clients before signing.

What Leaders Should Be Asking

The right questions from executive leadership sequence roughly like this:

  • Have we chosen a standard we're auditing against, and why that one? (ISO 42001 is the default answer for most enterprises. NIST AI RMF alignment is a stronger answer for US-federal-adjacent programmes.)
  • What is the audit scope for the first cycle, and how does it map to the highest-impact AI systems we run?
  • Who are the certification bodies we're shortlisting, and are they ISO 42006 accredited?
  • What evidence-capture infrastructure do we need before we go external — decision logs, exception logs, training records, incident registers, model cards?
  • How does our internal audit function relate to the external certification programme, and to red-teaming and conformity-assessment activities?
  • For EU-market activities: which of our AI uses trigger Article 26 deployer obligations, and are our providers' conformity assessments something we've reviewed?

The Underlying Point

AI audit is now a real market with a real standard, real accredited auditors, and real Big Four practice areas. The organisations that struggle with it in 2027 will not be the ones that failed a first audit — they will be the ones that treated audit as a documentation exercise rather than a governance capability. The auditor is checking whether the enterprise runs a coherent, evidence-based AI management system. The most useful thing an audit produces, when done properly, is the discipline of running the system that way in the first place.

Imagine Works helps enterprise leaders scope AI audit programmes, prepare for ISO 42001 certification, and integrate audit findings into the wider AI governance and risk-design practice. Get in touch to discuss your AI audit posture.

Related Service

AI Governance & Risk Design

Designing the governance framework and risk architecture that keeps your AI systems compliant, auditable, and board-ready — before regulation forces the issue.

Explore this service

More Insights

More on AI Governance

View all
AI Governance8 min read

OWASP LLM05: Improper Output Handling (Formerly LLM02): Enterprise Guide

The 2025 OWASP Top 10 for LLM Applications renamed "Insecure Output Handling" (LLM02:2023) to "Improper Output Handling" (LLM05:2025) — but the underlying enterprise vulnerability is the same and, in most deployed LLM-integrated applications, it is still not fixed. Model output that gets rendered, executed, or interpolated downstream without sanitisation is how prompt injections cross the threshold from "the model said a bad thing" to XSS, SSRF, and remote code execution. Here is what LLM05 actually is, how it differs from prompt injection, and the controls that neutralise it.

25 August 2026Read article
AI Governance9 min read

AI Literacy: The EU AI Act Obligation Every Employer Now Faces

The EU AI Act's AI-literacy obligation entered into force on 2 February 2025, but 2 August 2026 was the moment enforcement architecture activated across EU sectoral regulators. The obligation applies whether or not the AI systems in question are high-risk, and whether the employer is a provider or a deployer. Here is what Article 4 actually requires, how the European Commission expects "sufficient" to be interpreted, and what a defensible programme looks like.

22 August 2026Read article
AI Governance10 min read

AI Red Teaming: What Enterprise Leaders Should Actually Ask For

AI red teaming has moved from a research-lab activity to a boardroom expectation. The EU AI Act now requires adversarial testing of general-purpose AI models with systemic risk. Microsoft has red-teamed 100+ generative AI products since 2018. NIST published a formal adversarial-ML attack taxonomy in March 2025. Here is what enterprise leaders should ask for when they commission — or evaluate — an AI red team engagement.

8 July 2026Read article