5.3 Clause 9: Performance Evaluation, Internal Audit & Management Review

Key Takeaways

  • Clause 9.1 determines what and how to monitor and measure, timing, analysis, and evaluation of AI performance and AIMS effectiveness.

  • Clause 9.2 audits conformity to organizational and ISO/IEC 42001 requirements and tests effective implementation and maintenance.

  • Audit programmes consider process importance and previous audit results; “organizational changes” is not a separately listed consideration.

  • Auditor selection and audit conduct must ensure objectivity and impartiality.

  • Management review uses five input categories and produces decisions on improvement opportunities and needed AIMS changes.

Last updated: October 2026

Clause 9: performance evaluation

Clause 9 is the Check stage of PDCA. It asks whether AI performance and the AIMS are producing intended results, conforming to requirements, and remaining suitable, adequate, and effective.

9.1 Monitoring, measurement, analysis, and evaluation

The organization determines:

  • what needs to be monitored and measured;
  • methods for monitoring, measurement, analysis, and evaluation needed for valid results;
  • when monitoring and measurement will occur; and
  • when results will be analyzed and evaluated.

It evaluates AI performance and AIMS effectiveness and makes appropriate documented information available as evidence of results.

Selecting useful measures

Measures should follow objectives, risks, impacts, controls, and applicable requirements. Examples include model performance, service reliability, data quality, subgroup error patterns, incident trends, concern handling, supplier changes, objective progress, audit findings, and completion of impact reassessments.

No single metric set is mandatory. An organization using a rule-based internal system may not need LLM hallucination measures. A hiring system can require outcome and process measures different from a predictive-maintenance system.

“Valid results” means the method is suitable for the decision. A drift statistic without a baseline, sample window, or response rule may produce numbers without useful evaluation.

9.2 Internal audit

Internal audits occur at planned intervals to provide information on whether the AIMS:

  • conforms to the organization’s own AIMS requirements;
  • conforms to ISO/IEC 42001 requirements; and
  • is effectively implemented and maintained.

An internal audit is not the same as monitoring a model and not the same as an external certification audit. It evaluates the management system against defined audit criteria and scope.

Audit programme

The organization plans, establishes, implements, and maintains one or more audit programmes. Programmes include frequency, methods, responsibilities, planning requirements, and reporting. They consider the importance of relevant processes and the results of previous audits.

For each audit, the organization defines criteria and scope, selects auditors and conducts the audit to ensure objectivity and impartiality, and ensures results are reported to relevant managers. Documented information is available as evidence of programme implementation and audit results.

The standard states the outcome—objectivity and impartiality. Avoiding assignment of a person to audit their own work is a common way to protect that outcome, but ISO/IEC 42001 does not use the absolute sentence “an internal auditor can never audit any work they touched.” Small organizations can use cross-auditing or contracted auditors while managing conflicts.

9.3 Management review

Top management reviews the AIMS at planned intervals to ensure continuing suitability, adequacy, and effectiveness. “Planned intervals” does not automatically mean annually; frequency should fit the organization and be established.

Required input categories

The review includes five categories:

  1. status of actions from previous reviews;
  2. changes in external and internal issues relevant to the AIMS;
  3. changes in relevant interested-party needs and expectations;
  4. information on AIMS performance, including trends in nonconformities and corrective actions, monitoring and measurement results, and audit results; and
  5. opportunities for continual improvement.

ISO/IEC 42001 does not add objective achievement, resource adequacy, or effectiveness of risk-and-opportunity actions as separate required input categories here. Those matters can still be useful to management and can appear through the required categories or other chosen inputs, but they should not be presented as quoted Clause 9.3.2 items.

Results

Management-review results include decisions related to continual-improvement opportunities and any need for changes to the AIMS. The organization makes documented information available as evidence of results. Resource decisions can follow from a needed change, but “resource needs” is not a separately listed Clause 9.3.3 result.

A dashboard alone cannot make management decisions. It can be an input. The evidence should show top management considered required information and made or confirmed decisions with appropriate authority.

Monitoring, audit, and management review compared

ActivityPrimary purposeTypical actor
Monitoring and measurementGenerate and evaluate performance evidenceProcess and system owners
Internal auditIndependent, objective conformity/effectiveness evaluationCompetent, impartial auditors
Management reviewStrategic top-management evaluation and decisionsTop management

These activities reinforce one another. Monitoring can reveal a trend; internal audit can test whether the monitoring process conforms and works; management review can decide to change resources, objectives, or the AIMS.

Example

An organization monitors increasing override rates in an AI triage service. Internal audit finds that operators are using a new workflow not reflected in the documented process and that the change was not assessed. Management review considers the performance trend, audit result, resources, risks, and interested-party needs. It decides to revise the process, fund additional validation, and update competence requirements.

The example illustrates the Clause 9 chain without assuming that a particular override percentage automatically proves a nonconformity.

Finding severity

ISO/IEC 42001 defines requirements but does not in these clauses assign every gap a universal “major” or “minor” label. Certification bodies apply their conformity-assessment rules and evidence. Do not claim that one missing signature or one vague objective automatically guarantees a major finding.

Tip

If the question asks “does the AIMS conform and is it effectively implemented?” choose internal audit. If it asks “what should top management decide?” choose management review.

Test Your Knowledge

What must internal audits evaluate?

A

Only model accuracy

B

Only legal compliance

C

Employee satisfaction alone

D

Conformity to organizational and ISO/IEC 42001 requirements and effective implementation and maintenance

Test Your Knowledge

Which is an expressly required management-review input category?

A

The status of actions from previous management reviews

B

A public release of all model weights

C

A fixed annual certification score

D

A separate resource-adequacy report

Test Your Knowledge

What does Clause 9.2 require regarding auditors?

A

All audits must be performed by regulators

B

Selection and conduct that ensure objectivity and impartiality

C

The model developer must lead every audit

D

No documented audit results are needed

Sections you finish are checked off in the contents.