10.2 Audit Types, Objectives, Criteria & Scope
Key Takeaways
- First-party audits are internal; second-party are typically customer-on-supplier; third-party are independent (often certification) audits
- Audit criteria for an AIMS engagement commonly include ISO/IEC 42001 requirements, the organization’s AIMS documented information, the SoA, and other applicable requirements (contracts, laws, policies)
- Audit objectives define purpose; scope defines boundaries (units, locations, AI systems, activities, period); criteria define the reference for conformity
- The audit client commissions the audit; the auditee is the organization being audited—these roles can differ
- An audit program is a set of audits planned for a period; an individual audit is one systematic engagement within that program; ISO/IEC 17021-1 governs certification-body competence and impartiality for management-system certification
10.2 Audit Types, Objectives, Criteria & Scope
Before an AIMS audit can be planned or executed, the Lead Auditor must classify the engagement, name the parties, and lock down three design elements: objectives, criteria, and scope. Confusion among these concepts is a frequent source of exam errors and real-world audit failures.
ISO 19011 provides the vocabulary and process model for management-system auditing. For third-party certification of management systems (including an AIMS certified against ISO/IEC 42001), certification bodies also operate under ISO/IEC 17021-1 (requirements for bodies providing audit and certification of management systems).
First-, Second-, and Third-Party Audits
Audits are commonly classified by the relationship between the auditor and the organization being audited.
AUDIT CLASSIFICATION BY PARTY (AIMS)
┌────────────────────┬────────────────────┬────────────────────┐
│ First-party │ Second-party │ Third-party │
│ Internal audit │ Supplier / │ Independent │
│ (on behalf of the │ customer audit │ (e.g. certification│
│ organization) │ │ body) │
├────────────────────┼────────────────────┼────────────────────┤
│ ISO/IEC 42001 │ Contractual, SLA, │ Certification, │
│ Clause 9.2 │ vendor due │ supplier of │
│ internal audits │ diligence on AI │ independent │
│ │ providers │ assurance │
└────────────────────┴────────────────────┴────────────────────┘
First-party audits (internal)
First-party audits are conducted by, or on behalf of, the organization itself for management review, improvement, and verification of conformity. ISO/IEC 42001 Clause 9.2 requires internal audits at planned intervals to determine whether the AIMS:
- Conforms to the organization’s own requirements for its AIMS
- Conforms to the requirements of ISO/IEC 42001
- Is effectively implemented and maintained
AIMS example: An internal audit team samples high-risk AI systems, reviews impact assessments, and reports to top management before the external certification body arrives. Auditors should still be independent of the functions audited to the extent practical (e.g., not solely auditing their own model pipeline).
Second-party audits (supplier / customer)
Second-party audits are typically performed by parties having an interest in the organization, such as customers, or by other persons on their behalf. In the AI ecosystem, second-party audits are common when:
- A bank audits a fintech’s AI credit models under a partnership agreement
- An enterprise customer audits an AI SaaS provider’s AIMS controls before onboarding
- A manufacturer audits a computer-vision vendor’s data quality and change-control practices
Criteria may include ISO/IEC 42001, contract clauses, AI ethics codes, security questionnaires, or customer-specific AI policies—not only the full management-system standard.
Third-party audits (independent / certification)
Third-party audits are performed by independent auditing organizations, often for certification or legal/regulatory purposes. An accredited certification body (CB) auditing an AIMS against ISO/IEC 42001 is the classic third-party case.
Third-party certification audits usually include:
- Stage 1 — documentation and readiness (scope, policy, risk/impact processes, SoA, etc.)
- Stage 2 — evaluation of implementation and effectiveness
- Surveillance and recertification over the certification cycle
Exam trap: “External consultant conducting an internal audit on behalf of management” is still first-party in classification (on behalf of the organization). “Customer auditing supplier” is second-party. “Accredited CB certification audit” is third-party.
Internal vs Supplier vs Certification (Practical Mapping)
| Label in business language | Typical party type | Primary driver |
|---|---|---|
| Internal AIMS audit | First-party | Clause 9.2, management review, improvement |
| Supplier / AI vendor audit | Second-party | Contract, procurement, third-party risk (A.10) |
| Certification / surveillance audit | Third-party | Independent conformity assurance |
These labels help stakeholders, but exam answers should still use the first/second/third-party taxonomy when asked for classification.
Audit Objectives
Audit objectives define what the audit is intended to accomplish. They guide planning, resource needs, and conclusions. Objectives might include determining the extent of conformity of the AIMS (or parts of it) with audit criteria; evaluating capability to ensure compliance with legal and contractual requirements; evaluating effectiveness of the AIMS in meeting specified objectives; identifying opportunities for improvement; or evaluating AIMS suitability for certification.
AIMS examples of objectives:
- Determine conformity of the AIMS with ISO/IEC 42001:2023 for the defined scope
- Evaluate whether AI system impact assessment processes are implemented for high-risk systems
- Assess effectiveness of controls related to data for AI systems (Annex A.7) and third parties (Annex A.10)
- Verify readiness for Stage 2 following Stage 1 findings
Objectives should be realistic given time, access, and team competence. An objective of “prove zero bias in all models” is not an audit objective; determining whether bias-related controls and evaluations exist and operate is.
Audit Criteria
Audit criteria are the set of requirements used as a reference against which objective evidence is compared. Criteria may include applicable policies, procedures, standards, legal requirements, management-system requirements, contractual requirements, or codes of conduct.
For an ISO/IEC 42001 AIMS audit, criteria typically combine:
- ISO/IEC 42001 requirements (Clauses 4–10 and applicable Annex A controls as determined by the SoA)
- The organization’s own AIMS requirements (AI policy, processes, objectives, documented information)
- Statement of Applicability (SoA) — which Annex A controls are applicable/implemented and justifications for exclusions
- Other requirements — laws and regulations (e.g., sector AI rules), contracts with customers, internal codes, multi-standard integrated requirements (e.g., links to an ISMS)
Why the SoA matters: You do not audit “all 38 Annex A controls blindly.” You audit applicable controls as defined and justified in the SoA, plus mandatory Clause 4–10 requirements. Exclusions must be justified; unjustified exclusions become findings.
Exam trap: Audit criteria are not the same as audit evidence. Criteria = the rulebook. Evidence = what you collect to compare against the rulebook.
Audit Scope
Audit scope describes the extent and boundaries of the audit—physical locations, organizational units, activities, processes, AI systems, and the time period covered. Scope must be consistent with the audit program and objectives, and for certification it must align with the certified AIMS scope statement.
AIMS scope elements to define explicitly:
- Organizational units (e.g., Retail Banking AI Center of Excellence)
- Locations and remote delivery models
- AI systems / product lines included and excluded
- Lifecycle stages covered (design, development, deployment, monitoring, retirement)
- Interfaces with third-party model providers and data suppliers
- Period under review (especially for monitoring logs and change history)
Scenario: A global retailer claims AIMS certification for “all AI.” At Stage 1 the CB finds the documented scope only covers recommendation engines in one region, while hiring-screening AI in another region is live without impact assessments. Scope clarity is essential: either expand scope and readiness, or accurately limit the certificate—and still address legal/interested-party risks outside scope as context issues where relevant.
Audit Client vs Auditee
| Role | Meaning | AIMS example |
|---|---|---|
| Audit client | Organization or person requesting the audit | Company management requesting internal audit; CB’s certification client; customer requesting supplier audit |
| Auditee | Organization being audited | The legal entity (or defined units) whose AIMS is examined |
| Auditor / audit team | Person(s) conducting the audit | Internal auditors, CB auditors, customer auditors |
In first-party audits, the organization may be both client and auditee. In second-party audits, the customer is often the client and the supplier is the auditee. In third-party certification, the organization seeking certification is typically the client of the CB and also the auditee.
Exam trap: The person who greets you on site is not automatically the “audit client.” Client is defined by who commissions the audit relationship.
Audit Program vs Audit
| Concept | Definition | AIMS illustration |
|---|---|---|
| Audit program | Arrangements for a set of one or more audits planned for a specific time frame and directed toward a specific purpose | Annual internal AIMS audit program covering all in-scope processes; CB three-year certification cycle of Stage 1/2 + surveillance |
| Audit | Systematic, independent, documented process for obtaining evidence and evaluating it objectively to determine extent of criteria fulfillment | One Stage 2 AIMS audit conducted 12–16 June |
Program managers decide frequency, methods, resources, and risk-based prioritization across multiple audits. Lead Auditors execute individual audits within that framework (or, for a CB, within the CB’s certification scheme and ISO/IEC 17021-1 system).
ISO/IEC 17021-1 Relevance for Certification Bodies
ISO/IEC 17021-1 specifies principles and requirements for the competence, consistency, and impartiality of bodies providing audit and certification of management systems. It is not a substitute for ISO 19011, but it is the framework under which accredited CBs must operate when certifying systems such as an AIMS.
Implications for Lead Auditor candidates:
- Certification decisions must be impartial and based on objective evidence from audits
- CBs manage competence of audit teams (including AI/AIMS knowledge for ISO/IEC 42001 schemes)
- Consulting and certification conflicts are tightly controlled (cooling-off and separation of services)
- Multi-site, integrated, and transfer audits follow CB rules aligned with accreditation requirements
When exams mention certification-body obligations, impartiality committees, or competence management for third-party AIMS audits, think ISO/IEC 17021-1 (plus scheme-specific rules). When exams mention audit principles, planning, evidence, and conducting audits generically, think ISO 19011.
Putting Objectives, Scope, and Criteria Together
Worked mini-example:
- Type: Third-party Stage 2 certification audit
- Client: Fintech Co. (certification applicant)
- Auditee: Fintech Co. AI & Data division (as defined in scope)
- Objective: Evaluate implementation and effectiveness of the AIMS for conformity with ISO/IEC 42001 and suitability for certification recommendation
- Criteria: ISO/IEC 42001:2023; Fintech Co. AI policy and AIMS processes; current SoA; applicable credit-decision regulations referenced in legal register
- Scope: Automated credit underwriting AI systems in EU operations; development and production environments; period last 12 months of monitoring and change records; excludes experimental research lab models not deployed
With these locked, the audit plan, sampling, and report can stay consistent. Without them, findings become unarguable or unenforceable.
Exam Focus
Memorize the party taxonomy with AI vendor examples; define objectives / criteria / scope in one sentence each; distinguish client vs auditee; distinguish program vs audit; and map CB certification governance to ISO/IEC 17021-1 while mapping audit methodology to ISO 19011.
A large enterprise sends its AI governance team to audit a model-hosting SaaS supplier against contractual AI control requirements and selected ISO/IEC 42001 themes before onboarding. How is this audit best classified?
In an ISO/IEC 42001 certification audit, which set best represents typical audit criteria?
Which statement correctly distinguishes an audit program from an individual audit?
Why is ISO/IEC 17021-1 especially relevant to third-party AIMS certification audits?