11.3 Document Review & Stage 1 Readiness
Key Takeaways
- Stage 1 in management-system certification evaluates documented information, site/context understanding, and readiness for Stage 2—not full operational effectiveness of every AI control.
- AIMS document review prioritizes scope, AI policy, risk and impact-assessment methodology and results, Statement of Applicability, key procedures, and evidence of internal audit and management review maturity.
- Stage 1 outputs include readiness conclusions, areas of concern, focus areas for Stage 2 sampling (high-risk AI systems, weak SoA justifications, lifecycle interfaces), and agreement on logistics.
- Common AIMS Stage 1 findings include immature or missing AI system impact assessments, incomplete SoA justifications, inventory that does not match claimed scope, and internal audit programs that never sampled AI lifecycle processes.
- If critical design elements are missing, Stage 2 should be postponed; forcing Stage 2 on an unready AIMS produces chaos, not better assurance.
11.3 Document Review & Stage 1 Readiness
Quick Answer: For third-party management system certification, Stage 1 is the readiness and design gate. You review AIMS documented information, understand the organization’s AI context and sites, and decide whether Stage 2 (implementation and effectiveness) can proceed. You are not yet proving every model’s fairness in production—but you are judging whether the system exists on paper and in structure well enough to audit. ISO/IEC 17021-1 frames Stage 1; ISO 19011 still guides how you gather and evaluate information.
Internal auditors may perform an analogous document review before fieldwork even without a formal “Stage 1” label. Certification language is still the exam’s default model—know it and map it to internal practice.
Purpose of Stage 1 for Management System Certification
Stage 1 is designed to:
- Review the client’s management system documented information against the standard
- Evaluate the client’s site-specific conditions and readiness for Stage 2
- Review the client’s understanding of the standard’s requirements
- Obtain information on scope, processes, regulatory context, and multi-site issues
- Plan Stage 2 by identifying focus areas and confirming logistics and resources
- Provide a focus for planning Stage 2 by gaining sufficient understanding of the system and operations
STAGE 1 (design / readiness) STAGE 2 (implementation / effectiveness)
+---------------------------+ +--------------------------------------+
| Documented AIMS | | Operating processes & records |
| Scope, policy, SoA | ---> | Interviews, observation, sampling |
| Methods & planning | | AI artifacts in real use |
| Internal audit / MR status| | Conformity & effectiveness judgment |
+---------------------------+ +--------------------------------------+
What Stage 1 is not: a substitute for Stage 2, a certificate decision, or a consulting redesign of the client’s models. Findings from Stage 1 often appear as areas of concern that must be resolved before or during Stage 2; major design voids justify postponement.
Document Review of AIMS Documented Information
Work from the agreed criteria. A practical AIMS Stage 1 document pack includes:
| Document / record family | What the auditor looks for |
|---|---|
| AIMS scope | Clear boundaries of AI systems, units, locations; interfaces and exclusions |
| AI policy | Appropriate to purpose; includes commitments expected by ISO/IEC 42001; available and maintained |
| Context & interested parties | External/internal issues; AI-related party needs (users, regulators, customers, affected persons) |
| Risk & opportunity process | Methodology, criteria, recent results covering AI systems in scope |
| AI system impact assessment (6.1.4 thinking) | Method, triggers, coverage of systems, linkage to risk treatment and controls |
| AI objectives & plans | Measurable objectives aligned to policy; plans and resources |
| Statement of Applicability | Control status; implementation status; exclusions with real justifications |
| Operational planning & lifecycle procedures | How design, data, deployment, monitoring, and change are controlled |
| Competence & awareness | Role definitions for AI governance, development, oversight |
| Internal audit program & results | Coverage of AIMS processes; independence; nonconformity handling |
| Management review | Inputs/outputs including AI performance, incidents, improvements |
| Prior external reports / incidents | Open issues that Stage 2 must re-check |
Stage 1 rewards substance: a glossy ethics brochure without SoA or impact method is weaker than concise controlled procedures covering Clauses 4–10 and selected Annex A controls. Check control of documents, real implementation (not restatement), clear interfaces (who runs impact assessment before deployment), and inventory–scope match. Remote document review is fine when secure; use on-site/hybrid Stage 1 when multi-site MLOps or AIMS–engineering disconnects need observation.
Evaluating Readiness for Stage 2
Readiness is a professional judgment, not a single checkbox. Typical must-be-true signals before Stage 2:
- Scope is defined and stable enough to audit
- Policy and mandatory planning processes exist (risk, impact, objectives)
- SoA exists with justifications, not a blank template
- The AIMS has been operated long enough to produce records (not only drafts dated last night)
- Internal audit and management review have been conducted in a way that covers the AIMS (or integrated system) with meaningful outputs
- Key process owners are identifiable and available
| Readiness outcome | Meaning |
|---|---|
| Ready | Proceed to Stage 2 on agreed dates; note focus areas |
| Ready with concerns | Proceed only if concerns are addressable; may need extra Stage 2 time |
| Not ready | Postpone Stage 2; list required actions; avoid fake “partial Stage 2” |
Scenario: Stage 1 finds a solid AI policy and risk procedure, but zero completed impact assessments for two high-impact clinical decision systems already in production, and an SoA that marks A.5 controls “implemented” with no records. Conclusion: not ready for a full Stage 2 effectiveness audit of those controls. Document concerns; reschedule after evidence exists.
Identifying Focus Areas for Stage 2
Stage 1 should leave a risk-based Stage 2 plan, not a uniform clause walkthrough. Typical AIMS focus signals:
- High-impact AI systems — safety, rights, financial, medical, employment decisions
- Weak design points — impact assessments, data quality controls, human oversight design
- Third-party / foundation model dependencies — supplier controls and transparency gaps
- Change and retraining — models that update frequently without change control evidence
- SoA anomalies — controls marked N/A without logic; “implemented” without procedure owners
- Integration seams — AIMS claims to lean on ISMS controls that were never extended to AI-specific risks
- Multi-site inconsistency — central policy, local shadow deployments
Capture focus areas in the Stage 1 report and feed them into Stage 2 planning and sampling.
Common Stage 1 Findings for AIMS
| Finding pattern | Why it matters | Typical Stage 1 handling |
|---|---|---|
| Immature impact assessments | Design gap for AI harms / affected parties | Concern; block Stage 2 if high-impact production systems lack method/results |
| Incomplete SoA justifications | Applicable control criteria unclear | Complete SoA before Annex A sampling at Stage 2 |
| Scope ≠ inventory | Certificate and sampling risk | Align inventory and scope statement |
| Policy without procedures | Leadership text only | Concern on Clause 8 operational readiness |
| No AIMS internal audit / weak MR | System not self-checked or leadership not reviewing AI performance | Common postponement drivers |
| Invisible third-party AI | Uncontrolled external models | Focus A.10 design; Stage 2 supplier sampling |
| ISMS docs renamed “AIMS” | Superficial integration | Test whether AI-specific requirements are addressed |
A useful Stage 1 report confirms objectives/scope/criteria, lists documents reviewed, states areas of concern, readiness conclusion and Stage 2 timing, logistics, and competence needs. Do not pretend Stage 2 effectiveness was already tested—but state design voids firmly enough that commercial pressure cannot force a premature Stage 2. Convert conclusions into the plan, team, and working documents next.
What is the primary purpose of Stage 1 in an ISO/IEC 42001 management system certification audit?
Which pair is among the most common AIMS-specific Stage 1 concerns?
Stage 1 review shows no AIMS internal audit and no management review have ever been completed, though draft policies exist. How should the Lead Auditor typically treat Stage 2 timing?
How should Stage 1 outcomes influence Stage 2 for a multi-model AIMS?