Audit-ready vs certified: what Stage 1 and Stage 2 audits really check
"Are we certified yet?" is the wrong first question. Certification is the last mile. The milestone you control is audit-readiness — and knowing exactly what the two-stage audit examines is the difference between walking in prepared and walking in hopeful.
Two different finish lines
Audit-ready means your AI management system exists on paper and in practice: the policy is signed, the risks are scored, the controls are running, and you can produce evidence for each. Certified means an accredited certification body — not you, and not a consultant — has independently confirmed all of that and issued a certificate. You can be fully audit-ready for weeks before you book the audit. That gap is normal and, frankly, healthy: it's where you fix the things you'd rather an auditor didn't find.
Stage 1: the readiness review
The first stage is largely a documentation review. The auditor checks that your management system is designed correctly: Is there a defined scope? A top-management-approved policy? A risk process and a Statement of Applicability that maps to Annex A? Are objectives set and roles assigned? Stage 1 is where "governance theatre" gets exposed — a beautiful binder with no evidence that anyone uses it. The output is usually a list of gaps to close before Stage 2. Treat this stage as a gift: it tells you exactly where you stand while you can still act.
Stage 2: the evidence audit
Stage 2 is where readiness meets reality. The auditor samples your system and asks to see it working: show me the risk register and the treatment you actually did; show me the incident log; show me that the human-oversight step really happens; show me the record of your management review. This is why the honest advice is to run the system for a while before certifying — you cannot fabricate three months of operating evidence the night before. Findings are graded, and major nonconformities must be resolved before a certificate is issued.
What an auditor opens first
After years of watching this, the pattern is consistent. An auditor opens the policy (is leadership genuinely behind this?), then the Statement of Applicability (does the system map to the standard?), then the risk register (did you understand your exposure and act on it?). If those three are honest and evidenced, the rest of the audit is calmer. If they're thin, everything downstream is treated with suspicion. Build those three to a defensible standard and you've de-risked most of the audit.
Managed adds review checkpoints and an accredited-body introduction →
Educational orientation, not legal advice. ISO/IEC 42001 references current as of September 2026. Certification is performed by accredited bodies.