ISO 42001Certification

Audit-ready vs certified: what Stage 1 and Stage 2 audits really check

"Are we certified yet?" is the wrong first question. Certification is the last mile. The milestone you control is audit-readiness — and knowing exactly what the two-stage audit examines is the difference between walking in prepared and walking in hopeful.

Two different finish lines

Audit-ready means your AI management system exists on paper and in practice: the policy is signed, the risks are scored, the controls are running, and you can produce evidence for each. Certified means an accredited certification body — not you, and not a consultant — has independently confirmed all of that and issued a certificate. You can be fully audit-ready for weeks before you book the audit. That gap is normal and, frankly, healthy: it's where you fix the things you'd rather an auditor didn't find.

Stage 1: the readiness review

The first stage is largely a documentation review. The auditor checks that your management system is designed correctly: Is there a defined scope? A top-management-approved policy? A risk process and a Statement of Applicability that maps to Annex A? Are objectives set and roles assigned? Stage 1 is where "governance theatre" gets exposed — a beautiful binder with no evidence that anyone uses it. The output is usually a list of gaps to close before Stage 2. Treat this stage as a gift: it tells you exactly where you stand while you can still act.

Stage 2: the evidence audit

Stage 2 is where readiness meets reality. The auditor samples your system and asks to see it working: show me the risk register and the treatment you actually did; show me the incident log; show me that the human-oversight step really happens; show me the record of your management review. This is why the honest advice is to run the system for a while before certifying — you cannot fabricate three months of operating evidence the night before. Findings are graded, and major nonconformities must be resolved before a certificate is issued.

What an auditor opens first

After years of watching this, the pattern is consistent. An auditor opens the policy (is leadership genuinely behind this?), then the Statement of Applicability (does the system map to the standard?), then the risk register (did you understand your exposure and act on it?). If those three are honest and evidenced, the rest of the audit is calmer. If they're thin, everything downstream is treated with suspicion. Build those three to a defensible standard and you've de-risked most of the audit.

The mindset shift. Don't aim to "pass an audit." Aim to run a system you could show anyone, any day. Audit-readiness is a property of how you operate, not a document you produce the week before. Get that right and certification becomes a formality rather than a scramble.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. ISO/IEC 42001 references current as of September 2026. Certification is performed by accredited bodies.