ISO 42001Clause 9–10

Management review and continual improvement: keeping certification, not just getting it

Most teams aim at the certificate and stop thinking past it. But a certificate is a snapshot; the standard is about a system that keeps improving. Clauses 9 and 10 — performance evaluation, internal audit, management review and improvement — are the machinery that keeps your AIMS alive, and the part surveillance audits check hardest.

Performance evaluation: are your objectives being met?

Clause 9 asks you to actually measure how your management system is doing against the objectives you set. That means monitoring the right things — not vanity metrics, but indicators that tell you whether your controls work and your risks are trending the right way. The discipline is choosing a small number of meaningful measures and reviewing them, rather than collecting data no one looks at.

Internal audit: catch it before the auditor does

An internal audit is you checking your own system against the standard, before the certification body does. It's not a formality — done honestly, it surfaces the gaps you'd rather find yourself. The value is cultural as much as technical: a team that audits itself is a team that treats governance as ongoing work, and that shows in every other part of the system.

Management review: leadership, on the record

The management review is where top management looks at how the AIMS is performing — audit results, incidents, risk changes, objective progress — and makes decisions: resource it more, change direction, accept or escalate risks. This is the single clearest piece of evidence that leadership is genuinely engaged, which is exactly what an auditor probed in your policy. A dated, minuted review closes that loop.

Continual improvement: the point of the whole thing

Clause 10 turns findings into action. Nonconformities get corrected, root causes get addressed, and the system gets better over time. Surveillance audits (between full recertifications) exist precisely to check this heartbeat. A system that got certified and then froze will show it — the absence of improvement is itself a finding.

Why the rules move, not just you

There's an external reason this matters for AI specifically: the ground shifts. New EU AI Act guidance, new deadlines, new expectations from buyers. A static system decays against a moving standard. Continual improvement is how you stay current — which is also why ongoing monitoring, not one-time readiness, is the honest model for AI governance.

The mindset. Certification is a photograph; the standard is a film. Build the review-and-improve loop as a genuine habit and surveillance audits become routine — skip it, and your certificate quietly stops reflecting reality.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. ISO/IEC 42001 references current as of September 2026. Certification is performed by accredited bodies.