Stage 1: Documentation Review and Readiness Findings

Stage 1 is the formal documentation audit. During Stage 1, the auditor spends one to three days reviewing your documented information against the requirements of ISO 42001:2023. The auditor examines whether your policies are in place, whether procedures are documented, whether your statement of applicability is complete and whether your documentation addresses each clause of the standard.
Stage 1 is called a documentation review because the auditor focuses on what you have written, not yet on whether those controls actually work in practice. The auditor is checking whether you have documented a process for selecting and monitoring third-party AI suppliers (Clause 5.20) but will not yet test whether you actually follow that process. That testing happens during Stage 2. This distinction is important because it means you should complete Stage 1 with documented policies and procedures in place, but you do not yet need to have operated those controls for months to generate a history of evidence.
During Stage 1, the auditor will hold a meeting with your management team. This meeting typically covers the scope of certification, your organisation’s AI strategy, your risk environment and your approach to compliance. The auditor will present their findings as they work through the standard. If the auditor identifies a gap in your documentation, they will discuss it with you in real time. This allows you to clarify misunderstandings (e.g., “We do have a policy on this, it is just called something different than you expected”) and to take notes on what needs to be addressed.
At the end of Stage 1, the auditor produces a report listing findings in two categories: non-conformities and observations. A non-conformity is a failure to meet a requirement of the standard. It might be a missing policy, an incomplete procedure or a scope that does not match your actual operations. A non-conformity must be closed before Stage 2 can proceed. An observation is a suggestion for improvement but not a mandatory issue. Observations might include recommendations to document an informal practice, to clarify a procedure or to strengthen evidence.
Common Stage 1 Findings
The most common Stage 1 non-conformities relate to the statement of applicability (Clause 6.1.1). The statement of applicability is a table listing all the clauses in ISO 42001:2023 and indicating whether each clause is applicable to your organisation. If a clause is not applicable, you must provide justification. For example, if you do not process personal data, Clause 5.23 may not apply, but you must explain why.
Another common finding involves roles and responsibilities (Clause 5.2). Many organisations have AI teams but have not formally documented who is accountable for each control objective. The auditor will ask for an organisational chart or a responsibility matrix that names individuals and their specific duties related to AI management.
Training and awareness (Clause 5.3.2) is frequently cited as a non-conformity. Organisations often conduct training but do not retain records showing who attended, what was covered or whether the training was effective. The auditor needs to see a training schedule, attendance records and evidence that the training content addresses ISO 42001:2023 requirements or organisational policy.
Risk assessment (Clause 5.15) is another area where organisations often fall short. Many organisations have risk registers or risk assessments but have not specifically documented their approach to assessing impacts of AI systems on individuals and society. The auditor will expect to see a documented methodology for assessing AI risks and evidence that this methodology has been applied to the systems in your scope.
If the auditor finds non-conformities during Stage 1, you will receive a grace period to address them before Stage 2 begins. Typical timelines allow 30 to 90 days to close Stage 1 findings, depending on the certification body’s policy. You must provide evidence that you have corrected each non-conformity. If you were missing a policy, you must provide the policy. If the policy is new, you must explain how you ensured staff awareness of it. The auditor will review your responses to determine whether the non-conformities have been genuinely closed.
Most organisations use the Stage 1 to Stage 2 gap as an opportunity to pilot new controls or to test documentation with a sample of staff. This pilot period helps identify practical issues before Stage 2 testing, when the auditor will verify that controls actually work in operational conditions.
