The Readiness Review: Documents Auditors Ask For First

A readiness review is a preliminary assessment conducted before the formal Stage 1 audit begins. During this review, an auditor examines your existing documentation and control records to determine whether you are ready for a full audit. A readiness review takes one to three days depending on your organisation’s size and complexity. The purpose is to identify major gaps early so that you can address them before the formal audit, rather than discovering them when audit work is underway.
The auditor conducting the readiness review will request a list of all the documents you believe demonstrate compliance with ISO 42001:2023. This typically includes policies, procedures, training records, meeting minutes, incident logs, risk assessments and evidence of management review. The auditor reviews these documents to check whether they exist, whether they are current and whether they address the clauses in ISO 42001:2023.
Common documents that auditors expect to see include an AI governance policy or framework (addressing Clause 5.1), evidence of management review (Clause 6.2.1), the statement of applicability (Clause 6.1.1), risk assessments for AI systems (Clauses 5.15 and 5.19), records of roles and responsibilities (Clause 5.2), and training records for staff working with AI systems (Clause 5.3.2). If you operate systems that process personal data, the auditor will ask for data processing records (Clause 5.23). If you work with third-party AI suppliers, you will be asked for contracts or agreements that specify your control requirements (Clause 5.20).
The auditor also asks what systems you plan to include in scope. They will request evidence that these systems exist and operate in your organisation. They will ask whether any of these systems have been the subject of incidents or complaints. They will ask how you currently monitor system performance and whether you have processes for escalating problems or changing system configuration if performance drops below acceptable thresholds.
A readiness review is not a pass/fail gate. The auditor will produce a report highlighting gaps and recommendations but will not issue a certificate or formal findings. The report is intended to guide your preparation for the formal Stage 1 audit. If the readiness review reveals that you are missing critical documents (e.g., you have no documented policy on AI system oversight), you have time to draft that policy and test it before the formal audit begins.
What to Prepare for the Readiness Review
Preparation for a readiness review involves several steps. First, conduct an internal gap analysis by comparing your existing documentation against ISO 42001:2023. Create a spreadsheet listing each clause, what documentation you have that addresses it, and what gaps remain. This exercise often reveals that you have implemented controls but not documented them. For example, you might have annual management reviews but no formal procedure or record that says so. During the readiness review, the auditor will need to see evidence of these reviews.
Second, collect your evidence into a logical structure that an auditor can navigate. If you store evidence in shared drives, emails or various systems, prepare a summary document that tells the auditor where to find everything. A simple structure might be a folder for each clause, containing the relevant policies, procedures and records. When the auditor arrives, they should be able to locate a policy on third-party AI suppliers by opening one folder, rather than searching your entire company system.
Third, ensure that the evidence you provide is current and in force. If your AI governance policy was last updated two years ago and your organisation has since deployed new systems or changed its process, the policy is outdated. Auditors will flag outdated documentation as a finding. Similarly, if you claim to conduct annual management reviews but your last review was 18 months ago, that gap will be noted.
Fourth, prepare a summary of your AI systems. Document what each system does, who operates it, how it is monitored and what data it processes. This document becomes a reference during the audit. When the auditor is assessing whether your controls address your risks, they need to understand your system landscape.
During the readiness review meeting itself, the auditor will ask clarifying questions. They may ask “Who is the owner of this policy?” or “How do you know whether this control is operating effectively?” Take detailed notes during these conversations because the answers often reveal areas where you need to strengthen your documentation or evidence.
