Building a Risk Based Annual Audit Programme

A risk-based audit programme focuses audit effort where it matters most. This approach is efficient and credible. Instead of auditing every system equally or auditing nothing until the certification body arrives, you assess which AI systems and controls pose the greatest risk, then schedule audits to address those risks over a 12-month cycle. Risk-based prioritisation is expected by certification auditors and shows management commitment to evidence-based governance.

The first step is to list every AI system within your audit scope. This inventory was built during implementation and should be updated quarterly. For each system, document its name, purpose, deployment environment (production, pilot, development), users, and owner. A financial services firm might list a fraud detection AI, a customer propensity model, a chatbot for account inquiries and several experimental systems. A healthcare provider might list diagnostic AI, treatment recommendation systems, and administrative workflow automation. Maintaining an accurate inventory is itself a control; without it, systems can drift into production unmonitored.

The second step is to rate each system for risk. Risk depends on consequence and likelihood. A consequence assessment asks: if this AI system fails, what happens? Can it cause financial loss, bodily harm, discrimination, or operational disruption? An AI system that recommends employment decisions carries higher consequence than an AI system that recommends product bundles. Likelihood assessment asks: given the system’s design and operational controls, how probable is failure? An AI system running on poorly validated data in an unmonitored production environment has higher likelihood of undetected failure than a system with strong data governance and weekly performance checks. When consequence and likelihood are both high, risk is high.

Combine consequence and likelihood into a risk rating: high, medium or low. This exercise is not theoretical. It forces your team to think explicitly about what could go wrong and whether controls are adequate. A high-risk system requires annual audit. A medium-risk system might be audited every 18 months. A low-risk system could be audited every two years or included in a snapshot audit of multiple systems. Risk ratings should be reviewed and revised at least annually as systems and controls evolve.

Lesson concept diagram

The third step is to map the audit programme to control areas. Clauses 4 to 10 of ISO 42001 define control areas: context and scope (Clause 4), leadership and policy (Clause 5), risk and impact assessment (Clause 6), competence and awareness (Clause 7), operational controls (Clause 8), monitoring and internal audit (Clause 9), and nonconformity and improvement (Clause 10). Annex A adds specific controls for AI systems, data, models and suppliers. Your audit programme should ensure that each clause and each control relevant to your scope is audited at least once per certification cycle. If you audit only high-risk systems every 12 months, when do you audit leadership processes or competence? Build a matrix: list clauses and controls down the left, list months across the top, then assign audit activities so coverage is even. This matrix becomes your communication tool to show management that oversight is systematic.

The fourth step is to assign auditors. Internal auditors may rotate to build broader organisational knowledge. A data scientist might audit operational controls one year and supplier due diligence the next. A compliance officer might audit policy and governance one year and corrective action tracking the next. Rotation prevents stagnation and reduces the risk that one person becomes a single point of failure for audit credibility. Rotation also builds audit capability across the organisation, creating resilience.

Finally, document the audit programme and share it with management. The programme should be visible so that departments know when audits are coming and can prepare. Advance notice allows auditees to gather evidence proactively rather than scrambling when the auditor arrives. A visible audit programme demonstrates management commitment and allows teams to plan their calendars.

A risk-based audit programme is also flexible. If a system fails, an audit in the high-risk category may be scheduled early. If an area has no findings for two years, the audit frequency might be reduced. If a team changes and new people lack experience, audit frequency might increase. A static programme that never changes regardless of experience becomes irrelevant. The best programmes are reviewed quarterly and adjusted based on what audits reveal about organisational maturity and risk.