An audit and review cycle that tests how AI decisions operate, not just whether templates exist.
Set a scope that can be sampled
Start with the approved AI management system scope and the current AI inventory. Identify the important processes: intake, risk and impact assessment, supplier approval, development or acquisition, testing, release, monitoring, incident handling, and corrective action. Build an audit schedule around risk and change, not equal attention to every low-impact use.
Internal auditors should be able to examine decisions without reviewing their own work. Where a small organization has limited separation, document the safeguard used to preserve objective review.
Follow one use from intake to operation
Choose sample AI systems and trace their records end to end. Can a reviewer find the purpose, owner, data and supplier dependencies, impact assessment, selected controls, test results, approval, monitoring, and any exceptions? Does the live use still match what was approved?
Interview the people who actually operate the process. Compare a policy's stated review trigger with a real model or feature change. The gap between documented procedure and ordinary work is often the most useful finding.
Separate findings from improvement ideas
Record the requirement or internal commitment being tested, evidence seen, and why it supports the finding. Give each nonconformity an owner, cause analysis, correction, and effectiveness check. Keep improvement suggestions distinct from failures to meet a defined requirement.
Where a certification body is later engaged, it will make its own independent assessment and decision. Internal audit should prepare the organization to understand its system, not simulate or promise a certificate.
Give leadership a decision brief
Management review should bring together audit results, AI objectives, incidents, risk trends, supplier changes, feedback, resource needs, and open actions. Ask which uses should continue, change, or stop and whether the AIMS scope still reflects the business. Record decisions, resources, owners, and follow-up dates.
The next cycle should verify that those decisions happened. A management review that ends in minutes without accountable action will add little to AI risk control.
Put it into practice
- Select audit samples from the live AI inventory and recent changes.
- Trace evidence through actual deployment and monitoring decisions.
- Assign causes, corrections, and effectiveness checks to findings.
- Record leadership decisions and verify follow-through.
Primary sources
Normstone resources are general information, not legal advice or an independent assessment.