Internal audits must occur at planned intervals and determine whether the AIMS conforms both to the organisation's own requirements and to ISO/IEC 42001, and whether it is effectively implemented and maintained. The audit programme must define frequency, methods, responsibilities, planning, reporting, and the objectives, criteria, and scope of each audit. Auditors must be selected and audits conducted to preserve objectivity and impartiality.
Top management must review the AIMS at planned intervals. Inputs include earlier actions, changes in context and interested-party needs, trends in nonconformities, corrective actions, monitoring, measurement, and audit results, plus opportunities for improvement. The review must produce decisions on improvement opportunities and needed AIMS changes.
Use representative operating samples across the scope. A policy's existence does not show that risk assessments, impact assessments, supplier controls, monitoring, incident handling, or corrective actions work.