The Lead Auditor gets the attention, but the internal auditor does the audit no organization can avoid. That is the fact most guides bury, and it is where this one begins.

Every organization certified to ISO/IEC 42001:2023, the AI management system standard, is required to audit itself before anyone else does. The person who carries out that first-party audit is the internal auditor, and the credential that prepares them is the internal auditor certification.

So while the Lead Auditor credential is optional to any single company, the internal audit function is not. The standard demands it, which makes the internal auditor quietly one of the most necessary roles in the whole system.

This guide from the AI Governance Certification Institute (AIGCI) explains what an ISO 42001 internal auditor does, why the standard requires the role, how it differs from the Lead Auditor, and who should hold the certification.

"Know thyself."

The maxim inscribed at the Temple of Apollo at Delphi

The ancient instruction is the essence of internal audit. Before an external auditor judges an organization, the organization must first honestly examine itself, and the internal auditor is the person who makes that self-knowledge real rather than assumed.

What an ISO 42001 internal auditor actually does

An internal auditor conducts first-party audits, meaning they audit their own organization's AI management system against the standard. They plan the audit, gather evidence, test whether controls work, and report what they find, following the audit discipline set out in ISO 19011.

The purpose is not to award a certificate. It is to give the organization an honest picture of its own AIMS: what conforms, what does not, and what must be fixed. The internal auditor is the organization's own inspector, not an outside judge.

Those findings then feed the wider system. Nonconformities lead to corrective action, and the results inform the management review where leadership decides what to do next. Internal audit is the sensing mechanism that keeps the whole system honest between external visits.

Why the standard requires the role

This is the point that reframes everything. ISO 42001 does not merely permit internal audit; it requires it. Under the standard's performance-evaluation clause, an organization must conduct internal audits at planned intervals to check that its AI management system conforms and is effectively maintained.

That single requirement changes how you should see the role. A company can be certified without ever employing a Lead Auditor of its own, because the certification audit is done by an external body. But no company can be certified without internal audits happening, because the standard makes them mandatory.

In other words, the internal auditor performs the one audit the standard itself insists upon. Far from being the junior version of a Lead Auditor, it is the audit every certified organization must have, year after year.

Internal auditor and Lead auditor: the real difference

The two roles are often confused, yet they sit on opposite sides of the same fence. The clearest way to see it is side by side:

Attribute

Internal auditor

Lead auditor

Whose system they audit

Their own organization's AIMS

Other organizations' systems

Party

First party, from inside

Third party, from outside

Purpose

Find and fix issues, and satisfy the standard's internal-audit requirement

Decide whether an organization earns or keeps its certificate

Required or optional

Required of every certified organization

Needed by certification bodies and consultants

Typical setting

In-house audit, risk, or governance function

A certification body or a consultancy

The deeper distinction is one of independence, and it is worth understanding fully. The mechanics of first-party versus third-party auditing are covered in first-party vs third-party audit, so this guide stays on the role rather than repeating the audit theory.

The independence rule inside your own house

An obvious objection arises: if you audit your own organization, how can the audit be objective? The standard anticipates exactly this, and its answer is precise.

An internal auditor must be independent of the work they audit. You may audit your organization, but not the parts of the AI management system you are personally responsible for running. The auditor and the audited activity have to be different people.

This is objectivity within the organization rather than independence from it. It is a subtler discipline than external auditing, because the internal auditor knows the people and the politics, and must still report uncomfortable findings honestly. Learning to hold that line is a real part of what the certification teaches.

Why certification is won or lost in internal audit

Here is the insight experienced practitioners understand and newcomers often miss. The external certification audit is rarely where problems are first discovered; it is where they are confirmed or absent.

A strong internal audit function finds the nonconformities first, while there is still time to fix them. By the time the external auditor arrives, a well-audited organization has already corrected what a weak one is about to be caught on.

That makes internal audit the dress rehearsal that decides the performance. It is also why internal auditors must genuinely understand AI-specific risk, from bias to model drift, using frameworks such as the NIST AI Risk Management Framework to know what to look for. An internal auditor who only checks paperwork will pass problems straight through to the external audit.

What the internal auditor certification teaches you

The certification is practical, because the role is. It builds a specific set of capabilities rather than abstract knowledge.

You learn to plan an audit against ISO 42001, to gather and weigh evidence rather than accept assurances, to hold objectivity even among colleagues you know well, and to write findings that lead to action rather than argument. You also learn to recognise AI-specific risks, from bias to model drift, that a general auditor might overlook.

These are the skills that turn a required internal audit from a box-ticking ritual into a genuine safeguard, which is the whole reason the standard asks for one in the first place.

Who should get the internal auditor certification

The credential suits people whose job is to keep their own organization's AI governance honest. The most common are:

  • Internal audit, risk, and compliance staff who will run or support AIMS internal audits.

  • Quality and governance managers in organizations pursuing or maintaining ISO 42001 certification.

  • Lead Implementers who want to check systems they did not personally build, staying within the independence rule.

  • Professionals testing the waters of AI auditing who want a lower-stakes entry before external certification work.

If your organization is on the certification path, someone in it must be able to run these audits. That someone is exactly who this certification is for.

Common internal-audit mistakes to avoid

A few recurring errors weaken internal audits and let problems slip through to the external one:

  • Auditing only documents, not whether the controls actually work in practice.

  • Letting familiarity soften findings, so uncomfortable issues go quietly unreported.

  • Auditing your own work, which the standard forbids and which destroys objectivity.

  • Treating the audit as an annual formality rather than a genuine health check of the system.

Each of these is avoidable, and avoiding them is exactly what separates an internal audit that protects the organization from one that merely satisfies a clause.

Internal auditor or Lead auditor: which should you choose?

The choice is less about seniority than about where you intend to work.

Choose the internal auditor route if you will audit your own organization's AI management system, whether to prepare for certification or to maintain it. Choose the Lead Auditor route if you will audit other organizations for a certification body, or advise clients as a consultant, which is set out in the Lead Auditor path.

Neither is a lesser version of the other. They serve different masters: the internal auditor serves the organization's own improvement, and the Lead Auditor serves the credibility of the certificate itself.

Where the internal auditor credential leads

An internal auditor certification is a strong position in its own right, and it is also a natural stepping stone. Much of the judgement it builds transfers directly to external auditing.

Auditors who start inside their own organization often move toward the Lead Auditor role later, carrying real audit experience with them. Starting internal lets you build that judgement where the stakes are lower and the context is familiar, which is a sensible way to grow into AI assurance rather than leaping into it.

How internal audit fits the certification cycle

It helps to see where the internal auditor sits across the life of a certified system, because the role is far from a one-off.

Internal audits run before the first external certification audit, to catch problems while there is still time, and then continue at planned intervals for as long as the organization holds the certificate. They also feed the surveillance audits that keep certification alive between full assessments.

That recurring role matters more as regulation tightens. As the EU AI Act pushes organizations to demonstrate ongoing AI governance rather than a one-time effort, the internal auditor becomes the person who keeps the evidence current between external visits.

The bottom line

The ISO 42001 internal auditor runs the audit the standard requires, making the role indispensable to every certified organization rather than optional. It is the audit a company performs on itself, and it is where certification is quietly won.

If your organization is pursuing or holding ISO 42001, someone must be able to look it honestly in the mirror. The internal auditor certification is how they learn to do that well, and it is a foundation for a longer career in AI assurance.

Frequently asked questions

What does an ISO 42001 internal auditor do?

An internal auditor conducts first-party audits of their own organization's AI management system, checking whether it conforms to ISO 42001 and works in practice. They report findings that lead to corrective action and inform management review, rather than awarding any certificate.

Is internal audit required by ISO 42001?

Yes. The standard requires organizations to conduct internal audits at planned intervals to confirm the AI management system conforms and is effectively maintained. This makes the internal audit function mandatory for any certified organization, unlike an in-house Lead Auditor, which is optional.

How is an internal auditor different from a Lead Auditor?

An internal auditor audits their own organization from the inside as a first party, to find and fix issues. A Lead Auditor audits other organizations from the outside as a third party, to decide whether they earn or keep certification. The difference is one of independence and purpose, not seniority.

Can I audit my own work as an internal auditor?

No. The standard requires objectivity, so you may audit your organization but not the parts of the AI management system you are personally responsible for running. The auditor and the audited activity must be different, which preserves fairness within the organization.

Should I take the internal auditor or Lead Auditor certification first?

It depends on your goal. If you will audit your own organization, start with the internal auditor certification. If you will audit others for a certification body or as a consultant, the Lead Auditor route fits. Many people begin internally to build judgement before moving to external work.

Learn to audit your own AI management system

If your organization is on the ISO 42001 path, it needs someone who can run its internal audits well. AIGCI's Internal Auditor certification prepares you to conduct first-party audits with real objectivity, and it is a natural first step toward the Lead Auditor certification if you later move to external work. To compare every option, see all the ISO 42001 courses, and to learn how the institute designs them, read more about the institute.