How to prepare for an AI governance audit
A step-by-step guide to getting ready for an AI governance audit in Australia, anchored to ISO/IEC 42001 and the Voluntary AI Safety Standard.
How do you prepare for an AI governance audit?
An AI governance audit tests two things, whether the AI your organisation uses is governed and whether you can show it to someone outside the team that ran it. You get ready by confirming which AI systems are in scope, then showing that each has an owner, a recorded risk decision and the records that back them. This guide sets out how to do that, anchored to ISO/IEC 42001 and Australia's Voluntary AI Safety Standard. It is written for the person who has to answer for the framework, the chief risk officer, the chief audit executive, the CISO, the company secretary or the general counsel.
What an AI governance audit looks at
An AI governance audit is not an audit of the models. It looks at the management system around them, which means the scope of AI in use, who owns each system, how risk is assessed, what controls sit on top and the records that show all of it happened. ISO/IEC 42001 describes this as an AI management system, with requirements for documented information, internal audit and management review. A certification audit against that standard tests the same thing a board member, a regulator or an enterprise customer’s due-diligence team would ask to see, so preparing for one prepares you for the others.
Step 1: Confirm which AI systems are in scope
You cannot evidence governance over systems you have not listed, so the first thing an auditor asks for is the population. That means a current register of the AI systems in use, including the models embedded inside vendor software and the tools a team stood up without a formal decision. The systems that are missing from the register are the ones that undermine the audit, because a finding the auditor makes that you did not is the finding that costs you credibility. Reconcile the register against what is actually running before the audit starts, not during it.
Step 2: Show each system has an owner and a recorded risk decision
Guardrail 1 of the Voluntary AI Safety Standard asks you to establish and publish an accountability process for governing AI. Naming a person answerable for each system is how that accountability holds in practice. An auditor reads ownership as the first control, because a system no one owns has no one to answer for its risk. For each material system, show the named owner and the risk decision behind it, meaning that someone assessed the system, understood what could go wrong and decided the use was acceptable on the record. An assessment with no owner is a document, not a control, and an auditor treats it that way.
Step 3: Assemble the records behind each control
Guardrail 9 asks you to keep and maintain records that allow third parties to assess compliance. That is the guardrail an audit lives on. For each control you claim, hold the record that shows it operated, whether that is the impact assessment for a high-risk system, the approval line for an autonomous agent or the monitoring log for a deployed model. The records have to be the ones captured when the work happened and attributed to the people who did it, because a record reconstructed the week before the audit answers a weaker question than one that was there all along.
Step 4: Make the evidence verifiable, not just present
An auditor weighs whether a record exists and whether it is the record it claims to be. A document that could have been edited the night before carries less weight than one that can be shown unchanged since the date on it. This is where most governance evidence is thin, because a file in a shared drive proves its contents but not its history. Records that a third party can confirm have not changed since capture move the burden off your word and onto the record, which is what an auditor is looking for.
Step 5: Close the loop on incidents and reviews
Guardrail 4 asks you to monitor AI systems once they are deployed and to test them over their life, not only at the start. An auditor checks that the reviews actually happened and that when something went wrong you recorded it and acted. Show the review cadence for each material system, the dates reviews were done and the incidents you logged with what you did about them. A framework with no incidents recorded reads as one that is not watching, not one that has never had a problem.
What auditors most often find
- Shadow systems running in the business that never reached the register.
- Owners named on paper but no risk decision recorded behind them.
- Assessments done once at procurement and never revisited as the system changed.
- Records that exist but cannot be dated or shown unchanged since capture.
- Incidents handled in a corridor conversation and never written down.
Frequently asked questions
Who runs an AI governance audit? It can be your own internal audit function, an external assurance provider engaged to give an opinion or a certification body auditing you against ISO/IEC 42001. The preparation is the same for all three, because each is testing whether the governance is real and evidenced.
Is ISO/IEC 42001 mandatory in Australia? No. ISO/IEC 42001 is a voluntary certifiable standard, and the Voluntary AI Safety Standard is guidance rather than law. Organisations pursue them because boards, regulators and enterprise customers increasingly ask to see governance measured against a recognised reference.
How far back should records go? Far enough to show each material system has been governed across its life, not only at a point in time. That usually means the original assessment, every review since and everything logged in between.
Does Aicura certify or pass the audit for you? No. Aicura surfaces the picture and holds the evidence. It does not audit your systems, certify them or decide whether you pass. The accountable owner answers for the framework and the auditor forms the opinion.
Where Aicura fits
Aicura is your AI Register. It holds the AI systems in use as the record, versions each one as it changes and prompts you when a review is due, so the population an auditor asks for is current rather than reconstructed. Impact Assessments carry the risk work for the systems that warrant it and sit against each system as the record of the decision and its owner. Incidents give you the place to log when something went wrong and what you did, so the trail reflects how the systems actually behaved.
The Evidence Vault seals each record so it can be shown unchanged since capture, evidence you don’t have to trust us for, cryptographically anchored and verifiable without Aicura in the loop. The Trust Centre lets you share that evidence with the auditor directly, and Attestation lets an accountable owner sign a statement against the record. Aicura surfaces the picture and holds the evidence. It does not run the audit, certify your systems or decide whether you pass. You make the calls and the auditor forms the opinion.
If you are weighing tooling for this, the AI governance software overview sets out what Aicura supports. For the related work, read how to respond to an AI governance due-diligence questionnaire and how to keep AI governance records that stand up.
Sources
- Voluntary AI Safety Standard, Department of Industry, Science and Resources, industry.gov.au/publications/voluntary-ai-safety-standard
- ISO/IEC 42001:2023, AI management system, International Organization for Standardization, iso.org
- AI Risk Management Framework (AI RMF 1.0), National Institute of Standards and Technology, nist.gov/itl/ai-risk-management-framework
A note on this page
This guide is general information on how to prepare for an AI governance audit against current Australian and allied guidance. It is not legal advice and it does not tell you whether a particular system or framework meets a particular obligation. For how the guidance applies to your organisation, read the primary sources above and take your own professional advice.
When you need to show your work
Aicura is your AI Register, and Pro adds the assurance layer, meaning impact assessments, incident records, attestation and the Evidence Vault, which seals each record so it can be verified without taking anyone's word for it, ours included. Pro is sales-led, so the best next step is a conversation and a walkthrough.