← Back to blog

How to audit an AI system: a step-by-step process

How to audit an AI system: a step-by-step process

Auditing an AI system is a defined process, not a vague review. This guide walks the whole sequence — from scoping and gathering evidence to testing, gap analysis and reporting. Part of our guide to the AI audit.

AramGRC Team·AI Audit & Assurance·September 11, 2026·9 min read

Before you start

Two decisions frame every AI audit: the scope (which system or systems, and which of their components) and the standard you'll audit against — ISO/IEC 42001, the EU AI Act's high-risk requirements, the NIST AI RMF, or your own AI policy. Fix both before you begin, because they determine what “good” looks like.

The AI audit process

  1. Scope and standard — define what's being audited and against which benchmark.
  2. Gather evidence — collect documentation, model cards, data lineage, test results, monitoring logs and governance records.
  3. Test and review — run bias and fairness testing, performance and robustness checks, and review the controls and human oversight around the system.
  4. Gap analysis — compare findings against the standard and rate the severity of each gap.
  5. Report and remediation — deliver a report with prioritised findings and a remediation roadmap.
  6. Attestation — where appropriate, issue an independent attestation the organisation can share.

What to test

An audit examines the system across dimensions: performance against intended use, bias and fairness across affected groups, data quality and lawful basis, robustness and security, explainability, human oversight, and the governance around it. Use the AI audit checklist to make sure nothing is missed.

Common findings

The gaps auditors see most often: no documented risk or impact assessment, training data with no lawful basis, bias never tested for, no monitoring for drift in production, unclear ownership, and no evidence trail. Most are governance failures, not model failures.

How the standard shapes the audit

The benchmark drives the work: an ISO/IEC 42001 audit focuses on the management system and Annex A controls; an EU AI Act audit focuses on the high-risk requirements and conformity. Structure it with an AI audit framework.

How AramGRC helps

AramGRC runs independent AI audits end to end — scoping, testing, gap analysis and an actionable report — against ISO/IEC 42001, the EU AI Act and your own policy.

Frequently asked questions

How do you audit an AI system?+

Define the scope and standard, gather evidence (data lineage, model cards, test results, governance records), test for bias, performance and robustness, analyse gaps against the standard, and report findings with a remediation roadmap.

What do you test in an AI audit?+

Performance, bias and fairness, data quality and lawful basis, robustness and security, explainability, human oversight, and governance.

What standard do you audit an AI system against?+

Commonly ISO/IEC 42001, the EU AI Act's high-risk requirements, the NIST AI RMF, or an internal AI policy — the choice defines the audit criteria.

How long does an AI audit take?+

It depends on scope and complexity — a single system against a defined standard is faster than an organisation-wide governance audit. A prior gap assessment shortens it.

AI AuditProcess
WhatsApp