How to Conduct an AI Act Internal Audit: A Practical Step-by-Step Methodology
Before regulators audit you, you should audit yourself. An AI Act internal audit gives you early warning of compliance gaps and creates a documented track record of good-faith compliance efforts.
The Case for Internal Auditing
An organization with documented internal audit results — even ones that identified and corrected problems — is in a fundamentally better position than one that never looked. Internal AI Act audits identify compliance gaps before they become regulatory findings, create documentation of your compliance journey, demonstrate good faith to regulators, and improve AI governance processes.
The Six-Phase Internal Audit Methodology
Phase 1 — AI Inventory and Scope Definition: Build or update your complete AI system inventory. For each system, document: use case, provider (internal/third-party), users, affected persons, data inputs/outputs, decisions influenced, and initial risk classification. Prioritize high-risk systems and those with significant impact on individuals' rights. Phase 2 — Documentation Review: Collect and assess technical documentation, risk management records, data governance documentation, instructions for use, post-market monitoring logs, and the Declaration of Conformity. Document all gaps: missing sections, undated records, inadequate specificity, or documentation not matching actual system behavior. Phase 3 — Technical Testing: Validate accuracy metrics against deployed populations, run fairness assessments across protected demographic groups, test edge cases and failure modes, and verify monitoring infrastructure is functioning. Phase 4 — Process Walkthrough: Interview human overseers (do they genuinely have authority to override?), data governance owners, incident management teams, and deployer communications staff. Phase 5 — Gap Analysis: Rate each finding by regulatory risk, business risk, and remediation effort. Phase 6 — Remediation Planning: For each gap, assign owner, target date, and interim mitigations.
Audit Cadence
Annual full audit across all high-risk AI systems; quarterly monitoring review of post-market data and incident reports; event-triggered review after significant system updates, serious incidents, or material regulatory changes; pre-inspection readiness check when regulatory interest in your sector is signaled.
Need help designing or conducting your first AI Act internal audit? Browse our directory of AI compliance auditors and governance experts.