Give an AI tool a prompt and it will draft an ISO policy or procedure in seconds, and plenty of organisations are now building their whole management system this way. As a starting point, that’s fine. The trouble is that AI-generated systems routinely miss the mark in exactly the places an auditor looks hardest. Here’s where they go wrong, what AI is genuinely good at, and how to put it right.
I can usually pick an AI-drafted system within the first ten minutes of an audit. The wording is polished and the clause numbers are all present, but the context is generic, the risks are the ones every business has rather than the ones this business actually faces, and there’s no trail of evidence behind any of it. The documents read beautifully; the organisation underneath them hasn’t changed at all.

First, what AI is genuinely good at
It’s worth being fair to the tools. Used sensibly, AI is a fast, tireless junior that gets the blank page filled. It’s good at first drafts of policies and procedures, turning your rough notes into structured documentation, explaining what a clause actually means in plain English, mapping your activities to the relevant clauses or Annex A controls, and giving you a starting-point risk register to react to. That’s real time saved, and there is nothing wrong with using it. A certificate simply isn’t awarded for documentation. It’s awarded for a system that conforms, is implemented, and can prove it.
Where AI-built ISO systems fall short
- Context and scope (Clause 4). AI doesn’t know your business, your interested parties or your real risks, so it produces generic context that auditors see straight through.
- Risk assessment. A credible risk assessment reflects your actual operations and decisions. AI invents plausible-looking risks that don’t match what you really do.
- The Statement of Applicability (ISO 27001). AI will happily generate an SoA that doesn’t match the controls you’ve actually implemented, a classic audit failure.
- Implementation and records. A system isn’t the documents. It’s the evidence that you’re doing what they say, and AI can’t generate your records for you.
- The internal audit (Clause 9.2). Every certified system needs an objective, independent internal audit. This is the one requirement AI and templates simply cannot satisfy.
There’s an accuracy problem on top of all that. I have seen AI confidently cite clause numbers that don’t exist and invent Annex A controls out of thin air. If you don’t already know the standard well enough to catch it, you will build the error straight into your system, and defend it, in good faith, right up until the auditor asks you to show them where it comes from.
Why it matters
A system that looks complete on paper but doesn’t reflect reality is exactly what triggers non-conformities at a certification audit, costing you delays, rework and, sometimes, a failed audit. The documentation was the easy part; the judgement, the implementation and the independent check are where certification is actually won.
The pattern I see most often is a beautifully written procedure paired with staff who have never read it. In the interview room I ask the person doing the work to walk me through how they actually do it. When their answer bears no resemblance to the document, that gap becomes the non-conformity. AI can write the procedure, but it can’t make your people own it.
The one part you can’t do yourself
Even a well-built, AI-assisted system has to clear clause 9.2, the internal audit, before a certification body will look at it. And an internal audit has to be objective and impartial: you cannot credibly audit the system you just wrote. That independence requirement is exactly why so many capable DIY teams still bring in an outside auditor for the 9.2 audit. It is the one piece you cannot self-certify, and it is usually what stands between a first-time pass and a failed Stage 2.
How to make an AI-built system pass
You don’t have to throw away the work AI has done. You need an experienced auditor to make it real. Streamline can mentor your team to fix the gaps and embed the system, and provide the independent internal audit under ISO clause 9.2 with best-practice recommendations before the certification body sees it. If you are not sure how close you are, an independent gap analysis turns “I think it’s done” into a costed action list, and a certification readiness review confirms you will pass before you book the audit. You keep control and cost down; we make sure it will certify.
A short checklist for using AI on your ISO system
- Prompt it with your real processes, not just the standard. Feed it how you actually work, or you’ll get a generic manual.
- Keep a human in the loop on every clause, and verify anything it cites against the actual standard.
- Never document a control you don’t run. Build the evidence first, then describe it.
- Get an independent set of eyes (a gap analysis or readiness review) before Stage 2.
- Run a genuine internal audit and management review, and use them to fix things, not to tick a box.
Using AI vs managing AI: an important distinction
Everything above is about using AI as a tool to help build your management system. That is different from governing AI as part of your product or operations. If AI is something you deploy and are accountable for, the relevant standard is ISO 42001, the world’s first AI management system standard. See what ISO 42001 means for AI companies and how ISO 42001 and ISO 27001 fit together.
Frequently asked questions
Can I use AI to build an ISO 9001 or ISO 27001 system?
Yes, as a drafting aid, but AI output needs expert review, real implementation and an independent internal audit before it will pass certification. On its own it rarely meets the standard.
Will an AI-built ISO system pass certification?
Not reliably on its own. The documentation may look right, but auditors test whether the system reflects your operations and is actually implemented, which is where AI-built systems usually fall down. Mentoring and an independent internal audit close that gap.
Does using AI make certification cheaper?
It can. AI and your own team can carry most of the documentation load, which brings the implementation-support component of the cost down. See our ISO 9001 and ISO 27001 cost guides. What you cannot remove is the certification body audit and the independent internal audit.
Speak with an experienced ISO auditor
Built your system with AI and want to be sure it will pass? Email hello@streamline.business or call us:
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Related reading: Shadow AI in the Workplace: The Wild West of Ungoverned AI: how ungoverned employee AI use creates data-loss risk, and how ISO 27001 and ISO 42001 bring it under control.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











