> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/reports-and-audits/internal-audits.md).

# Internal audits

How Memori verifies that its processes comply with the ISO standards it has adopted

As part of the ISO 27001:2022, ISO 9001:2015 and ISO 42001:2023 certified Management Systems, Memori runs regular cycles of internal audits to verify that business processes meet the requirements of the adopted standards and to identify opportunities for improvement. Internal audits are mandatory under ISO certification and are scheduled in the annual audit program.

### What is audited

#### ISO 27001 - Information security

* Risk management and vulnerability treatment
* Physical and logical access control
* Security incident management
* Communications security and encryption
* Security in software development (SDLC)
* Management of suppliers and sub-processors
* Regulatory compliance (GDPR, AI Act)
* Business continuity and disaster recovery

#### ISO 9001 - Quality

* Software development and testing processes
* Management of requirements and user stories
* Software production planning and control
* Customer satisfaction and feedback management
* Control of nonconforming products and services
* Corrective actions and continual improvement

#### ISO 42001 - Artificial Intelligence Management Systems

* AI system governance and definition of roles and responsibilities
* AI risk management across the entire system lifecycle
* Impact assessment of AI systems on users' rights and safety
* Transparency and explainability of the outputs generated by the platform
* Human oversight mechanisms and control of Agents
* Management of data used in AI systems (quality, provenance, bias)
* Continuous monitoring of the performance and behavior of the AI system
* Management of AI component suppliers (LLM providers and third-party models)
* Compliance with the AI Act and updating of the risk classification

### Frequency and methodology

Internal audits are planned at least annually for each process in scope. The methodology follows the guidelines of ISO 19011 (Guidelines for auditing management systems). Results are documented in formal reports, shared with management and used as input for the management review.

### Availability of results

| Document                         | Availability                                       |
| -------------------------------- | -------------------------------------------------- |
| Annual audit plan                | Internal                                           |
| Detailed audit reports           | Internal                                           |
| Summary of results for customers | On request (PaaS/Enterprise) — <privacy@memori.ai> |
| Management review report         | Internal                                           |

> During vendor assessment or due diligence, customers with a PaaS or Enterprise contract may request a summary of the audit results and of the nonconformities found in the reference period. The request must be sent to [privacy@memori.ai.](mailto:privacy@memori.ai)
