Skip to content

ISO/IEC 42001:2023

ISO/IEC 42001:2023 is a management-system standard, so its Annex A controls apply from the edition date with no classification or role filter — an organisation decides its Statement of Applicability. The catalog maps the Annex A controls the gateway can produce evidence for; organisational controls are shown against pointers and declarations.

Registry id iso-42001
Kind standard
Jurisdiction Global
Instrument ISO/IEC 42001:2023 Artificial intelligence management system, Annex A
Catalog versions 2026-09 from 2023-12-18 (current) — First edition (2023)
Verified against instrument yes
Tagging key (compliance tags) iso_42001
Incident deadline rules none
Retention floors none at classification level
Obligations 15

ISO/IEC 42001 sets no retention floor of its own; the value you record in your SoA is the one that applies. The existing ISO 42001 activity endpoint (GET /v1/admin/compliance/iso-42001/activity) is kept.

Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.

a5-impact-assessment · Annex A.5.2–A.5.5 · applies from 2023-12-18

A process to assess the potential consequences of the AI system for individuals, groups and society, with the results documented. Applies to every system for which the framework is active.

What the gateway cannot show: Organisational control, evidenced by pointer and declaration only.

Statement Basis Resolver Does not show
A current AI system impact assessment is on file. recomputed evidence.pointer_on_file {"kind": "impact_assessment"} A pointer to a document produced outside the platform; its content is not evaluated.
The impact assessment process is declared. declared profile.field_declared {"path": "frameworks.iso-42001.impact_assessment_process_reference"} The process is organisational; the gateway cannot observe it.

Processes for responsible AI system design and development

Section titled “Processes for responsible AI system design and development”

a6-1-3-responsible-development · Annex A.6.1.3 · applies from 2023-12-18

Defined processes for responsible design and development — here, the contract lifecycle gate every change to the system’s grants goes through. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
The responsible-development process is declared. declared profile.field_declared {"path": "frameworks.iso-42001.development_process_reference"} The process is organisational; only its gate at the gateway is observable.
No grant was widened without going through the lifecycle gate. recomputed change.no_unapproved_widening Covers configuration held by the gateway; upstream changes (a vendor’s model) are shown as drift.

a6-2-2-requirements · Annex A.6.2.2 · applies from 2023-12-18

Requirements for the AI system are specified — the hash-pinned contract minted from the system’s declared intended use and grants. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
The contract that specifies the system was promoted with a sealed record naming its approver. recomputed change.promotions_sealed Shows the specification was signed off; the quality of the intended-use text is not evaluated.

a6-2-4-verification-validation · Annex A.6.2.4 · applies from 2023-12-18

Verification and validation measures are defined and applied before deployment. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Contract promotions went through the lifecycle gate (replay suite before promotion). recomputed change.promotions_sealed Shows the gate was used; whether the replay suite is sufficient is not evaluated.

a6-2-5-deployment · Annex A.6.2.5 · applies from 2023-12-18

A deployment plan, with the requirements met before the system is deployed. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Every contract promotion has a sealed epoch-boundary record naming its approver. recomputed change.promotions_sealed Changes made outside the contract lifecycle are not visible here.
No grant was widened without going through the lifecycle gate. recomputed change.no_unapproved_widening Covers configuration held by the gateway; upstream changes (a vendor’s model) are shown as drift.

a6-2-6-operation-monitoring · Annex A.6.2.6 · applies from 2023-12-18

The elements needed for ongoing operation, including monitoring, repairs and the ability to stop the system. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Liveness, drift and health were evaluated every day. recomputed monitoring.daily_health Shows the monitoring ran; what a human did with its findings is shown in the inbox trail.
Suspension and run-abort controls are available and every use of them was sealed. recomputed monitoring.suspend_available Shows the stop controls and their use; not whether they were used when they should have been.

a6-2-7-technical-documentation · Annex A.6.2.7 · applies from 2023-12-18

Technical documentation for the relevant interested parties. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
A documentation export exists for the active contract version, with its digest sealed. recomputed docs.technical_documentation {"framework": "iso-42001"} A skeleton generated from the register and contract; its adequacy is not evaluated.

a6-2-8-event-logs · Annex A.6.2.8 · applies from 2023-12-18

Event logs are recorded during the phases of the lifecycle where it matters, at minimum in use. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Every governed action produced a sealed record, including refusals. recomputed records.every_verdict_sealed Integrity is not completeness: covers actions routed through the gateway only; records sealed late by backfill are reported separately.
The tenant log’s tree heads covering the window were countersigned by an independent witness. recomputed records.witnessed A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested.
Record chains are closed and epoch boundaries match the contract history. recomputed records.chain_complete Checks the chains the gateway opened; actions that never reached the gateway cannot be counted.
Every gap in the retained logs is a declared prune. recomputed retention.declared_prunes A declared prune is shown as a gap with its reason; the pruned content cannot be recovered.

Data for AI systems (management, provenance, quality)

Section titled “Data for AI systems (management, provenance, quality)”

a7-data-management · Annex A.7.2–A.7.6 · applies from 2023-12-18

Data management processes, data provenance and data quality requirements are defined. Applies to every system for which the framework is active.

What the gateway cannot show: Organisational control, evidenced by pointer and declaration only.

Statement Basis Resolver Does not show
A data-governance record is on file. recomputed evidence.pointer_on_file {"kind": "data_governance"} A pointer to a document produced outside the platform; its content is not evaluated.
The data management process is declared. declared profile.field_declared {"path": "frameworks.iso-42001.data_management_reference"} Training and reference data sit outside the gateway.

System documentation and information for users

Section titled “System documentation and information for users”

a8-2-user-information · Annex A.8.2 · applies from 2023-12-18

Information users need is provided, including that they are interacting with an AI system. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
A documentation export exists for the active contract version, with its digest sealed. recomputed docs.technical_documentation {"framework": "iso-42001"} A skeleton generated from the register and contract; its adequacy is not evaluated.
The notice text and the surface it is shown on are declared and sealed. declared notice.text_declared The text is declared by the operator; whether it is understood is not evaluated.

a8-3-external-reporting · Annex A.8.3 · applies from 2023-12-18

Interested parties can report adverse impacts — here, the monthly Evidence Report built on a witnessed log. Applies to every system for which the framework is active.

What the gateway cannot show: The Evidence Reports themselves are listed on the Reports page; a reporting channel for the public is organisational.

Statement Basis Resolver Does not show
The log the monthly Evidence Report is built from is countersigned by an independent witness. recomputed records.witnessed A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested.

a8-4-incident-communication · Annex A.8.4 · applies from 2023-12-18

A plan for communicating incidents to users of the AI system. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
An incident register is kept and no open incident is past its deadline. recomputed incidents.register_exists Shows incidents someone entered; an incident nobody recorded cannot be counted.

Processes for responsible use (human oversight)

Section titled “Processes for responsible use (human oversight)”

a9-2-responsible-use · Annex A.9.2 · applies from 2023-12-18

Processes for the responsible use of AI systems, including human oversight of their operation. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
A human can override or stop the system. recomputed oversight.override_available Shows the controls exist and are assigned, not that the assigned people are competent.
Human approval requests were decided by humans (requested, decided, lapsed). recomputed oversight.exercised Records the fact of human disposition, not its quality.
Approval latency and denial rate are tracked for movement. indicator oversight.not_rubber_stamp An indicator of movement, never a threshold; it cannot show a decision was considered.

a9-3-a9-4-intended-use · Annex A.9.3, A.9.4 · applies from 2023-12-18

The system is used according to its intended use and the objectives for responsible use. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Every action outside the contract or grant was refused. recomputed authz.out_of_grant_refused Covers actions the gateway observed; the grant itself is a declaration.
Grants, capability filters and argument policies are bound and sealed. declared authz.least_privilege_declared Whether the grants are the least the system needs is the operator’s judgement, not evaluated.
Sampled runs stay within the declared intended use. judged judge.per_instructions Judged by a model over a disclosed sample; stated with human agreement, never merged with recomputed rows.

a10-third-parties · Annex A.10.2–A.10.4 · applies from 2023-12-18

Responsibilities are allocated between the organisation, suppliers and customers; vendor-operated systems are identified in the register. Applies to every system for which the framework is active.

What the gateway cannot show: Organisational control, evidenced by declaration and supplier pointers.

Statement Basis Resolver Does not show
The organisation’s role for this system (builder, operator, vendor) is declared. declared profile.field_declared {"path": "core.operator_role"} Supplier management is organisational; contracts with suppliers are not evaluated.
Every dependency supplied by another legal entity has the supplier’s written information on file. recomputed dependencies.supplier_information_on_file A pointer to the agreement, pinned by hash; its content is not evaluated.