ISO/IEC 42001:2023
ISO/IEC 42001:2023 is a management-system standard, so its Annex A controls apply from the edition date with no classification or role filter — an organisation decides its Statement of Applicability. The catalog maps the Annex A controls the gateway can produce evidence for; organisational controls are shown against pointers and declarations.
| Registry id | iso-42001 |
| Kind | standard |
| Jurisdiction | Global |
| Instrument | ISO/IEC 42001:2023 Artificial intelligence management system, Annex A |
| Catalog versions | 2026-09 from 2023-12-18 (current) — First edition (2023) |
| Verified against instrument | yes |
| Tagging key (compliance tags) | iso_42001 |
| Incident deadline rules | none |
| Retention floors | none at classification level |
| Obligations | 15 |
ISO/IEC 42001 sets no retention floor of its own; the value you record in your SoA is the one that applies. The existing ISO 42001 activity endpoint (GET /v1/admin/compliance/iso-42001/activity) is kept.
Obligations and their evidence
Section titled “Obligations and their evidence”Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.
AI system impact assessment
Section titled “AI system impact assessment”a5-impact-assessment · Annex A.5.2–A.5.5 · applies from 2023-12-18
A process to assess the potential consequences of the AI system for individuals, groups and society, with the results documented. Applies to every system for which the framework is active.
What the gateway cannot show: Organisational control, evidenced by pointer and declaration only.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A current AI system impact assessment is on file. | recomputed | evidence.pointer_on_file {"kind": "impact_assessment"} |
A pointer to a document produced outside the platform; its content is not evaluated. |
| The impact assessment process is declared. | declared | profile.field_declared {"path": "frameworks.iso-42001.impact_assessment_process_reference"} |
The process is organisational; the gateway cannot observe it. |
Processes for responsible AI system design and development
Section titled “Processes for responsible AI system design and development”a6-1-3-responsible-development · Annex A.6.1.3 · applies from 2023-12-18
Defined processes for responsible design and development — here, the contract lifecycle gate every change to the system’s grants goes through. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The responsible-development process is declared. | declared | profile.field_declared {"path": "frameworks.iso-42001.development_process_reference"} |
The process is organisational; only its gate at the gateway is observable. |
| No grant was widened without going through the lifecycle gate. | recomputed | change.no_unapproved_widening |
Covers configuration held by the gateway; upstream changes (a vendor’s model) are shown as drift. |
AI system requirements and specification
Section titled “AI system requirements and specification”a6-2-2-requirements · Annex A.6.2.2 · applies from 2023-12-18
Requirements for the AI system are specified — the hash-pinned contract minted from the system’s declared intended use and grants. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The contract that specifies the system was promoted with a sealed record naming its approver. | recomputed | change.promotions_sealed |
Shows the specification was signed off; the quality of the intended-use text is not evaluated. |
AI system verification and validation
Section titled “AI system verification and validation”a6-2-4-verification-validation · Annex A.6.2.4 · applies from 2023-12-18
Verification and validation measures are defined and applied before deployment. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Contract promotions went through the lifecycle gate (replay suite before promotion). | recomputed | change.promotions_sealed |
Shows the gate was used; whether the replay suite is sufficient is not evaluated. |
AI system deployment
Section titled “AI system deployment”a6-2-5-deployment · Annex A.6.2.5 · applies from 2023-12-18
A deployment plan, with the requirements met before the system is deployed. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every contract promotion has a sealed epoch-boundary record naming its approver. | recomputed | change.promotions_sealed |
Changes made outside the contract lifecycle are not visible here. |
| No grant was widened without going through the lifecycle gate. | recomputed | change.no_unapproved_widening |
Covers configuration held by the gateway; upstream changes (a vendor’s model) are shown as drift. |
AI system operation and monitoring
Section titled “AI system operation and monitoring”a6-2-6-operation-monitoring · Annex A.6.2.6 · applies from 2023-12-18
The elements needed for ongoing operation, including monitoring, repairs and the ability to stop the system. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Liveness, drift and health were evaluated every day. | recomputed | monitoring.daily_health |
Shows the monitoring ran; what a human did with its findings is shown in the inbox trail. |
| Suspension and run-abort controls are available and every use of them was sealed. | recomputed | monitoring.suspend_available |
Shows the stop controls and their use; not whether they were used when they should have been. |
AI system technical documentation
Section titled “AI system technical documentation”a6-2-7-technical-documentation · Annex A.6.2.7 · applies from 2023-12-18
Technical documentation for the relevant interested parties. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A documentation export exists for the active contract version, with its digest sealed. | recomputed | docs.technical_documentation {"framework": "iso-42001"} |
A skeleton generated from the register and contract; its adequacy is not evaluated. |
AI system recording of event logs
Section titled “AI system recording of event logs”a6-2-8-event-logs · Annex A.6.2.8 · applies from 2023-12-18
Event logs are recorded during the phases of the lifecycle where it matters, at minimum in use. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every governed action produced a sealed record, including refusals. | recomputed | records.every_verdict_sealed |
Integrity is not completeness: covers actions routed through the gateway only; records sealed late by backfill are reported separately. |
| The tenant log’s tree heads covering the window were countersigned by an independent witness. | recomputed | records.witnessed |
A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested. |
| Record chains are closed and epoch boundaries match the contract history. | recomputed | records.chain_complete |
Checks the chains the gateway opened; actions that never reached the gateway cannot be counted. |
| Every gap in the retained logs is a declared prune. | recomputed | retention.declared_prunes |
A declared prune is shown as a gap with its reason; the pruned content cannot be recovered. |
Data for AI systems (management, provenance, quality)
Section titled “Data for AI systems (management, provenance, quality)”a7-data-management · Annex A.7.2–A.7.6 · applies from 2023-12-18
Data management processes, data provenance and data quality requirements are defined. Applies to every system for which the framework is active.
What the gateway cannot show: Organisational control, evidenced by pointer and declaration only.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A data-governance record is on file. | recomputed | evidence.pointer_on_file {"kind": "data_governance"} |
A pointer to a document produced outside the platform; its content is not evaluated. |
| The data management process is declared. | declared | profile.field_declared {"path": "frameworks.iso-42001.data_management_reference"} |
Training and reference data sit outside the gateway. |
System documentation and information for users
Section titled “System documentation and information for users”a8-2-user-information · Annex A.8.2 · applies from 2023-12-18
Information users need is provided, including that they are interacting with an AI system. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A documentation export exists for the active contract version, with its digest sealed. | recomputed | docs.technical_documentation {"framework": "iso-42001"} |
A skeleton generated from the register and contract; its adequacy is not evaluated. |
| The notice text and the surface it is shown on are declared and sealed. | declared | notice.text_declared |
The text is declared by the operator; whether it is understood is not evaluated. |
External reporting
Section titled “External reporting”a8-3-external-reporting · Annex A.8.3 · applies from 2023-12-18
Interested parties can report adverse impacts — here, the monthly Evidence Report built on a witnessed log. Applies to every system for which the framework is active.
What the gateway cannot show: The Evidence Reports themselves are listed on the Reports page; a reporting channel for the public is organisational.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The log the monthly Evidence Report is built from is countersigned by an independent witness. | recomputed | records.witnessed |
A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested. |
Communication of incidents
Section titled “Communication of incidents”a8-4-incident-communication · Annex A.8.4 · applies from 2023-12-18
A plan for communicating incidents to users of the AI system. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| An incident register is kept and no open incident is past its deadline. | recomputed | incidents.register_exists |
Shows incidents someone entered; an incident nobody recorded cannot be counted. |
Processes for responsible use (human oversight)
Section titled “Processes for responsible use (human oversight)”a9-2-responsible-use · Annex A.9.2 · applies from 2023-12-18
Processes for the responsible use of AI systems, including human oversight of their operation. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A human can override or stop the system. | recomputed | oversight.override_available |
Shows the controls exist and are assigned, not that the assigned people are competent. |
| Human approval requests were decided by humans (requested, decided, lapsed). | recomputed | oversight.exercised |
Records the fact of human disposition, not its quality. |
| Approval latency and denial rate are tracked for movement. | indicator | oversight.not_rubber_stamp |
An indicator of movement, never a threshold; it cannot show a decision was considered. |
Objectives and intended use
Section titled “Objectives and intended use”a9-3-a9-4-intended-use · Annex A.9.3, A.9.4 · applies from 2023-12-18
The system is used according to its intended use and the objectives for responsible use. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every action outside the contract or grant was refused. | recomputed | authz.out_of_grant_refused |
Covers actions the gateway observed; the grant itself is a declaration. |
| Grants, capability filters and argument policies are bound and sealed. | declared | authz.least_privilege_declared |
Whether the grants are the least the system needs is the operator’s judgement, not evaluated. |
| Sampled runs stay within the declared intended use. | judged | judge.per_instructions |
Judged by a model over a disclosed sample; stated with human agreement, never merged with recomputed rows. |
Third-party and customer relationships
Section titled “Third-party and customer relationships”a10-third-parties · Annex A.10.2–A.10.4 · applies from 2023-12-18
Responsibilities are allocated between the organisation, suppliers and customers; vendor-operated systems are identified in the register. Applies to every system for which the framework is active.
What the gateway cannot show: Organisational control, evidenced by declaration and supplier pointers.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The organisation’s role for this system (builder, operator, vendor) is declared. | declared | profile.field_declared {"path": "core.operator_role"} |
Supplier management is organisational; contracts with suppliers are not evaluated. |
| Every dependency supplied by another legal entity has the supplier’s written information on file. | recomputed | dependencies.supplier_information_on_file |
A pointer to the agreement, pinned by hash; its content is not evaluated. |
Related
Section titled “Related”- Framework registry & evidence bases — how catalogs, resolvers and the version in force work
- The Compliance console — the Obligations matrix for this framework
- Incidents, reports & documentation

