ISO/IEC 42001:2023
Artificial intelligence management system standard. Specifies requirements for establishing, implementing, maintaining and improving an AI management system, including responsible AI development, deployment and use.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| A.2.2 | AI policy | |
| A.2.3 | AI roles and responsibilities | |
| A.2.4 | Monitoring, measurement, and review of AI systems | |
| A.3.2 | AI roles, responsibilities, and authorities | |
| A.3.3 | Reporting AI incidents and concerns | |
| A.4.2 | AI system inventory and documentation | |
| A.4.3 | Data management for AI systems | |
| A.4.4 | Technology resource management for AI | |
| A.4.5 | AI system continuity and resilience | |
| A.4.6 | AI competence, awareness, and training | |
| A.5.2 | AI risk assessment | |
| A.5.3 | AI risk treatment | |
| A.5.4 | AI impact assessment | |
| A.5.5 | AI system risk documentation | |
| A.6.1.2 | AI system design and architecture | |
| A.6.1.3 | AI system development practices | |
| A.6.2.2 | AI system acquisition requirements | |
| A.6.2.3 | AI system configuration and deployment | |
| A.6.2.4 | AI system testing and validation | |
| A.6.2.5 | AI system change management | |
| A.6.2.6 | AI system maintenance and monitoring | |
| A.6.2.7 | AI system documentation | |
| A.6.2.8 | AI system logging and audit trails | |
| A.7.2 | Data quality for AI | |
| A.7.3 | Data provenance and lineage for AI | |
| A.7.4 | Data labelling and annotation | |
| A.7.5 | Data integrity and authenticity for AI | |
| A.8.2 | AI system transparency | |
| A.8.3 | AI system reporting to stakeholders | |
| A.8.4 | AI incident management | |
| A.8.5 | AI system record keeping | |
| A.9.2 | Human oversight of AI systems | |
| A.9.3 | AI system user interaction | |
| A.9.4 | Restriction of AI system autonomy | |
| A.10.2 | Third-party AI components and services | |
| A.10.3 | AI supply chain risk management | |
| A.10.4 | Third-party monitoring for AI |