SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.4.2Resource documentation

Document the resources and dependencies required to build, operate, monitor and retire each AI system.

Mapping at a glance

A.4.2 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI system inventory
The single, up-to-date register of the AI systems the company builds or uses, recording each one's purpose, owner, life-cycle stage and criticality, plus the models, libraries, platforms, data sources and infrastructure it depends on.
From the Sekit evidence catalog

In practice

Documenting AI resources means keeping one register that lists each AI system the company builds or buys, its purpose, its owner, and what it depends on: the underlying model, the data source, the hosting platform. An auditor asks for the AI system inventory and checks it is current, not a one-time export, and that it names dependencies specific enough to matter, like which model version a feature relies on. The common gap is an inventory that lists a tool by brand name with no owner, no dependency detail, and no update since it was first created for a prior audit cycle.

Common gaps

The AI system inventory lists tool names but no owner, dependency detail, or model version, so it cannot support an incident response.
A new AI feature went into production without ever being added to the inventory, discovered only when an auditor asked directly.
The inventory was built once for a prior audit and has not been updated as AI dependencies changed since.

Questions your auditor will ask

Where is the current list of AI systems the company uses?
The AI system inventory, listing each system's purpose, owner, life-cycle stage and dependencies, kept current rather than built once for audit.
How do you know what a given AI feature depends on?
The inventory records each system's models, libraries, platforms and data sources as dependencies, reviewed for single points of failure.
Who owns each AI system on the inventory?
Every entry names an accountable owner, following the same service-dependency register discipline used for the company's other critical services.

Where regulation demands it

ENS op.exp.1 (Inventario de activos) requires an asset inventory, extended for AI to the models, data sources and platforms each system depends on.
Ask Sekura: “What evidence proves A.4.2?”
Also via MCP, free with account