SekitCrosswalk
Start free trial
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.4.5System and computing resources

Plan and control the computing capacity, environments and infrastructure needed for reliable AI development and operation.

Mapping at a glance

A.4.5 is covered by 2 Sekit CSF controls. Open in the full graph →

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 · Annex A controls counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Availability and capacity management
How the company ensures its critical services are available as expected, plans their capacity, and prevents problems from recurring.
From the Sekit evidence catalog

In practice

Reliable AI operation needs planned computing capacity: enough inference throughput or GPU access that a customer-facing AI feature does not degrade under load, and a record of what infrastructure each AI system runs on, whether that is the company's own servers or a vendor's cloud capacity. An auditor asks for the availability and capacity management record and checks it names the infrastructure behind at least one AI-powered feature, with a plan for what happens if that capacity is exceeded or the underlying service goes down. The common gap is capacity planning that covers the company's core systems but never considered the AI feature added last quarter.

Common gaps

Capacity planning covers the company's core infrastructure but the AI feature added last quarter was never added to that plan.
An AI feature's response times degrade under load with no documented capacity threshold or escalation path defined for it.
The infrastructure behind an AI system, cloud GPU access or a vendor's inference capacity, is not named anywhere in the resource register.

Questions your auditor will ask

What infrastructure does this AI feature run on, specifically?
The resource record names the specific infrastructure, whether company servers or vendor cloud capacity, behind each AI-powered feature.
What happens if AI inference capacity is exceeded?
The availability and capacity management plan sets a threshold and an escalation path specific to the AI feature's expected load.
Is AI infrastructure included in the standard hardware and capacity register?
Yes, it is reconciled on the same fixed cadence as the company's other hardware and service capacity, not tracked separately.

Where regulation demands it

ENS op.exp.1 (Inventario de activos) requires a current asset inventory, extended here to the computing capacity and infrastructure an AI feature depends on to stay available.
Ask Sekura: “What evidence proves A.4.5?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk
  1. In Claude or ChatGPT, add a custom connector and paste this URL.
  2. Sign in with your email to finish. Free, read-only, no organization required.