SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.7.3Acquisition of data

Acquire data through controlled sources with documented rights, consent, restrictions, provenance and acceptance checks.

Mapping at a glance

A.7.3 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI dataset record: provenance, permitted use and quality
For each dataset an AI system uses, the record of where it came from, what the company is allowed to do with it (licence, consent, restrictions), whether it contains personal data, and the quality and preparation checks run before using it (cleaning, labelling, data split).
From the Sekit evidence catalog

In practice

Acquiring data for an AI system, buying a dataset, licensing a corpus, scraping a partner feed, needs supplier-grade due diligence whether that data trains your own model or feeds a vendor tool: a purchased contact list loaded into a CRM assistant, or a scraped feed piped into a vendor summarizer, needs the same check. Before use, someone verifies where the data came from, what the licence permits, and whether no-resale or no-AI-training clauses apply. An auditor asks for the AI dataset record and matches it against the actual purchase or licence agreement. The recurring gap is data grabbed through a quick download or a free API with no acceptance check on what the source terms allow.

Common gaps

A purchased contact list gets loaded into a vendor CRM assistant with no check of whether the seller's licence allows that AI use at all.
Data acquired through a vendor contract has no clause covering AI-specific restrictions, so the supplier agreement never addresses training use.
Acceptance checks exist for regular supplier onboarding but skip any source treated as a quick download instead of a procurement.

Questions your auditor will ask

How was the data feeding this vendor tool acquired, and under what terms?
The AI dataset record names the source and the licence, consent or contract basis for each dataset acquired, whether it trains your own model or feeds a vendor tool.
Does the data source allow use for AI training?
Permitted use is checked against the acquisition terms before the dataset enters a training pipeline or a vendor tool, and any restriction is recorded.
Was this data source risk-assessed like any other supplier?
Data suppliers go through the same third-party risk assessment as other vendors, including data sources acquired specifically for AI.
Do your supplier contracts cover AI-specific data restrictions?
Contract review checks for AI training clauses alongside standard breach notification and data protection terms, catching restrictions before use.

Where regulation demands it

GDPR's processor obligations (28.1, 28.3) apply when a data supplier for AI training processes personal data on the company's behalf, not only to conventional IT vendors.
NIS2 art. 5.2 (Directory of suppliers and service providers) should list data sources acquired for AI the same way it lists any other service provider.
Ask Sekura: “What evidence proves A.7.3?”
Also via MCP, free with account