SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.10.3Suppliers

Assess, contract and monitor AI suppliers against defined responsible-AI, data, security, transparency and incident requirements.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0316Vendor due diligence · PolicysupportsRCF-0316 requires a documented security check before a supplier is engaged; A.10.3 needs that check extended to AI-specific risks like training-use and model provenance, which the Sekit control does not probe on its own.RCF-0317Vendor due diligence · ProcesssupportsRCF-0317 confirms the onboarding assessment runs in practice and repeats on a cycle; it supports A.10.3 by giving the AI vendor a home in that existing rhythm rather than a separate process.RCF-0319Contractual security clauses · PolicysupportsRCF-0319 mandates security clauses in supplier contracts; A.10.3 needs those clauses to also cover AI terms like training-data use and incident notice, a gap the Sekit control does not close alone.RCF-0320Contractual security clauses · ProcesssupportsRCF-0320 tracks whether suppliers meet contractual obligations; applied to an AI vendor it supports A.10.3 by catching a missed incident notice or an unnotified model change, not only generic non-compliance.RCF-0322Ongoing monitoring · PolicysupportsRCF-0322 commits the company to monitoring critical suppliers for the life of the relationship; A.10.3 needs that commitment to name AI vendors explicitly, since a chatbot subscription is easy to leave off that list.RCF-0323Ongoing monitoring · ProcesssupportsRCF-0323 runs periodic supplier reviews and watches breach signals; it supports A.10.3 by giving the AI vendor the same review cadence, though it does not check AI-specific terms like training-use by itself.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog

In practice

For a company buying an AI vendor's API or chatbot, this control means running the same due diligence on that vendor as any critical supplier, then adding AI-specific questions: does the vendor train on your prompts, who are its sub-processors, and how does it notify you when it deprecates a model version. An auditor pulls the AI supplier terms and assurances record and checks it against the vendor's actual data processing agreement, not a sales page. The typical gap is a team signing up for a new AI tool on a company card, skipping the vendor security review that every other supplier goes through.

Common gaps

A department buys an AI subscription with a company card and skips the vendor security review required for every other supplier.
The onboarding assessment checks general security posture but never asks whether the AI vendor trains on the company's prompts or documents.
Ongoing supplier monitoring covers infrastructure providers but stops at the AI vendor, so a model deprecation arrives with no warning.

Questions your auditor will ask

How do you vet an AI vendor before signing up?
The same supplier due diligence process applies, plus questions on prompt training use, sub-processors and incident notification, recorded in the AI supplier terms file.
Does the AI vendor use our data to train its models?
The AI supplier terms and assurances record states the vendor's training-use policy, taken from its actual data processing agreement rather than marketing copy.
What happens if the AI vendor changes or retires a model version?
The record captures the vendor's version-change notice period and any certification it publishes, checked at onboarding and on the review cycle.
How often is the AI vendor's security posture reviewed after onboarding?
Vendor due diligence and monitoring sets a defined review cycle and tracks breach or incident signals for the AI vendor like any critical supplier.

Where regulation demands it

GDPR Articles 28.1 and 28.3 require choosing a processor with sufficient guarantees and binding it by contract, which applies directly to an AI vendor processing company data.
Ask Sekura: “What evidence proves A.10.3?”
Also via MCP, free with account