SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.2.2AI policy

Define an approved AI policy covering principles, acceptable uses, prohibited practices, accountability and oversight.

Mapping at a glance
A.2.2AI policyISO/IEC 42001:2023 — Annex A

A.2.2 is covered by 1 Sekit CSF control. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI policy
The written, leadership-approved document that sets out how the company develops, buys and uses artificial intelligence: principles, acceptable and prohibited uses, who is accountable, and how it connects to the company's other policies.
From the Sekit evidence catalog

In practice

Writing the AI policy means naming, in one leadership-approved document, what the company allows: buying a vendor copilot for drafting emails, say, but not pasting client data into a public chatbot. An auditor asks to see the document itself, checks it has an owner and a review date, and confirms it names prohibited practices specific to how this company uses AI, not a template downloaded wholesale. The common failure is a policy that reads like generic AI ethics language, naming no real tool, no real prohibited use, and no accountable person, so it fails the moment someone asks who signed it and when.

Common gaps

The AI policy is copied from a template and never edited to name the company's actual tools, so it reads as generic and unenforceable.
Leadership approved the policy once but no owner or review date is recorded, leaving nobody accountable when a new AI tool shows up.
The policy states principles but lists no prohibited uses, so staff pasting client data into a public chatbot breaks no written rule.

Questions your auditor will ask

Does the company have an approved AI policy, and who signed it?
The AI policy document names its approver and date, kept alongside the company's other leadership-approved policies.
What does the policy specifically prohibit?
It lists specific prohibited uses, such as pasting client data into a public chatbot, not only general principles.
Who is accountable if the AI policy is not followed?
The policy names an accountable owner responsible for enforcement and for updating it as AI use changes.

Where regulation demands it

GDPR Article 24.2 expects data protection commitments to sit inside an organization's policies, and ENS org.1 (Política de seguridad) asks for that same approved security policy in writing.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.2.2?”
Also via MCP, free with account