SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.2.4Review of the AI policy

Review the AI policy on a defined schedule and after material legal, risk, technology or business changes.

Mapping at a glance
A.2.4Review of the AI policyISO/IEC 42001:2023 — Annex A

A.2.4 is covered by 1 Sekit CSF control. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI policy
The written, leadership-approved document that sets out how the company develops, buys and uses artificial intelligence: principles, acceptable and prohibited uses, who is accountable, and how it connects to the company's other policies.
From the Sekit evidence catalog

In practice

Reviewing the AI policy on schedule means more than a calendar reminder: when the company adopts a new AI vendor, changes how it uses customer data, or a relevant law takes effect, the policy gets reopened and reissued, not left stale for a year. An auditor checks the review log for dates, triggers and what changed in the document text, then asks how staff learned about the update. The common gap is a policy carrying a review date field that nobody has touched since it was first approved, even after the company added two new AI tools in the meantime.

Common gaps

The policy carries a review date field but the document text has not changed since it was first approved a year ago.
A new AI vendor was adopted and no one reopened the AI policy to check whether it still covers the new use.
Staff were never told the AI policy changed, so the update exists on paper but nobody works to the new version.

Questions your auditor will ask

How often is the AI policy reviewed?
On a defined schedule stated in the policy itself, and also whenever the company adopts a new AI tool or a relevant law changes.
How do staff learn the AI policy has changed?
The routine that communicates security policy updates company-wide also covers AI policy changes, with a record of who acknowledged it.
What triggers an out-of-cycle review?
A new AI vendor, a material change in AI use, or a legal change each trigger a review outside the normal schedule, logged with the trigger.

Where regulation demands it

GDPR Article 24.1 makes the controller responsible for keeping protective measures current, the same obligation behind reviewing the AI policy after a material change.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.2.4?”
Also via MCP, free with account