SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.3.2AI roles and responsibilities

Assign decision rights, accountability and operating responsibilities for each stage of the AI system life cycle.

Mapping at a glance

A.3.2 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI roles, competence and training records
The record of who manages and decides on the company's AI, at every stage from choosing a tool to using it in production, together with the evidence that those people have the training or outside expertise needed to do it well.
From the Sekit evidence catalog

In practice

This control asks for a written record of who decides what at each stage of using AI, from choosing a vendor tool to approving its output in a customer-facing process, plus proof those people know what they are doing. An auditor pulls the AI roles, competence and training record and checks it names a real person for each stage, not a department, and shows training or outside expertise behind the decision-maker rather than someone learning the tool on the job. The common failure is a single AI owner title with no defined scope and no training evidence attached to it.

Common gaps

One person is named AI owner in a slide deck but the role has no defined scope, decision rights, or training evidence.
The person approving AI-generated customer content has no record of AI-specific training, only general job competence.
Roles are assigned for choosing an AI tool but nobody is named responsible once it moves into daily production use.

Questions your auditor will ask

Who decides which AI tools the company adopts?
The AI roles record names a specific person or role with that decision right at each life-cycle stage, from selection to retirement.
How do you know the people managing AI are competent to do so?
Training records or documented outside expertise are attached to each named role in the AI roles and training record.
Is there a single person accountable for AI once it is in production, not only at selection?
Yes, the record assigns a separate operating owner for the production stage from the person who selected the tool.

Where regulation demands it

NIS2 art. 1.2 (Roles, responsibilities and authorities) requires named roles, extended here to every stage of selecting and running AI tools.
Ask Sekura: “What evidence proves A.3.2?”
Also via MCP, free with account