SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.4.4Tooling resources

Approve and maintain the software, models, libraries, evaluation tools and development platforms used for AI.

Mapping at a glance

A.4.4 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI system inventory
The single, up-to-date register of the AI systems the company builds or uses, recording each one's purpose, owner, life-cycle stage and criticality, plus the models, libraries, platforms, data sources and infrastructure it depends on.
From the Sekit evidence catalog

In practice

Approving AI tooling means treating a new AI library, model API, or evaluation tool the same way the company treats any new software: recorded, licensed, and approved before a team starts using it, with a clear rule against a developer wiring in an unsanctioned model API on their own. An auditor checks the AI system inventory against the software register and asks how a new AI library gets approved before use, then looks for evidence of at least one tool that was refused or removed. The common failure is an engineering team adopting a new model provider without it ever reaching the approval process.

Common gaps

An engineer adds a new AI model API to the codebase without it going through the software approval process used for other tools.
The software register tracks office applications but has never been checked against the AI libraries or model providers in real use.
A deprecated AI tool is still listed as active because nobody removed it from the register when the team stopped using it.

Questions your auditor will ask

How is a new AI tool or model API approved before use?
It goes through the same software approval process as any other tool, recorded in the AI system inventory with licence status and an owner.
What stops a developer from adding an unsanctioned AI library?
The written software policy prohibits unapproved tools, and the inventory is reconciled periodically to catch anything added outside the process.
Is the AI tooling register kept current as tools change?
Yes, entries are removed or updated when a tool is retired or replaced, following the same cadence as the software register.

Where regulation demands it

NIS2 art. 6.9 (Protection against malicious and unauthorised software) covers this, extended for AI to an unapproved model API or library reaching production.
Ask Sekura: “What evidence proves A.4.4?”
Also via MCP, free with account