SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.4.6Human resources

Provide enough competent people, training and independent expertise to fulfil AI responsibilities.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI roles, competence and training records
The record of who manages and decides on the company's AI, at every stage from choosing a tool to using it in production, together with the evidence that those people have the training or outside expertise needed to do it well.
From the Sekit evidence catalog

In practice

In a small company this means naming who owns AI decisions: the person who approves a new vendor chatbot, the person who reviews prompts touching client data, and what training they have had beyond reading the terms of service. Auditors ask for the AI roles, competence and training records and probe whether the named owner can explain a recent tool adoption, or whether the role exists only on paper while decisions happen in a Slack thread nobody logged.

Common gaps

A team adopts a vendor AI tool without anyone assigned to own the risk or usage decisions for it.
Security awareness training covers phishing and passwords but never mentions AI tool use or data handling.
The named AI owner cannot describe the tools in use or point to any training beyond a generic onboarding module.

Questions your auditor will ask

Who is accountable for AI decisions in this company?
A named person or small group, documented in the AI roles, competence and training records, who approves tool adoption and reviews AI-related risk.
Does general security awareness training cover AI use?
Yes, the annual awareness cycle includes AI-specific content: acceptable tools, data handling limits and where to raise concerns.
What happens if no one in-house understands the AI tool being adopted?
The company brings in outside expertise, documented alongside the internal training record, before the tool goes into regular use.
How do you verify people completed the training rather than only being assigned it?
Completion and comprehension are tracked per person, with non-completers followed up until closed out.

Where regulation demands it

NIS2 art. 8.2 (Security training) requires this for staff with elevated responsibilities, which for an AI-buying SME means the people who choose and configure the tools.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.4.6?”
Also via MCP, free with account