SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.6.1.2Objectives for responsible development of AI system

Set measurable responsible-development objectives and acceptance criteria for each in-scope AI initiative.

Mapping at a glance
A.6.1.2Objectives for responsible development of AI systemISO/IEC 42001:2023 — Annex A

A.6.1.2 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Responsible AI development procedure and objectives
The internal standard for developing or adopting AI systems responsibly: the measurable objectives each initiative must meet (accuracy, fairness, robustness, transparency) and the review stages, such as risk, data, human oversight and testing, that make those objectives real in practice.
From the Sekit evidence catalog

In practice

Before writing a line of code or configuring a vendor model, the team should agree what "responsible" means for this specific AI initiative: an accuracy floor, a fairness check, a human review step. The responsible AI development procedure and objectives record captures those measurable targets and the review stages meant to hit them. Auditors probe whether the objectives are measurable, accuracy above what threshold, tested how, or whether they are aspirational language copied from a policy template with no acceptance criteria attached to any real project.

Common gaps

Objectives like fairness or robustness are stated but have no measurable threshold or acceptance test attached.
The procedure exists for internally built AI but was never applied to a purchased or configured vendor AI tool.
Objectives were set once at project kickoff and never checked against what was ultimately delivered.

Questions your auditor will ask

What measurable objectives does this AI initiative have?
Documented targets, for example an accuracy floor or a required human review step, recorded in the responsible AI development procedure.
Do these objectives apply to purchased AI tools, not only internally built ones?
Yes, adopting a vendor tool triggers the same objective-setting step before it is approved for use.
Who checks whether an objective was met before release?
The review stage named in the procedure, for example a risk or testing reviewer, confirms the acceptance criteria before go-live.
How is this different from a general secure development policy?
It adds AI-specific criteria, such as fairness or transparency targets, on top of the existing security requirements already built into development.

Where regulation demands it

NIS2 art. 6.2 (Secure development life cycle) requires exactly this, extended for an AI initiative to responsible-AI objectives set before build begins.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.6.1.2?”
Also via MCP, free with account