SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.6.1.3Processes for responsible design and development of AI systems

Embed risk, human oversight, data governance, testing, security and approval activities into the AI development process.

Mapping at a glance
A.6.1.3Processes for responsible design and development of AI systemsISO/IEC 42001:2023 — Annex A

A.6.1.3 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Responsible AI development procedure and objectives
The internal standard for developing or adopting AI systems responsibly: the measurable objectives each initiative must meet (accuracy, fairness, robustness, transparency) and the review stages, such as risk, data, human oversight and testing, that make those objectives real in practice.
From the Sekit evidence catalog

In practice

This is where objectives turn into a checklist a project walks through in order: was risk assessed, was there a human oversight point, was the training or vendor data reviewed, was it tested, did someone approve it. The responsible AI development procedure names these stages. A common failure is a team that skips the human oversight and data governance steps when adopting a vendor tool because "we didn't build it," even though the same review is meant to apply to configuration and integration decisions. Auditors ask to walk one project through every stage of the record.

Common gaps

Risk and data governance steps are defined for AI built in-house but skipped for vendor tools that were only configured, not coded.
The human oversight stage exists on paper but no reviewer was assigned or consulted for the last AI project.
Testing happened, but its results were never linked back to the responsible-development record for that system.

Questions your auditor will ask

Does an AI project need to walk through every stage, or can some be skipped?
Every stage in the procedure applies, including for vendor AI tools that are only configured rather than built from scratch.
Who provides human oversight during development, not only at launch?
A named reviewer assigned to the project checks risk, data and testing decisions as they happen, recorded in the project's development record.
How does data governance show up in this process for a bought AI tool?
The privacy-by-design check confirms what data the vendor tool touches and whether that use has a lawful basis, before adoption is approved.
Where does the approval to move a stage forward get recorded?
In the same development record used for the objectives, so risk, data, oversight and testing decisions are traceable to one file per system.

Where regulation demands it

NIS2 art. 6.2 (Secure development life cycle) requires secure development activities to be applied through the life cycle, which for AI extends to risk, oversight and data governance stages.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.6.1.3?”
Also via MCP, free with account