SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.8.2System documentation and information for users

Give users accurate, accessible information about intended use, capabilities, limitations, human oversight and safe operation.

Mapping at a glance
A.8.2System documentation and information for usersISO/IEC 42001:2023 — Annex A

A.8.2 is covered by 1 Sekit CSF control. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI system documentation for users
The material the company gives to the people who use the AI system: what it is for, what it cannot do, its known limitations, how to interpret and challenge its outputs, and how the person is told they are dealing with AI.
From the Sekit evidence catalog

In practice

This is the material given to the people using an AI system: what it does, what it does not do, its known limitations, how to challenge or question its output, and a clear signal that they are dealing with AI rather than a person. A firm rolling out an AI drafting tool to staff needs a short, plain-language guide, not the vendor's technical manual. An auditor asks to see the AI system documentation for users and checks it against what staff received: was it handed out, is it current, do people know it exists. The common gap is a policy document written for the file that was never shared with the people using the tool.

Common gaps

Users are pointed to the vendor's technical manual instead of a plain-language guide covering what the tool cannot do and how to challenge its output.
Documentation for an AI tool exists in a policy folder but was never distributed to the staff who use the tool daily.
Nobody tells users they are interacting with an AI system rather than a person, so there is no record they were informed.

Questions your auditor will ask

What do users of this AI system know about its limitations?
The AI system documentation for users names known limitations in plain language and is distributed before the tool goes into use, not buried in a policy folder.
How does a user know they are dealing with AI, not a person?
User documentation includes a clear statement that the interaction involves an AI system, part of the same package covering intended use and limitations.
Can users challenge or question an AI output they disagree with?
The documentation explains how to interpret and challenge outputs, giving users a defined path rather than leaving them to guess.
How do you know this documentation reached the people using the tool?
Distribution is treated as evidence to retain, so there is a dated record of who received the current version and when.

Where regulation demands it

GDPR accountability (5.2) means being able to show, not only state, that users were informed about how an AI system works and what it cannot do.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.2?”
Also via MCP, free with account