SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.8.4Communication of incidents

Communicate AI incidents promptly to affected and accountable parties using defined triggers, content, channels and timelines.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Incident response plan
The plan defining how the company acts when a security incident occurs: who does what, who is notified, and within what timeframes.
Crisis communications plan
The plan defining how the company communicates during and after a serious incident: what is said to employees, customers, regulators and the public, who the spokesperson is, through which channels, and with what approved messaging.
From the Sekit evidence catalog

In practice

An AI incident, a model producing a harmful output, a chatbot leaking data, a decision that discriminates, needs the same clear notification path as any other security incident: who is told, by whom, within what deadline. A firm should be able to say who gets called if its AI vendor reports a breach at 6pm on a Friday. An auditor checks the incident response plan and crisis communications plan for an explicit reference to AI systems, not only generic IT incidents, and asks for a record of a notification sent within the promised timeframe. The common gap is an incident plan that covers ransomware and outages in detail but has never been tested against an AI-specific scenario.

Common gaps

The incident response plan lists notification deadlines for data breaches but has never been exercised against an AI-specific scenario like a harmful output.
Nobody has decided who gets notified if an AI vendor reports a problem outside normal business hours.
Notifications went to the data protection authority for a data breach, but no equivalent trigger exists for an AI system producing a discriminatory decision.

Questions your auditor will ask

Who gets notified if this AI system causes an incident, and how fast?
The incident response plan names roles and deadlines, extended to cover AI incidents such as harmful outputs or a vendor breach, not only conventional IT events.
Has this plan ever been tested against an AI-specific scenario?
Incident roles are activated and rehearsed so people know their part; testing should include at least one AI-related scenario, not only ransomware or outage drills.
What do you tell customers if an AI decision affecting them turns out to be wrong?
The crisis communications plan sets approved messaging and a spokesperson for serious incidents, applicable to an AI-caused incident the same way it covers any other.
Can you show a record of a notification sent within the required deadline?
Notification records are kept for each incident, including the recipient, channel and timestamp, so the 72-hour and other deadlines can be verified.

Where regulation demands it

GDPR gives you 72 hours to notify the supervisory authority of a breach (33.1) and requires notifying affected individuals for high-risk cases (34.1); an AI system leaking or misusing personal data runs the same clock.
Ask Sekura: “What evidence proves A.8.4?”
Also via MCP, free with account