SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.8.5Information for interested parties

Identify interested parties and provide the AI information each needs to understand impacts, rights, responsibilities and recourse.

Mapping at a glance
A.8.5Information for interested partiesISO/IEC 42001:2023 — Annex A

A.8.5 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI transparency and external reporting plan
The map of the parties interested in the company's AI (customers, regulators, partners, affected individuals, staff) with the information about impacts, rights and recourse each one needs, plus the rules for when and how AI information is reported externally.
From the Sekit evidence catalog

In practice

This control is about mapping who is affected by an AI system, customers, job candidates, employees, the public, and giving each group the specific information they need about impacts, rights and how to get help if something goes wrong. A recruitment AI screening applicants needs to tell those applicants that AI is involved and how they can ask for a human review. An auditor asks for the AI transparency and external reporting plan and checks whether it lists real groups with real information needs, not a generic privacy notice repurposed for AI. The common gap is a company that has a solid privacy notice for data collection but nothing that addresses AI-specific rights like contesting an automated decision.

Common gaps

The privacy notice covers data collection in general but says nothing about a specific AI system making automated decisions about the person.
Affected individuals are never told they can request a human review of an AI-assisted decision that affects them.
The interested-parties map lists customers and regulators but skips employees affected by an internal AI tool, like one used in performance review.

Questions your auditor will ask

Do affected individuals know an AI system is involved in a decision about them?
The transparency plan names each interested party and the specific AI-related information they are given, including that automated processing is taking place.
Can someone ask for a human review of an AI decision?
The plan documents the right to contest or request human review of an AI-assisted decision as part of what affected individuals are told.
Is your privacy notice specific about AI processing, or generic?
Privacy notices are reviewed on a fixed cadence to match current processing; that review should confirm AI-specific processing is named, not folded into general language.
Who besides customers is affected by your AI systems?
The interested-parties map covers employees and other internal groups affected by an AI tool, not only external customers and regulators.

Where regulation demands it

GDPR Article 13 requires telling people what happens to their data at the point of collection; where an AI system is part of that processing, that fact belongs in the notice.
Ask Sekura: “What evidence proves A.8.5?”
Also via MCP, free with account