SekitCrosswalk
ISO/IEC 42001:2023 — Annex A · derived mapping target

A.9.2Processes for responsible use of AI systems

Operate AI systems within approved conditions using trained users, human oversight, access controls and escalation procedures.

Mapping at a glance

A.9.2 is covered by 3 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

NIST CSF 2.0 counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

AI acceptable use and human oversight procedure
The operating rules for each AI system: what it is for, who may use it, valid inputs and outputs, prohibited uses, and how humans stay in control (trained users, review before decisions, restricted access, and a way to stop or override it).
From the Sekit evidence catalog

In practice

This is the operating rulebook for each AI system in daily use: who is allowed to use it, what inputs and outputs are valid, what uses are off limits, and how a human stays able to review, override or stop it. A firm using AI to draft client reports needs a rule that a human reviews the draft before it goes out, not a tool running unsupervised. An auditor asks for the AI acceptable use and human oversight procedure per system and checks whether staff using it completed the training tied to that role. The common gap is a general acceptable-use policy that mentions AI in passing but never specifies who can override an output or how.

Common gaps

A general acceptable-use policy mentions AI once but never says who is allowed to override an output or how to stop the system.
Staff use an AI drafting tool daily but never completed any training specific to that tool's risks or limits.
Human oversight is described as a principle but no procedure says at what point a person must review an AI output before it is acted on.

Questions your auditor will ask

Who is allowed to use this AI system, and for what?
The acceptable use procedure names permitted users, valid inputs and outputs, and prohibited uses per AI system, not a blanket rule across all tools.
How does a human stay in control of this AI system's output?
The procedure defines the review point before a decision is acted on and how a person can override or stop the system, per system.
Did the people using this AI system complete relevant training?
Completion is tracked and chased through the awareness training cycle, extended to cover role-specific AI use where relevant.
Do people with elevated AI-related responsibilities get extra training?
Roles carrying elevated responsibility get defined additional training delivered and verified on schedule, covering AI-specific duties where they apply.

Where regulation demands it

NIS2 art. 8.1 (Awareness raising and basic cyber hygiene) and art. 8.2 (Security training) cover how staff use AI tools day to day, not only how IT configures them.
GDPR's controller responsibility (24.1) means demonstrating appropriate measures for automated processing, which includes proof that human oversight of an AI system happens in practice.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.9.2?”
Also via MCP, free with account