49% of ISO/IEC 42001:2023 you already have
ISO/IEC 23894:2023 already covers about 49% of ISO/IEC 42001:2023, leaving
40 of 78 controls as genuinely new work.
Already covered 10
Likely covered 28
New work 40
What is genuinely new work
Nothing in ISO/IEC 23894:2023 reaches these. This is the list to scope.
A.10.2Confidentiality obligations of personnel
A.10.3Restriction of creation of hardcopy material
A.10.4Control and logging of data restoration
A.2.3Alignment with other organizational policies
A.2.4Review of the AI policy
A.3.3Reporting of concerns
A.4.2Resource documentation
A.4.5System and computing resources
A.5.3Documentation of AI system impact assessments
A.5.4Assessing AI system impact on individuals or groups
A.5.5Assessing societal impacts of AI systems
A.6.1.1Objectives for responsible development of AI systems
A.6.1.2Processes for responsible AI system design and development
A.6.2.2AI system requirements and specification
A.6.2.3Documentation of AI system design and development
A.6.2.4AI system verification and validation
A.6.2.5AI system deployment
A.6.2.6AI system operation and monitoring
A.6.2.7AI system technical documentation
A.6.2.8AI system event logging
A.7.2Data for development and enhancement of AI systems
A.8.5Information for interested parties
A.9.2Processes for responsible use of AI systems
A.9.3Objectives for responsible use of AI system
A.9.4Intended use of the AI system
6.2Objectives and planning to achieve them
7.5.3Control of documented information
8.3AI system lifecycle management
8.5Information for interested parties of AI systems
8.7Third-party and customer relationships
9.1Monitoring, measurement, analysis and evaluation
A.10Third-party and customer relationships
A.5Assessing impacts of AI systems
A.8Information for interested parties of AI systems
Show the 38 you already have
A.5.2AI system impact assessment process
10.1Continual improvement
4.1Understanding the organization and its context
5.1Leadership and commitment
5.3Roles, responsibilities and authorities
6.1.4AI system impact assessment
8.2AI system impact assessment
A.3.2AI roles and responsibilities
A.7.4Quality of data for AI systems
A.8.2System documentation and information for users
A.8.4Communication of incidents
10.2Nonconformity and corrective action
4.2Understanding the needs and expectations of interested parties
4.3Determining the scope of the management system
6.1Actions to address risks and opportunities
7.5Documented information
7.5.2Creating and updating
8.1Operational planning and control
A.2Policies related to AI
A.4Resources for AI systems
How this is calculated
Already covered means a mapping runs from a control in ISO/IEC 23894:2023 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition