SCRM Supplier Compliance & Risk Management

Home

ISO/IEC 42001:2023 · Annex A.10

With an AI model you usually do not even know where the data came from.

ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence. Its annex gives third parties and customers a section of their own – for good reason.

Almost nobody builds AI entirely in-house. Models, training data, interfaces and operating platforms come from others. Responsibility spreads across a chain in which each party sees only a slice – which is exactly what the standard addresses.

It therefore requires roles and responsibilities along that chain to be allocated explicitly, requirements to be placed on providers, and the provenance of the data in use to be known. Anyone watching the EU AI Act will find the matching foundation here.

Where the chain breaks

  • Model providers whose training data provenance is undocumented.
  • Interfaces to services that further process user input.
  • Bought-in components whose behaviour changes with an update.
  • Unclear accountability between provider and deployer when something goes wrong.

What the annex requires

A.10.2
Explicitly allocate responsibilities among the parties in the AI chain.
A.10.3
Define and verify requirements for suppliers of AI systems and components.
A.10.4
Provide customers and users with the information needed for responsible use.
A.7
Understand the provenance, quality and permitted use of the data in play.
A.6
Govern the life cycle from development to retirement, supplied parts included.

How SCRM covers it

Provider per component

Model, platform and data source as separate records with an owner.

Commitments and evidence

Declarations on data provenance and usage rights with validity.

Track changes

Model and version changes as events, not silent adjustments.

Responsibility matrix

Who answers for what, recorded before the first incident asks.

Frequently asked

Do we need 42001 if we only buy AI?

Nobody has to certify. But the standard’s questions arise in mere use too: who is liable, where does the data come from, what happens when the model changes.

How does it relate to the EU AI Act?

The AI Act is law, the standard a management system. A system run to 42001 makes many obligations easier to evidence but does not replace legal assessment.

Is ISO 27001 enough?

For information security yes, for AI-specific questions no. Data provenance, model behaviour and allocation of responsibility do not appear there.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required