ISO/IEC 42001:2023 · Annex A.10
With an AI model you usually do not even know where the data came from.
ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence. Its annex gives third parties and customers a section of their own – for good reason.
Almost nobody builds AI entirely in-house. Models, training data, interfaces and operating platforms come from others. Responsibility spreads across a chain in which each party sees only a slice – which is exactly what the standard addresses.
It therefore requires roles and responsibilities along that chain to be allocated explicitly, requirements to be placed on providers, and the provenance of the data in use to be known. Anyone watching the EU AI Act will find the matching foundation here.
Where the chain breaks
- Model providers whose training data provenance is undocumented.
- Interfaces to services that further process user input.
- Bought-in components whose behaviour changes with an update.
- Unclear accountability between provider and deployer when something goes wrong.
What the annex requires
- A.10.2
- Explicitly allocate responsibilities among the parties in the AI chain.
- A.10.3
- Define and verify requirements for suppliers of AI systems and components.
- A.10.4
- Provide customers and users with the information needed for responsible use.
- A.7
- Understand the provenance, quality and permitted use of the data in play.
- A.6
- Govern the life cycle from development to retirement, supplied parts included.
How SCRM covers it
Provider per component
Model, platform and data source as separate records with an owner.
Commitments and evidence
Declarations on data provenance and usage rights with validity.
Track changes
Model and version changes as events, not silent adjustments.
Responsibility matrix
Who answers for what, recorded before the first incident asks.
Frequently asked
Do we need 42001 if we only buy AI?
Nobody has to certify. But the standard’s questions arise in mere use too: who is liable, where does the data come from, what happens when the model changes.
How does it relate to the EU AI Act?
The AI Act is law, the standard a management system. A system run to 42001 makes many obligations easier to evidence but does not replace legal assessment.
Is ISO 27001 enough?
For information security yes, for AI-specific questions no. Data provenance, model behaviour and allocation of responsibility do not appear there.