Se rendre au contenu

Sécurité et conformité

Lynx Compliance - ISO/IEC 42001 (AI Management)

ISO/IEC 42001:2023 Artificial Intelligence Management System - clauses 4 to 10 and the full Annex A control set, cross-referenced to ISO 27001 Annex A so an existing certification carries across.

lynx_compliance_iso42001 · v19.0.1.0.0 · Complément Bêta

Ce que cela résout

Lynx Compliance - ISO/IEC 42001 (AI Management)

ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence. It follows the harmonised structure shared with ISO 27001, so clauses 4 to 10 will be familiar to anyone who has been through a 27001 audit. Annex A is where the AI-specific obligations sit.

Two design decisions in this pack are worth stating.

The clause requirements and the Annex A controls are kept in separate functions. The standard treats them differently: the clauses are requirements you must meet, Annex A is a control set you select from with a statement of applicability. Merging them would hide that distinction, and an auditor will ask about it.

Risk to the organisation and impact on people are kept apart. ISO 42001 expects both an AI risk assessment and an AI system impact assessment, and the most common failure is folding the second into the first. A classifier that is low risk to the business can be high impact on the person whose application it declines.

Key Features

  • 68 controls across five functions - clauses 4 to 10 under their own numbering, plus Annex A.2 through A.10.

  • ISO 27001 Annex A references throughout - populated wherever the AI control genuinely rests on an information security control, so a 27001 assessment propagates through the crosswalk instead of being re-answered.

  • Impact assessment routed to the PIA record - which enforces two signers for high and critical ratings, so the assessment that matters most cannot be signed off alone.

  • Lifecycle controls assessed per AI system - Annex A.6 evidence is per system, and the guidance says so, because the usual gap is the model nobody built.

  • Data provenance as a first-class control - Annex A.7 is evidenced against processing activities and cross-border transfer records, not against the model performing well.

  • Third-party AI terms called out specifically - model change notice, evaluation access and training-data provenance, which a standard security questionnaire does not cover.

Integrates With

  • lynx_compliance_certification - the ISO 27001 Annex A controls this pack references.

  • lynx_compliance_privacy - impact assessments, processing activities and transfer records evidence Annex A.5 and A.7.

  • lynx_compliance_vendor_posture - supplier assessments evidence Annex A.10.

Essayer Lynx Compliance - ISO/IEC 42001 (AI Management) de votre équipe.

Essai gratuit, sans carte de crédit. Parlez à l'équipe des ventes quand vous êtes prêt.