Orphaned Account Checker

ISO/IEC 42001: what it asks of an account list

ISO/IEC 42001 asks for roles, responsibilities and authorities to be allocated and made known (clause 5.3) and for AI roles and responsibilities to be defined (A.3.2). Its lines read here on AI agent credentials only: an agent acts through a credential someone has to own.

When to tick it: tick it when the company runs an AI management system to ISO/IEC 42001; its lines read on agent credentials only.

Findings that cite it

FindingClause
11. AI agent credential with no owner or no reviewISO/IEC 42001 clause 5.3 (every account type)
ISO/IEC 42001 A.3.2 (every account type)

ISO/IEC 42001: every clause cited

2 of the 74 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

ISO/IEC 42001 clause 5.3Roles, responsibilities and authorities

Top management must make sure relevant roles have their responsibilities and authorities allocated and made known, and must assign responsibility and authority for keeping the AIMS conformant with the standard and for reporting AIMS performance to top management (control A.3.2 addresses AI roles).

What an auditor asks to see: Role descriptions or RACI for AIMS roles; Named owner for AIMS conformity; Named owner for AIMS performance reporting; Communication of roles
Where account lists usually fall short: No one assigned to report AIMS performance to top management; Roles assigned but not communicated
Source: ISO/IEC 42001:2023
ISO/IEC 42001 A.3.2AI roles and responsibilities

Define and allocate AI roles and responsibilities according to the organization's needs.

What an auditor asks to see: AI roles and responsibilities matrix; Coverage of human oversight, security, privacy, safety, performance, development, suppliers, legal compliance, data quality, assets and resources, impact assessment and risk management; Evidence roles were assigned considering policy, objectives and risks
Where account lists usually fall short: No role owns human oversight; Data quality responsibility undefined across the life cycle
Source: ISO/IEC 42001:2023