ISO/IEC 42001: what it asks of an account list
ISO/IEC 42001 asks for roles, responsibilities and authorities to be allocated and made known (clause 5.3) and for AI roles and responsibilities to be defined (A.3.2). Its lines read here on AI agent credentials only: an agent acts through a credential someone has to own.
When to tick it: tick it when the company runs an AI management system to ISO/IEC 42001; its lines read on agent credentials only.
Findings that cite it
| Finding | Clause |
|---|---|
| 11. AI agent credential with no owner or no review | ISO/IEC 42001 clause 5.3 (every account type) ISO/IEC 42001 A.3.2 (every account type) |
ISO/IEC 42001: every clause cited
2 of the 74 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
ISO/IEC 42001 clause 5.3Roles, responsibilities and authoritiesTop management must make sure relevant roles have their responsibilities and authorities allocated and made known, and must assign responsibility and authority for keeping the AIMS conformant with the standard and for reporting AIMS performance to top management (control A.3.2 addresses AI roles).
ISO/IEC 42001 A.3.2AI roles and responsibilitiesDefine and allocate AI roles and responsibilities according to the organization's needs.