Crosswalks / ISO/IEC 42001
ISO/IEC 42001 — execution-evidence crosswalk
- Source version
- ISO/IEC 42001:2023
- Crosswalk version
- iso-iec-42001@1.0.0
- Source authority
- ISO/IEC — published standard metadata
- Last reviewed
- 2026-08-13
What ISO/IEC 42001 is
A management-system standard specifying requirements for establishing, implementing, maintaining and improving an AI management system (AIMS).
What AIEF is
AIEF is an independent, implementation-agnostic framework for AI execution integrity. It defines the evidence properties an AI or agent execution must have to be reconstructed, attributed and independently verified after the fact — execution artifacts, integrity protection, version pinning, retention and independent validation.
Where they overlap
Clauses concerning documented information, operational control, monitoring and evaluation, internal audit, and Annex A controls covering AI system operation and event logging all require retained, trustworthy operational records.
Where they do not
AIEF is not a management system. It says nothing about leadership commitment, policy, planning, objectives, competence, awareness, communication, supplier governance, improvement cycles or certification.
Control mapping — 7 AIEF controls, 9 mapped references
Relationship strength is stated explicitly and deliberately conservative. Where a relationship is uncertain it is downgraded rather than overstated. Provisions with no credible execution-evidence relationship are left unmapped.
| AIEF control | External reference | Relationship | Rationale | Limitation |
|---|---|---|---|---|
| AIEF-01Execution Artifact Completeness | Annex A — AI system operation and event logging controlsRecording of event logs during AI system operation | Strong supporting relevance | Annex A includes controls addressing the recording of events during AI system operation. AIEF-01 requires automatic emission of structured execution records at the point of execution. | Annex A controls are selected and justified through the organisation's own applicability process. AIEF-01 provides a capability, not the statement of applicability, the justification or the operating evidence an auditor would test. |
| AIEF-01Execution Artifact Completeness | Clause 8.1Operational planning and control — retained documented information | Supporting relevance | Operational control expects retained documented information giving confidence that processes were carried out as planned. Execution records are direct evidence of what an AI process actually did. | Execution records are one form of documented information among many. They do not evidence planning, criteria-setting or change control. |
| AIEF-01Execution Artifact Completeness | Clause 9.1Monitoring, measurement, analysis and evaluation | Supporting relevance | Evaluation of AI system performance requires an accurate record of operation. Structured execution records supply that input. | AIEF does not define what should be monitored, which metrics matter, or how results are evaluated against objectives. |
| AIEF-02Tamper-Evidence | Clause 7.5Documented information — protection from unintended alteration | Supporting relevance | Retained records are expected to be protected from loss of integrity. Tamper-evidence makes post-issuance modification of a defined protected set detectable. | Tamper-evidence detects change; it does not prevent it, and it does not address access control or storage governance. |
| AIEF-05Independent Validation Capability | Clause 9.2Internal audit | Supporting relevance | Internal audit requires objective evidence. Evidence that an auditor can verify independently of the system owner materially raises its objectivity. | AIEF-05 provides a verification path; it does not constitute an audit programme, auditor competence or audit conclusions. |
| AIEF-08Retention, Portability and Offline Verification | Clause 7.5Documented information — control, retention and availability | Supporting relevance | Documented information must remain available and suitable for use where and when it is needed. AIEF-08 requires evidence to survive export and remain verifiable independently of the originating system. | AIEF-08 does not address document control processes, versioning of policies, distribution, access authorisation or disposal governance. |
| AIEF-04Version Preservation and Context Pinning | Clause 7.5Documented information — suitability for use over time | Related consideration | Retained records are only useful if they can still be interpreted later. Version and context pinning preserves that interpretability. | This concerns the readability of execution evidence, not the organisation's wider documented-information system. |
| AIEF-06External Dependency Evidence / Tool Calls | Annex A — third-party and supplier relationship controlsUse of third-party components and services in AI systems | Related consideration | Where external services materially influence outcomes, evidence identifying those calls supports the organisation's understanding of third-party involvement. | AIEF does not assess supplier due diligence, contractual controls or third-party risk management. |
| AIEF-09Privacy, Minimization and Redaction Controls | Annex A — data management and privacy-related controlsHandling of data used by and produced from AI systems | Related consideration | Evidence records frequently contain sensitive input and output data; minimisation and redaction practices apply to them as to any other data holding. | AIEF-09 covers evidence handling only and is not a privacy management or data governance assessment. |
- Strong supporting relevance
- The AIEF capability produces evidence of the kind the external provision is concerned with. It does not satisfy the provision.
- Supporting relevance
- The AIEF capability may help provide relevant evidence, but does not itself satisfy the external requirement.
- Related consideration
- A material conceptual relationship. Satisfying one does not imply satisfying the other.
- Contextual only
- Useful context only. No evidentiary claim is made.
Limitations and source
AIEF is not a management system. It says nothing about leadership commitment, policy, planning, objectives, competence, awareness, communication, supplier governance, improvement cycles or certification.
Only clause and Annex A control identifiers plus concise original summaries are stored. No standard text is reproduced. Pinned explicitly to the 2023 edition; a future edition requires a new crosswalk version.
Authored against ISO/IEC — published standard metadata — https://www.iso.org/standard/81230.html (ISO/IEC 42001:2023). Crosswalk iso-iec-42001@1.0.0, reviewed 2026-08-13.
Run an AIEF assessment