Customer developer docs

ISO/IEC 42001:2023 — Extended Clauses 5, 6, 7

ISO/IEC 42001 Clauses 5, 6, 7 — leadership, planning, support, and data quality/provenance via signed training-data lineage.

ISO/IEC 42001:2023 — Extended Clauses 5, 6, 7

This mapping extends the Clause 8 baseline with the leadership, planning, support, and documentation clauses that complete the ISO/IEC 42001 AI Management System requirements. Ledgix evidences each clause via policy snapshots, human-principal attributions, the framework mapping document, and signed training-data lineage records.

Status: Full — every control resolves to an artifact Ledgix produces today following the Phase 9 training-data lineage shipping.

Scope

Clauses 5, 6, and 7 address leadership and commitment, the AI policy, roles and responsibilities, planning of actions to address risks and opportunities, risk treatment, competence, communication, documented information, and data quality/provenance. Ledgix's policy lifecycle, per-decision accountability metadata, and the signed evidence pack satisfy each clause.

Controls covered

FieldTypeRequiredDescription
ISO42001-5.1policy_snapshotsLeadership and CommitmentSigned and versioned policies demonstrate documented top-management commitment.
ISO42001-5.2policy_snapshotsAI PolicyAI policy versions preserved with content hashes.
ISO42001-5.3events_jsonlRoles, Responsibilities, and AuthoritiesPer-action accountable-actor identification (agent_id, human_principal).
ISO42001-6.1.1policy_snapshots / events_jsonlActions to Address Risks and Opportunities — GeneralRisk-driven policy rules as planned actions; denial decisions instantiate the planned response.
ISO42001-6.1.3policy_snapshotsAI Risk TreatmentPolicy-encoded risk treatments; structured impact assessments available for deeper coverage.
ISO42001-7.2events_jsonlCompetenceHuman-principal attributions across HITL decisions support competence records.
ISO42001-7.4framework_mapping / signaturesCommunicationExportable, human-readable mapping plus signed evidence pack supports external communication.
ISO42001-7.5policy_snapshots / framework_mapping / checkpoint_chainDocumented InformationVersioned policies, the framework mapping, and the operational log constitute documented information.
ISO42001-7.6training_data_lineage / dataset_sheets / model_cardsData Quality and Provenance for AI SystemsSigned lineage records, dataset sheets, and model cards covering every model reference.

Evidence types referenced

Known gaps (if any)

None — every control resolves to an artifact Ledgix produces today. Clause 6.1.3 risk-treatment coverage is richer for tenants that have authored structured impact assessments from the Phase 4 module.

Audit pack workflow

Export an evidence ZIP for this framework from the admin console's Evidence Exports panel by selecting ISO/IEC 42001:2023 — Extended Clauses 5, 6, 7 and a time window. Each control's evidence_locators[] in the included framework_mapping.json points to the corresponding file in the ZIP.

References