{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-009.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-009",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-009",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-009",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-009.json",
    "title": "Internal Audit Answered from the Evidence Store",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Internal audit of the AI management system is answered from one evidence store, the same one that answers internal audit for any management system run alongside ISO/IEC 42001, and each Annex A control listed as applicable points at the running control and the evidence stream that implement it.",
    "failureModes": [
      "Internal audit collects evidence by hand for each management system instead of querying one evidence store.",
      "An Annex A control listed as applicable in the Statement of Applicability points at no running control or evidence stream, or an exclusion carries no justification or owner.",
      "The internal audit programme does not cover the AI controls."
    ],
    "scope": "Organisations that run an AI management system to ISO/IEC 42001, alone or with ISO/IEC 27001, ISO/IEC 27701 or ISO 9001. What internal audit tests and how management review runs are not derived here: chapter 22 names clause 9 only as one evidence store answering internal audit.",
    "enforcementPoints": [
      "periodic"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Statement of Applicability generated from control metadata, each applicable control linked to its evidence stream, each exclusion with its justification and owner",
        "schemaId": null,
        "schema": null,
        "layer": 5
      },
      {
        "artefact": "Evidence records internal audit queries, filed under the registry id",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified: the source material states no failure response for this control."
    },
    "layer": 5,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "continuous-assurance-telemetry",
        "title": "Continuous Assurance Telemetry",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
      },
      {
        "slug": "machine-readable-evidence-oscal",
        "title": "Machine-Readable Evidence (OSCAL)",
        "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "continuous-assurance-telemetry",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
      },
      {
        "kind": "pattern",
        "ref": "machine-readable-evidence-oscal",
        "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
      },
      {
        "kind": "chapter",
        "ref": "principles-and-standards",
        "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
      }
    ],
    "mappings": {
      "obligations": [],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [
        "E008"
      ],
      "csaAicm": [],
      "other": [
        {
          "framework": "ISO/IEC 42001:2023",
          "ref": "9",
          "note": "Performance evaluation: one evidence store answering internal audit (clause heading as chapter 22 names it)"
        }
      ]
    },
    "references": [
      {
        "n": 18,
        "title": "Principles, soft law and standards",
        "text": "Principles, soft law and standards (AI Governance Engineering Body of Knowledge v0.5.0, chapter 22, section \"Integrating with 27001, 27701 and 9001\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/principles-and-standards#integrating-with-27001-27701-and-9001",
        "verified": "primary"
      },
      {
        "n": 19,
        "title": "Principles, soft law and standards",
        "text": "Principles, soft law and standards (AI Governance Engineering Body of Knowledge v0.5.0, chapter 22, section \"The management-system trio\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/principles-and-standards#the-management-system-trio",
        "verified": "primary"
      },
      {
        "n": 11,
        "title": "Pattern: Continuous Assurance Telemetry",
        "text": "Pattern: Continuous Assurance Telemetry (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry",
        "verified": "primary"
      },
      {
        "n": 13,
        "title": "Pattern: Machine-Readable Evidence (OSCAL)",
        "text": "Pattern: Machine-Readable Evidence (OSCAL) (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems",
        "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 9,
        "title": "AIUC-1 requirements",
        "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
        "url": "https://standard.aiuc-1.com/llms.txt",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Treat the Statement of Applicability as a generated file, not a document: each applicable Annex A control points at the running control and its evidence stream, and each exclusion carries its justification and an owner.",
      "Map each shared clause of the Harmonized Structure to one artefact serving every management system; for clause 9 that is one evidence store answering internal audit. In chapter 22's illustrative case, a team that held ISO/IEC 27001 added AI controls to its internal audit programme and generated the 42001 Statement of Applicability from the same control metadata."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "Chapter 22 names clause 9 only at heading level: which inputs and outputs of internal audit and management review should this control cover once they are read against the standard?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
