ISO 42001 A.4: Resources for AI systems
Data, tooling, compute, human resources documented
AIGE-OBL-ISO42001-A4. Drawn from chapter 08.
Text alternative
- Clause: ISO 42001, A.4.
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Resource inventory.
- Layer: Layer 02 Inventory & Transparency.
- Evidence record: AI system register entry.
- Record schemas: AI system register entry .
- The same topic in 16 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-ISO42001-A4- Instrument
- ISO/IEC 42001 standard
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs ISO 42001
- Clause
- A.4
- Applies from
- No date Voluntary · Voluntary management-system standard (2023); no presumption of conformity
The artefact that evidences it
Resource inventory; AIBOM; environment manifests.
Patterns that build it
No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Data governance
- EU AI Act Art. 10 Data and data governance (core)
- ISO 42001 A.7 Data for AI systems (core)
- TC260 Framework 3.0 TC260 2.1.3 Data safety risks (core)
- China GenAI Measures GenAI Art. 7 Training-data lawful sourcing (core)
- China GenAI Measures GenAI Art. 8 Data-annotation standards (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- China Deep Synthesis DeepSyn Art. 14 Training-data management (core)
- GB/T 45654 GB/T 45654 Corpus security Training-corpus (data) security requirements (core) (clause not verified)
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- GDPR Art. 5(1)(c) Data minimisation (core)
- GDPR Art. 25 Data protection by design and by default (core)
- ISO 42001 A.7.3 Acquisition of data (core) (clause not verified)
- CSA AICM DSP-20 Data Provenance and Transparency (core)
- UK ATRS ATRS 2.4.3 Development data specification (core)
- Singapore GenAI GenAI 2 Data (core)
- GAO AI Accountability 2.1 Sources: document sources and origins of data used to develop the models (core)
- GAO AI Accountability 2.2 Reliability: assess reliability of data used to develop the models (core)
- EU AI Act Art. 4a Special-category data for bias detection
- NIST AI RMF MAP 2 MAP 2: Categorization of the AI system is performed
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system is examined and documented
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias are evaluated and results are documented
- TC260 Framework 3.0 TC260 5.1 Model R&D safety guidelines
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations
- EU AI Act Art. 5(1)(e) Prohibited: untargeted scraping of facial images
- GPAI Code Copyright 1.1–1.5 Commitment 1: Copyright policy (Measures 1.1 to 1.5)
- GDPR Art. 9 Processing of special categories of personal data
- CSA AICM DSP-21 Data Poisoning Prevention & Detection
- OWASP LLM LLM05:2026 Data and Model Poisoning
- GAO AI Accountability 2.4 Variable selection: assess data variables used in the AI component models
- GAO AI Accountability 2.5 Enhancement: assess the use of synthetic, imputed, and/or augmented data
Inventory and registration
- EU AI Act Art. 49 Registration (core)
- EU AI Act Art. 71 EU database for high-risk AI systems (core)
- NIST AI RMF GOVERN 1.6 GOVERN 1.6: Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities (core)
- China Algo. Rec. AlgoRec Art. 24 Algorithm filing (core)
- China Deep Synthesis DeepSyn Art. 19 Filing for public-opinion services (core)
- China GenAI Measures GenAI Art. 17 Algorithm filing (core)
- UK ATRS ATRS Tier 1 Summary information (the published record) (core)
- EU AI Act Art. 6 Classification rules for high-risk AI systems
- TC260 Framework 3.0 TC260 App. 2 II.2 Identity and access management
- TC260 Framework 3.0 TC260 4.4.1 CII registration and filing
- EU AI Act Art. 3(1) Definition of an AI system
- EU AI Act Art. 52 Procedure
- NIST AI RMF GOVERN 1.7 GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness
- CSA AICM STA-08 Supply Chain Inventory
- CSA AICM IAM-03 Identity Inventory
- Korea AI Act Art. 33 Confirmation of high-impact AI
- GAO AI Accountability 3.1 Documentation: catalog model and non-model components, along with operating specifications and parameters
Source
Chapter 08, section ISO/IEC 42001, 42005 and 42006, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-iso42001-a4.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). ISO 42001 A.4: Resources for AI systems (AIGE-OBL-ISO42001-A4). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a4. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{ISO 42001 A.4: Resources for AI systems (AIGE-OBL-ISO42001-A4)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a4},
note = {Version 0.5.0}
}