ISO 42001 A.9: Use of AI systems
Responsible-use controls and monitoring
AIGE-OBL-ISO42001-A9. Drawn from chapter 08.
Text alternative
- Clause: ISO 42001, A.9.
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Runtime guardrails.
- Layer: Layer 04 Runtime Controls & Observability.
- Evidence record: Agent register entry, +1 more.
- Record schemas: Agent register entry , Deployment decision record .
- The same topic in 19 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-ISO42001-A9- Instrument
- ISO/IEC 42001 standard
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs ISO 42001
- Clause
- A.9
- Applies from
- No date Voluntary · Voluntary management-system standard (2023); no presumption of conformity
The artefact that evidences it
Runtime guardrails; usage telemetry.
Patterns that build it
- Use-Case Intake & Risk Tiering (layer 1 and 2)
- Decision Notice & Contest Path (layer 4 and 5)
- Sanctioned AI Gateway (layer 4 and 2)
- Downstream Use Register (layer 2 and 1)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Human oversight
- EU AI Act Art. 14 Human oversight (core)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval (core)
- GDPR Art. 22 Automated individual decision-making, including profiling (core)
- NIST AI RMF MAP 3.5 MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function (core)
- CSA AICM GRC-15 Human supervision (core)
- Korea AI Act Art. 34(1)(4) Human management and supervision (core)
- UK DUAA UK GDPR Art. 22C Safeguards for automated decision-making (core)
- UK ATRS ATRS 2.3.2 Human review (core)
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight (core)
- GAO AI Accountability 3.9 Human supervision: define and develop procedures for human supervision of the AI system (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- China Algo. Rec. AlgoRec Art. 17 User option to switch off
- China GenAI Measures GenAI Art. 10 User guidance and protection
- EU AI Act Art. 14(4)(b) Awareness of automation bias
- OWASP Agentic ASI09 Human-Agent Trust Exploitation
- CoE Convention CoE Art. 8 Transparency and oversight
- OECD AI Principles OECD 1.2(b) Human agency and oversight safeguards
Runtime guardrails
- NIST AI RMF MANAGE 2 MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by relevant AI actors (core)
- TC260 Framework 3.0 TC260 App. 2 II.5 Dynamic runtime management (core)
- TC260 Framework 3.0 TC260 3.2.1 Technological countermeasures for agentic AI (core)
- China GenAI Measures GenAI Art. 10 Guided, bounded use (core)
- China GenAI Measures GenAI Art. 14 Stop unlawful generation (core)
- China Deep Synthesis DeepSyn Art. 10 Input and output review (core)
- CSA AICM TVM-13 Guardrails (core)
- CSA AICM AIS-09 Input Validation (core)
- CSA AICM AIS-10 Output Validation (core)
- OWASP LLM LLM01:2026 Prompt Injection (core)
- OWASP LLM LLM10:2026 Improper Output Handling (core)
- Singapore Agentic Agentic 2.3.1 During design and development, use technical controls (core)
- EU AI Act Art. 5 Prohibited AI practices
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity
- ISO 42001 A.6 AI system life cycle
- China Algo. Rec. AlgoRec Art. 8 Periodic algorithm review
- China Algo. Rec. AlgoRec Art. 9 Feature database for unlawful content
- EU AI Act Art. 5(1)(a)–(b) Manipulative techniques; exploitation of vulnerabilities
- GPAI Code Safety C5 Commitment 5: Safety mitigations
- OWASP LLM LLM06:2026 Unbounded Consumption
Prohibited practices
- EU AI Act Art. 5 Prohibited AI practices (core)
- CoE Convention CoE Art. 16(4) Assess the need for a moratorium, ban or other measures for incompatible uses (core)
- NIST AI RMF GOVERN 1.1 GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented
- CSA AICM GRC-09 Acceptable Use of the AI Service
- CSA AICM HRS-15 AI Acceptable Use
- Singapore Agentic Agentic 2.1.1 Determine suitable use cases for agent deployment
- China GenAI Measures GenAI Art. 4 Prohibited content and baseline duties
Deployment, change and decommissioning
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems (core)
- ISO 42001 A.6.2.5 AI system deployment (core) (clause not verified)
- ISO 42001 A.6.2.6 AI system operation and monitoring (core) (clause not verified)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- NIST AI RMF MANAGE 4.1 MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management (core)
- NIST AI RMF GOVERN 1.7 GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness (core)
- CSA AICM AIS-06 Secure Application Deployment (core)
- EU AI Act Art. 25 Responsibilities along the AI value chain
- EU AI Act Art. 43(4) New conformity assessment on substantial modification
- EU AI Act Art. 20 Corrective actions and duty of information
- EU AI Act Art. 79 Procedure at national level for dealing with AI systems presenting a risk
- EU AI Act Art. 86 Right to explanation of individual decision-making
- CSA AICM CCC-01 Change Management Policy and Procedures
- CSA AICM DSP-02 Secure Disposal
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified
- OECD AI Principles OECD 1.4 Robustness, security and safety
- TC260 Framework 3.0 TC260 5.3 Operators' safety guidelines
- TC260 Framework 3.0 TC260 5.3.19 Re-assessment on material change
- GAO AI Accountability 4.4 Ongoing assessment: assess the utility of the AI system to ensure its relevance to the current context
- GAO AI Accountability 4.5 Scaling: identify conditions, if any, under which the AI system may be scaled or expanded beyond its current use
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-DATA-012Registered Downstream Consumers of Outputs (Data admission and privacy profile)
Source
Chapter 08, section ISO/IEC 42001, 42005 and 42006, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-iso42001-a9.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). ISO 42001 A.9: Use of AI systems (AIGE-OBL-ISO42001-A9). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{ISO 42001 A.9: Use of AI systems (AIGE-OBL-ISO42001-A9)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9},
note = {Version 0.5.0}
}