ISO/IEC 42001:2023
Annex A AIMS controls - A.8 Information for interested parties of AI systems

ISO/IEC 42001:2023 A.8.4: Communication of incidents

Work out and write down how incidents will be communicated to the people using the AI system.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 60 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

EU AI Act · 3 controls

  • EUAI-Art.20 Corrective actions and duty of information
  • EUAI-Art.55 Obligations of providers of GPAI models with systemic risk
  • EUAI-Art.73 Reporting of serious incidents

ISO 27001:2022 · 3 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents

SOC 2 · 3 controls

  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC7.5 CC7.5 Recovering from security incidents
  • SOC2-P6.6 P6.6 Notifying breaches and incidents

APRA CPS 234 · 2 controls

  • CPS234-P24 Information Security Response Plans
  • CPS234-P25 Response Plan Content and Escalation Mechanisms

FedRAMP High · 2 controls

  • IR-6 Incident Reporting
  • IR-8 Incident Response Plan

FedRAMP Moderate · 2 controls

  • IR-6 Incident Reporting
  • IR-8 Incident Response Plan

ISO 27002:2022 · 2 controls

  • 5.24 Information security incident management planning and preparation
  • 5.27 Learning from information security incidents
  • ISO-37002-7.4 Communication
  • ISO37002-7.4 Communication
  • ISO-41001-7.4 Communication
  • ISO41001-7.4 Communication
  • ISO-50001-7.4 Communication
  • 7.4 Communication

ISO/IEC 27003:2017 · 2 controls

  • AIRMF-MN-2.3 Procedures are followed to respond to and recover from a previously unknown risk when it is identified
  • AIRMF-MN-4.3 Incidents and errors are communicated to relevant AI actors including affected communities, and processes for tracking, responding to, and recovering from incidents and errors are followed and documented
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents

AICPA SOC 3 · 1 control

  • SOC3-COMMS Communication
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • BS65000-7.4 Communication

CIS Controls v8 · 1 control

  • CIS-17.6 Define Mechanisms for Communicating During Incident Response

CMMC 2.0 · 1 control

DORA · 1 control

ISO 13485:2016 · 1 control

ISO 14001:2015 · 1 control

  • 7.4 Communication

ISO 14004:2016 · 1 control

  • 7.4 Communication

ISO 22000:2018 · 1 control

  • 7.4 Communication

ISO 22301:2019 · 1 control

  • 7.4 Communication

ISO 27701:2019 · 1 control

ISO 30401 · 1 control

  • ISO30401-7.4 Communication

ISO 37001:2016 · 1 control

  • 7.4 7.4 Communication

ISO 37301:2021 · 1 control

  • 7.4 Communication
  • ISO-39001-7.4 Communication

ISO 45001:2018 · 1 control

  • 7.4 Communication

ISO 55001:2014 · 1 control

  • 7.4 Communication

ISO 56002 · 1 control

  • ISO-56002-7.4 Communication

ISO 9001:2015 · 1 control

  • 7.4 Communication
  • 7.3 7.3 Report AI related incidents

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A AIMS controls - A.8 Information for interested parties of AI systems

You are reading one control. How much of ISO/IEC 42001:2023 have you already done?

ISO/IEC 42001:2023 A.8.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO/IEC 42001:2023 your existing evidence covers. Hold NIST AI Risk Management Framework (AI RMF 1.0) and 30 of 38 ISO/IEC 42001:2023 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST AI Risk Management Framework (AI RMF 1.0) pair alone.

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.