Delegation of Authority Matrix Validator
Regime

ISO/IEC 42001:2023: what it asks of an approval matrix

The AI management system controls for lines an AI agent or automation may execute: roles, allocated responsibilities, intended use, operation and event logs.

Quoted for every matrix.

ISO/IEC 42001:2023: every clause cited, quoted

5 of the 38 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

ISO/IEC 42001 A.3.2 AI roles and responsibilities

Roles and responsibilities for AI shall be defined and allocated according to the organization's needs.

What an auditor asks to see: Role descriptions; RACI matrix; Org chart; AI-specific roles (AI ethics officer, model risk manager, AI system owner, data steward); Allocation across functions; Segregation of duties where appropriate
Where matrices usually fall short: Are AI-specific roles defined or rolled into existing IT roles?
Source: ISO/IEC 42001:2023
ISO/IEC 42001 A.6.2.6 AI system operation and monitoring

AI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.

What an auditor asks to see: Operations runbooks; Monitoring dashboards; Incident logs; Drift, performance, fairness monitoring; Alerting thresholds; Incident response evidence
Where matrices usually fall short: Is monitoring active and alerts acted upon?
Source: ISO/IEC 42001:2023
ISO/IEC 42001 A.6.2.8 AI system event logging

Event logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.

What an auditor asks to see: Logging standards; Log samples; Log retention policy; Logged events (inputs, outputs, overrides, anomalies); Tamper protection; Retention aligned to regulatory requirements
Where matrices usually fall short: Are logs sufficient to reconstruct an incident or audit a decision?
Source: ISO/IEC 42001:2023
ISO/IEC 42001 A.9.4 Intended use of the AI system

The organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.

What an auditor asks to see: Intended use statements; Use case approval records; Monitoring of use; Documented intended use per system; Approval workflow for new use cases; Detection of off-label use
Where matrices usually fall short: Is off-label use detected and addressed?
Source: ISO/IEC 42001:2023
ISO/IEC 42001 A.10.2 Allocating responsibilities

Ensure responsibilities across the AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.

What an auditor asks to see: RACI or equivalent covering each life cycle stage and each external party; Contract clauses that state who is accountable for what; Evidence the allocation is reviewed when the arrangement changes
Where matrices usually fall short: Responsibilities assumed rather than allocated; Gaps where no party owns a life cycle stage; Allocation never revisited after a supplier change
Source: ISO/IEC 42001:2023