Acme Corp's codebase was assessed against the AI management system (AIMS) controls of ISO/IEC 42001:2023 (Annex A) (ISO/IEC 42001:2023 2023) using automated code-level analysis. The assessment covers 17 controls, of which 9 are testable at the code level (53% coverage).
A.7.3 Data Provenance — 1 finding(s), severity MediumThis assessment covers CODE-LEVEL controls only. The following areas require separate, organizational assessment:
A.5.3 AI System Impact AssessmentA.6.2.4 AI System Testing & ValidationA.6.2.6 AI System Deployment CriteriaA.7.2 Data Quality for AIA.7.4 Data PreparationA.8.4 Reporting AI System IssuesA.9.2 AI System Use ProceduresA.9.3 Human Oversight of AIDisclaimer: Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.
Note: Code-level AI management controls only. ISO/IEC 42001 requires organizational policies, risk assessments, and process evidence that are beyond the scope of code scanning. This is a development aid for identifying code-level control gaps, not a certification tool — consult a qualified auditor for formal certification.
I, the undersigned, have reviewed the above assessment and confirm that:
Name: Dana Lee
Title: Chief Information Security Officer
Signature: ____________________
Date: ____________________