| Annex A Reference | Control Name | Implementation Status | Evidence | Gaps / Notes | Owner |
|---|---|---|---|---|---|
A.5.3 |
AI System Impact Assessment | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
A.6.1.3 |
Responsible AI Design & Development | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
A.6.1.4 |
AI System Documentation | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
A.6.2.4 |
AI System Testing & Validation | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
A.6.2.6 |
AI System Deployment Criteria | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
A.6.2.8 |
AI System Event Logging | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
A.7.2 |
Data Quality for AI | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
A.7.3 |
Data Provenance | PARTIALLY IMPLEMENTED | 1 lower-severity finding mapped to this control. | 1 open finding — see Gap Plan | [ORG TO COMPLETE: Control owner] |
A.7.4 |
Data Preparation | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
A.7.5 |
Data Acquisition | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
A.8.2 |
AI System Transparency | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
A.8.4 |
Reporting AI System Issues | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
A.9.2 |
AI System Use Procedures | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
A.9.3 |
Human Oversight of AI | NOT ASSESSED — outside code scanning scope | Not covered — RepoScope has no code-level detector for this control. | Requires organizational evidence | [ORG TO COMPLETE: Control owner] |
A.9.4 |
AI System Monitoring | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
A.10.2 |
Third-Party AI Components | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
A.10.3 |
Supply Chain Security | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
Disclaimer: Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.
Note: Code-level AI management controls only. ISO/IEC 42001 requires organizational policies, risk assessments, and process evidence that are beyond the scope of code scanning. This is a development aid for identifying code-level control gaps, not a certification tool — consult a qualified auditor for formal certification.