ISO/IEC 42001 Evidence: How Asqav Receipts Map To The AI Management System

ISO/IEC 42001:2023 is the international management-system standard for artificial intelligence. It asks an organisation to run an AI management system (AIMS): document its AI processes, keep records of operation, and produce evidence on audit that the controls it claims are in place.

Asqav does not run your AIMS. It produces the signed, tamper-evident record layer an ISO 42001 auditor reads when checking the operational-evidence clauses of the standard.

What this page maps: the ISO/IEC 42001 control areas that touch operational records, against the Asqav wire fields and reports that already ship in production.

Where the line sits: Asqav is the notary and evidence layer, not the management system. The iso_42001 taxonomy entries on a receipt are caller-supplied, not Asqav-verified.

Where Asqav fits in an ISO 42001 audit

ISO/IEC 42001 separates two jobs:

Those records are what an auditor inspects, and a self-attested log is weak evidence because the party under audit also holds the pen.

Asqav signs each AI action into a receipt that the producing party cannot later edit, and it publishes the verify key independently of the producer. The auditor gets an evidence trail whose integrity does not depend on trusting the audited party's storage.

The iso_42001 taxonomy field

Asqav carries an optional iso_42001 wire field on every receipt. It is a list of ISO/IEC 42001 Annex A control ids (for example A.6.2.6) that the producer asserts the action maps to.

The field is self-declared. The cloud does not check that A.6.2.6 is a real Annex A id, and it does not certify that the action satisfies that control. It preserves the caller's claim verbatim inside the signed envelope and marks it as producer-declared, so a downstream auditor knows the mapping came from the producer, not from Asqav. The signed binding guarantees the receipt was issued against THAT control claim, not a later claim that papered over a missed control.

The field is published on /.well-known/governance.json and specified in draft-marques-asqav-compliance-receipts on the IETF Datatracker.

Mapping ISO 42001 record clauses to Asqav

Clause 7.5 Documented information and Clause 9.1 monitoring records

ISO/IEC 42001 Clause 7.5 requires documented information to be controlled, protected, and available. Clause 9.1 requires records of monitoring and measurement results. Asqav's signed receipt is the record:

Clause 8 Operation: evidence the controls ran

Clause 8 asks the organisation to plan, implement, and control the processes needed to meet AIMS requirements. Asqav's controls_evaluated field records which enforcement controls genuinely fired on each signed action:

The omission-over-false design is the load-bearing property for ISO 42001 evidence: the receipt never claims a control ran without that control having run.

Clause 9.2 Internal audit and Clause 10 Improvement

Internal audit and corrective action need a trail an auditor can replay. Asqav's audit trail and incident records carry it. Where the producer accepts a residual risk rather than blocking, the protectmcp:lifecycle:risk_acceptance receipt type records who accepted what and when, inside the same signed chain. Where a configuration changes, the protectmcp:lifecycle:configuration_change receipt type binds the before-and-after manifest digest.

Generated evidence reports

Asqav ships generated evidence reports that overlap the AI-governance scope an ISO 42001 audit examines, including a dedicated ISO/IEC 42001 evidence report alongside the NIST AI Risk Management Framework report and the EU AI Act Annex IV technical-documentation report. Each report assembles the underlying signed receipts into an auditor-readable document. The iso_42001 taxonomy field and the audit-pack export add further ISO-specific evidence surface.

What Asqav does not do

Asqav is not an AI management system and does not certify ISO/IEC 42001 conformance. It does not author your AI policy, run your risk assessments, or maintain your Statement of Applicability. It does not validate that an iso_42001 control id is real or that the action satisfies that control. ISO 42001 certification is issued by an accredited certification body after an audit. Asqav supplies evidence that audit reads, it does not replace it.

Related documentation