ISO42001-A.6.2.11-01
Requirement
A.6.2.11 — Management of Third-Party AI System Components
Establish Third-Party AI Component Management Processes
Description
The organization must establish formal processes for the evaluation, selection, and management of third-party AI system components including pre-trained models, datasets, libraries, APIs, and...
Full Analysis & Evidence Requirements
Sign in to view the full obligation text, AI-generated applicability analysis, evidence checklists, and compliance mapping.
Sign In to ViewRelated Obligations
ISO42001-A.6.2.11-02
Risk Management
Assess Third-Party Component Risks
ISO42001-A.6.2.11-03
Requirement
Define Third-Party Component Requirements
ISO42001-A.6.2.11-04
Requirement
Establish Supplier Agreements
ISO42001-A.6.2.11-05
Monitoring
Monitor Third-Party Component Performance and Compliance
ISO42001-A.6.2.11-06
Documentation
Maintain Third-Party Component Documentation
Map this obligation to your AI systems
ReguLume automatically maps regulatory obligations to your system inventory, identifies compliance gaps, and generates remediation plans.
Get Started