Skip to content
arrow_back
Annex A 4.2psychologyISO/IEC 42001:2023

Resource Documentation

The organisation identifies and documents the resources needed for each stage of an AI system's life cycle and for any other AI-related work it carries out. Resources include data, computing power, tooling, and the skilled people who build and run the system.

record_voice_over

Plain language

An AI system needs things to do its job, much like a new staff member needs a desk, a laptop, and access to the right files. Those things include the data the model learns from, the computing power and software that run it, and the people with the skills to build, check, and operate it. This control asks you to write down what each of those resources is, and which stage of the AI's life it belongs to (for example, gathering data, training the model, testing it, running it day to day, or retiring it). When something goes wrong, say the model starts giving poor answers, a clear written list lets you see quickly what is missing, out of date, or broken, rather than guessing.

Framework

ISO/IEC 42001:2023

Control effect

Preventative

Classifications

N/A

Official last update

01 Dec 2023

Control Stack last updated

19 June 2026

Official control statement

The organisation shall identify and document relevant resources required for the activities at given AI system life cycle stages and other AI-related activities relevant for the organisation.
psychologyISO/IEC 42001:2023Annex A 4.2
priority_high

Why it matters

Without a written record of the resources each AI activity depends on, the team relies on memory, so a single staff departure or an expired data licence can quietly stall a project. Gaps in computing power, tooling, or skills tend to surface only after the AI starts producing poor results or stops working altogether. Documenting resources up front turns these surprises into items you can plan for and budget against.

settings

Operational notes

Keep one register that maps each resource (data sets, computing and storage, software and models, and the people or skills involved) to the life cycle stage it supports. Update it whenever you add a data source, change a supplier, scale the infrastructure, or shift responsibilities, so the record matches what the system actually uses. A shared spreadsheet or a page in your existing asset register is enough to start; the point is that it stays current and someone owns it.

build

Implementation tips

  • List the resources each AI activity depends on, working stage by stage through the life cycle (gathering data, training, testing, running, and retiring the system); a single spreadsheet is enough to begin with.
  • Record where each data set comes from, when it was obtained, and what it may be used for, so a licence ending or a source changing does not catch the project off guard.
  • Track how much computing power and storage the system uses against what is available, and note the point at which capacity needs to grow before performance suffers.
  • Confirm at least once a year that suppliers of key software, models, and cloud services can still meet what the AI needs, and write down the outcome of each check.
  • Name the skills and the people behind each activity, and add a fallback for the resources you cannot do without, so a single absence or outage does not halt the work.
fact_check

Audit / evidence tips

  • AskAsk to see the AI resource register.GoodThe register covers every resource type and maps each one to the relevant stage of the AI life cycle.
  • AskAsk for the record of data sources behind the AI.GoodThe data source record is complete and current for every data set the AI relies on.
  • AskAsk for a recent report on computing and storage use.GoodThe report shows current usage against capacity and confirms there are no unaddressed shortfalls.
  • AskAsk for the latest supplier or licence confirmations for key AI tooling and services.GoodSupplier and licence confirmations are on file, current, and cover every critical resource.
  • AskAsk how the organisation copes when a key AI resource or skilled person is unavailable.GoodDocumented fallbacks exist for every critical resource and name who is responsible.
link

Cross-framework mappings

How Annex A 4.2 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

link_off

No cross-framework mappings recorded yet.

See all A.4 Resources for AI systems controls, or browse the full ISO 42001 Annex A library.

psychology

Want to implement this AI control?

Mindset Cyber runs PECB-accredited ISO/IEC 42001 training that maps directly to the AI controls in this library.

Mapping detail

Mapping

Direction

Controls