Why you can trust this course
We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.
How this ISO/IEC 42001 AI Management System Practitioner Certification register is built
This trust page is the citation register for the ISO/IEC 42001 AI Management System Practitioner Certification course. It cites 76 authorities across 18 statutory instruments, drawn from the legal basis snapshot above (ISO/IEC 42001 primary-source stack current to 19 September 2026. Core: ISO/IEC 42001:2023 first edition December 2023 (ten clauses 0-10 plus Annex A with 38 controls across groups A.2 Policies related to AI, A.3 Internal organisation, A.4 Resources for AI systems, A.5 Assessing impacts of AI systems on individuals or groups and societies, A.6 AI system lifecycle, A.7 Data for AI systems, A.8 Information for interested parties of AI systems, A.9 Use of AI systems, A.10 Third-party and customer relationships, plus Annex B implementation guidance, Annex C AI-related organisational objectives, Annex D use of AIMS across domains). Companion standards: ISO/IEC 23894:2023 (guidance on AI risk management), ISO/IEC 23053:2022 (framework for AI systems using machine learning), ISO/IEC 42005:2025 (AI system impact assessment), ISO/IEC 22989:2022 (AI concepts and terminology), ISO/IEC TR 24028:2020 (trustworthiness in AI). Integration standards: ISO/IEC 27001:2022 for the AIMS-on-top-of-ISMS pattern, ISO/IEC 27701:2025 for the PIMS integration. India-specific stack: India AI Governance Guidelines released by MeitY in November 2025 (seven sutras Trust / People-first / Innovation over restraint / Fairness and equity / Accountability / Understandability by design / Safety resilience sustainability, across six pillars Infrastructure / Capacity building / Policy and regulation / Risk mitigation / Accountability / Institutions, with Annexure 6 recommending ISO/IEC 42001), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 effective 20 February 2026 introducing Synthetically Generated Information as a due-diligence category with visual labelling audio disclosure metadata embedding and 2 to 3 hour takedown for deepfake harm, MeitY AI Advisory dated March 2024 on labelling AI-generated content operative until superseded on labelling by the 2026 Rules, SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 (Advisory on emerging advanced AI tools for vulnerability detection, Cyber-suraksha.ai task force, applies to every regulated entity in the Indian securities market), Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay released 13 August 2025 (seven sutras 26 recommendations six pillars Infrastructure Policy Capacity Governance Protection Assurance), DPDP Act 2023 and DPDP Rules 2025 notified November 2025 with phased commencement (no equivalent to GDPR Article 22, no right to explanation), BIS adoption as IS/ISO/IEC 42001:2023 identical to ISO text, IndiaAI Mission approved March 2024 with ₹10,371 crore outlay over five years across seven pillars including Safe & Trusted AI (13 projects funded as of July 2026 on deepfake and bias), IndiaAI Safety Institute announced January 2025. Global adjacent regulation for extraterritorial reach and crosswalk: EU AI Act Regulation (EU) 2024/1689 phased application 2 February 2025 prohibited practices and AI literacy live, 2 August 2025 GPAI transparency for new models, 2 August 2026 general application and Article 50 transparency, 2 December 2026 new prohibited practices on synthetic intimate content and CSAM, 2 December 2027 Annex III high-risk (pushed back from August 2026 by Digital Omnibus), 2 August 2028 Annex I product-embedded high-risk. NIST AI Risk Management Framework 1.0 (January 2023) four functions Govern Map Measure Manage with official crosswalk to ISO/IEC 42001 published by NIST AIRC. OECD AI Principles (2019 updated 2024). UNESCO Recommendation on the Ethics of AI (2021). Council of Europe AI Framework Convention (opened for signature September 2024). Certification body landscape referenced: A-LIGN, BSI India, Bureau Veritas India, DNV Business Assurance India, Schellman, SGS India, TÜV SÜD South Asia, TÜV Nord India, Intertek India (accredited under ANAB, UKAS, RvA pending NABCB scheme extension). Personal certification schemes referenced (not primary): PECB Lead Implementer and Lead Auditor for ISO 42001, BSI ISO 42001 Lead Implementer, operating under ISO/IEC 17024. India first-mover organisational certifications referenced: Mphasis (first Indian IT services company to certify, 2025) and KPMG India (certified by SGS December 2025). Items requiring ongoing verification and flagged inside the relevant lessons: NABCB scheme extension timeline for ISO 42001; any ISO/IEC 42001 amendment beyond first edition; Digital India Act draft status and eventual enactment; RBI conversion of FREE-AI Report recommendations into binding master directions; DPDP Board of India Chairperson appointment status; new India AI-specific legislation.).
Primary sources: ISO/IEC 42001:2023 (57 entries), EU AI Act 2024/1689 (2 entries), Public ISO 42001 Certification (2 entries).
Every claim in every ISO/IEC 42001 AI Management System Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below.
If a lesson references a specific obligation, click the [Lx-Cy] marker in that
lesson to jump to the verbatim text in the register.
Our verification promise
- Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the
[Lx-Cy]marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013. - Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
- Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
- Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
The full citation register
Every authority used in any lesson appears below. Click a row to expand the verbatim text.
IS/ISO/IEC 42001:2023 BIS adoption , BIS national standard adoption 01 Jun 2024
DPDP Act 2023 no Article 22 equivalent , Automated decisions not restricted 11 Aug 2023
DPDP Rules 2025 notified Nov 2025 , Phased commencement 14 Nov 2025
EU AI Act Article 5 prohibited practices , Prohibited practices live Feb 2025 02 Feb 2025
EU AI Act general application 2-Aug-2026 , General application + Article 50 02 Aug 2026
IndiaAI Mission Mar 2024 approval , Rs 10,371 cr five-year outlay 07 Mar 2024
ISO 31000:2018 Risk management , General risk management guidance 15 Feb 2018
ISO/IEC 22989:2022 AI terminology , AI concepts and terminology 26 Jul 2022
ISO/IEC 23053:2022 ML framework , Framework for AI using ML 13 Jun 2022
ISO/IEC 23894:2023 AI risk management , Guidance on AI risk management 06 Feb 2023
Annex A A.10 Third-party customer relations , Group A.10 third-party 18 Dec 2023
Annex A A.10.3 Suppliers , Supplier controls 18 Dec 2023
Annex A A.10.4 Customers , Customer obligations 18 Dec 2023
Annex A A.2.2 AI Policy , AI policy documented 18 Dec 2023
Annex A A.2.3 Alignment with other policies , Policy alignment 18 Dec 2023
Annex A A.2.4 Review of AI policy , Policy review at intervals 18 Dec 2023
Annex A A.3.2 AI roles , AI roles and responsibilities 18 Dec 2023
Annex A A.3.3 Reporting of concerns , Concerns reporting channel 18 Dec 2023
Annex A A.4 Resources for AI systems , Group A.4 resources 18 Dec 2023
Annex A A.4.2 Data resources , Data resources 18 Dec 2023
Annex A A.4.3 Tooling resources , Tooling resources 18 Dec 2023
Annex A A.4.4 System computing resources , Compute resources 18 Dec 2023
Annex A A.4.5 Human resources , Human resources for AI 18 Dec 2023
Annex A A.4.6 Financial resources , Financial resources 18 Dec 2023
Annex A A.5.2 AI Impact Assessment , AIIA process required 18 Dec 2023
Annex A A.5.3 AIIA documentation , AIIA documented per system 18 Dec 2023
Annex A A.5.4 Impact on individuals groups , Impact on individuals and groups 18 Dec 2023
Annex A A.5.5 Impact on societies , Impact on societies 18 Dec 2023
Annex A A.6 AI system life cycle , Group A.6 AI lifecycle 18 Dec 2023
Annex A A.6.2.5 V and V , Verification and validation 18 Dec 2023
Annex A A.6.2.7 Operation and monitoring , Operation and monitoring 18 Dec 2023
Annex A A.6.2.9 AI system event logs , AI system event logs 18 Dec 2023
Annex A A.7 Data for AI systems , Group A.7 data 18 Dec 2023
Annex A A.7.4 Quality of data , Data quality for AI 18 Dec 2023
Annex A A.7.5 Data provenance , Data provenance 18 Dec 2023
Annex A A.8 Information for interested parties , Group A.8 information 18 Dec 2023
Annex A A.8.2 System documentation for users , System doc for users 18 Dec 2023
Annex A A.9 Use of AI systems , Group A.9 use 18 Dec 2023
Annex A A.9.2 Processes for responsible use , Responsible use processes 18 Dec 2023
Annex B.4.1 Guidance context of org , Annex B guidance on Clause 4 18 Dec 2023
Clause 10.1 Continual improvement , AIMS continual improvement 18 Dec 2023
Clause 10.2 Nonconformity and CAPA , Handling nonconformities 18 Dec 2023
Clause 4.1 Understanding the organisation , Internal and external issues for AIMS 18 Dec 2023
Clause 4.2 Interested parties , Interested parties for AIMS 18 Dec 2023
Clause 4.3 Scope of the AIMS , AIMS scope statement 18 Dec 2023
Clause 5.1 Leadership and commitment , Top management commitment 18 Dec 2023
Clause 5.2 AI policy , AI policy requirements 18 Dec 2023
Clause 5.3 Roles responsibilities auth , AI roles and authorities 18 Dec 2023
Clause 6.1.1 Actions to address risk , Risks and opportunities 18 Dec 2023
Clause 6.1.2 AI risk assessment , AI risk assessment process 18 Dec 2023
Clause 6.1.3 AI risk treatment , Risk treatment and SoA 18 Dec 2023
Clause 6.1.4 AI system impact assessment , AIIA as a planning input 18 Dec 2023
Clause 6.2 AI objectives and planning , AI objectives 18 Dec 2023
Clause 6.3 Planning of changes , Change control 18 Dec 2023
Clause 7.1 Resources , Resources for the AIMS 18 Dec 2023
Clause 7.2 Competence , Competence requirements 18 Dec 2023
Clause 7.3 Awareness , AIMS awareness 18 Dec 2023
Clause 7.4 Communication , Internal and external communication 18 Dec 2023
Clause 7.5 Documented information , What must be documented 18 Dec 2023
Clause 8.1 Operational planning control , Operational execution 18 Dec 2023
Clause 8.2 AI risk assessment execution , Executing the risk assessment 18 Dec 2023
Clause 8.3 AI risk treatment execution , Executing risk treatment 18 Dec 2023
Clause 8.4 AI system impact assessment op , AIIA operational execution 18 Dec 2023
Clause 9.1 Monitoring measurement analysis , AIMS performance measurement 18 Dec 2023
Clause 9.2 Internal audit , Internal audit programme 18 Dec 2023
Clause 9.3 Management review , Management review inputs and outputs 18 Dec 2023
ISO/IEC 42001:2023 (Dec 2023 first edition) , AI management systems Requirements 18 Dec 2023
ISO/IEC 42005:2025 AI impact assessment , AI system impact assessment 01 Jun 2025
IT Rules Amendment 2026 SGI , SGI due-diligence obligations 10 Feb 2026
MeitY AI Advisory 15-Mar-2024 , AI content labelling advisory 15 Mar 2024
India AI Governance Guidelines Nov 2025 , Seven sutras + six pillars 05 Nov 2025
NIST AI RMF 1.0 four functions , Govern Map Measure Manage 26 Jan 2023
Mphasis first Indian IT services ISO 42001 , Mphasis 2025 certification 15 Jun 2025
KPMG India ISO 42001 by SGS Dec 2025 , KPMG India certification 15 Dec 2025
RBI FREE-AI Report 13-Aug-2025 , Bhattacharyya Committee framework 13 Aug 2025
SEBI Advisory 5-May-2026 Mythos , AI vulnerability detection advisory 05 May 2026
Found an error? We pay for it.
If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.
- ₹1,000 credit for the first report of any verifiable factual error.
- ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
- Credit on your dcomply Academy account usable against any future course.
We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.
- 🟢 Our verification promise
- 📊 Course statistics
- 📚 Full citation register
- 🐛 Bug bounty for errors
Maintained by the dcomply Academy editorial team. Last reviewed recently.