Control A.10.4 – Customers
In today's article by Kimova AI, we close the A.10 series with Annex A Control A.10.4 – Customers, the control that governs the other end of the relationship: the people your AI system actually affects.
Where A.10.3 looks upstream at suppliers, A.10.4 looks downstream. In an AI-driven market, customer trust is not a marketing outcome — it is a governance obligation with evidence attached.
Objective of Control A.10.4
The control requires organizations to inform customers about the use of AI systems, define responsibilities clearly between the parties, and manage the risks that arise from AI-driven outputs reaching customers.
The aim is transparency that a customer can act on, and accountability that neither side can quietly disclaim.
What the control covers
From an ISMS auditor's perspective, four elements carry the weight:
- Clear communication of AI purposes, limitations and impacts — customers should know when AI is involved, what it does, and where it is unreliable
- Defined roles in contracts and SLAs for AI outputs and decisions, including who is answerable when an output is wrong
- Feedback mechanisms and escalation channels, so a customer can challenge or query an AI-driven decision
- Alignment with the AIMS, so customer-facing commitments are backed by internal controls rather than stated in isolation
Communicating limitations honestly
The hardest part of this control is documenting what the system cannot do. An AI transparency notice that lists only capabilities does not satisfy the intent. Auditors will look for stated limitations, known failure modes and the conditions under which human review applies.
What auditors look for
- AI transparency notices, and evidence they reach customers at the right moment
- contractual clauses allocating responsibility for AI-assisted outputs
- records of customer queries, complaints and escalations, with outcomes
- periodic review of customer-facing AI disclosures as systems change
- traceability from a customer commitment back to the control that supports it
Why it matters
Without customer governance, AI erodes exactly what it was deployed to improve. The predictable consequences are distrust, contractual disputes over who owns an incorrect output, and regulatory exposure where transparency obligations apply.
Handled well, the same control becomes a differentiator: an organization that can explain its AI clearly, and show who is accountable, is easier to buy from.
Best practices
- write transparency notices in the customer's language, not the model's
- review disclosures on a schedule and whenever the system materially changes
- route customer feedback into the same register you use for AI incidents
- keep human escalation genuinely available, and state how to reach it
Conclusion
Annex A Control A.10.4 completes the picture that A.10 sets out: AI accountability runs in both directions — through the suppliers who contribute to a system, and through to the customers it serves.
At Kimova AI, we see customer transparency as the visible proof of an AI management system that works. Everything upstream exists so that this part can be stated plainly and stand up to scrutiny.
This article closes our walk through Annex A.10 – Third-Party and Customer Relationships. In the next series by Kimova.AI, we continue exploring the controls that make an AI management system auditable in practice.