web analytics
General Business Governance

ISO 27001 and AI

Information Security Management Under AI

The one-paragraph answer

ISO 27001 AI compliance is the application of the international information security management system standard to AI systems. ISO 27001 provides comprehensive information security controls: access management, cryptography, operations security, communications security, supplier relationships, and more. All of these apply to AI systems that handle information. But ISO 27001 does not address AI-specific risks like bias, hallucination, or model drift, which is why ISO/IEC 42001 exists as its AI-specific companion.

The pain ISO 27001 AI compliance is causing our customers

Companies with ISO 27001 certification thought they were ready for AI. They are partially ready. ISO 27001 covers the security dimensions of AI systems but does not address AI-specific governance risks. Companies need to extend their ISO 27001 program to cover AI or add an AI management system (ISO/IEC 42001) alongside it.

What ISO 27001 AI compliance covers

Annex A controls

ISO 27001's Annex A includes 93 controls (in the 2022 version) covering organizational, people, physical, and technological domains. Most apply to AI systems: access controls to models, cryptography for training data, operations security for AI pipelines, supplier relationship controls for AI vendors.

Risk management

ISO 27001's risk management process applies to information security risks in AI systems. This includes confidentiality, integrity, and availability risks.

Continual improvement

The ISO 27001 management system requires ongoing monitoring, internal audit, and management review, all of which extend to AI systems within scope.

What ISO 27001 AI does not cover

AI-specific risks like algorithmic bias, model interpretability, training data provenance, model drift, and AI ethics are not addressed by ISO 27001. These need ISO/IEC 42001 or an equivalent AI-specific framework.

Why ISO 27001 AI compliance matters to you

ISO 27001 is the most widely adopted information security standard globally. Enterprise buyers require it. Insurance underwriters price against it. Extending it to cover AI is significantly cheaper than building parallel systems.

What the research says about ISO 27001 AI

The academic literature on ISO 27001 AI is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“Effective data governance is important for minimizing data breach activity and mitigating bias”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“AI governance is a system of rules, practices and processes employed to ensure an organization's use of AI aligns with its strategies, objectives, and values.”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about ISO 27001 AI arrives from the board, the buyer, or the regulator.

How to get compliant with ISO 27001 and AI: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under ISO 27001 AI. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities ISO 27001 AI reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation ISO 27001 AI expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, ISO 27001 AI becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about ISO 27001 AI

Does ISO 27001 AI coverage satisfy the EU Cyber Resilience Act?

No, though it helps considerably. The EU Cyber Resilience Act is product law: it demands a product-level conformity assessment, an SBOM, a vulnerability handling process tied to a support period, and CE marking. ISO 27001 governs the organisation’s information security management system, not the security of a product placed on a market. The controls overlap heavily and the evidence is reusable, but a certificate is not a declaration of conformity.

Should we get ISO/IEC 42001 or ISO 27001 for AI?

Both. ISO 27001 provides information security foundation. ISO/IEC 42001 adds AI-specific management. They integrate cleanly and are often certified together.

Where does ISO 27001 AI compliance fit in SRJ's work?

The Governance Framework Crosswalk™ in Appendix L of Volume III of The Operating Discipline for AI Library™ maps ISO 27001 controls to AI governance requirements.

What ISO 27001 AI coverage genuinely gives you

A great deal, and it should not be undersold. Access control over models and training data. Cryptographic protection of data at rest and in transit. Supplier relationship controls that reach your AI vendors. Operations security across the AI pipeline. Logging, monitoring, and incident response. Business continuity. An organisation with a mature ISO 27001 AI scope has solved the confidentiality, integrity, and availability problems that a great many AI programs have not even identified.

And what it does not touch

Nothing in Annex A tells you whether the model is biased. Nothing tells you whether its output can be explained to a person it disadvantaged. Nothing addresses training data provenance, model drift, hallucination, or the question of who is accountable when the AI is confidently wrong. These are not security failures, so a security standard does not catch them. That is precisely the gap ISO/IEC 42001 exists to close.

How to extend rather than duplicate

The two standards share a management system structure, which is deliberate. Extend your existing ISO 27001 AI scope statement to name AI systems explicitly. Add AI-specific risks to the existing risk assessment rather than starting a second register. Fold AI incidents into the existing incident process. Then layer the AI-specific clauses of ISO/IEC 42001 on top. Organisations that build a parallel AI program alongside their security program end up maintaining two systems that disagree with each other.

Primary sources on ISO 27001 AI

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning ISO 27001 AI that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including ISO 27001 and AI, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation