Information Security Management Under AI
The one-paragraph answer
ISO 27001 AI compliance is the application of the international information security management system standard to AI systems. ISO 27001 provides comprehensive information security controls: access management, cryptography, operations security, communications security, supplier relationships, and more. All of these apply to AI systems that handle information. But ISO 27001 does not address AI-specific risks like bias, hallucination, or model drift, which is why ISO/IEC 42001 exists as its AI-specific companion.
Companies with ISO 27001 certification thought they were ready for AI. They are partially ready. ISO 27001 covers the security dimensions of AI systems but does not address AI-specific governance risks. Companies need to extend their ISO 27001 program to cover AI or add an AI management system (ISO/IEC 42001) alongside it.
ISO 27001's Annex A includes 93 controls (in the 2022 version) covering organizational, people, physical, and technological domains. Most apply to AI systems: access controls to models, cryptography for training data, operations security for AI pipelines, supplier relationship controls for AI vendors.
ISO 27001's risk management process applies to information security risks in AI systems. This includes confidentiality, integrity, and availability risks.
The ISO 27001 management system requires ongoing monitoring, internal audit, and management review, all of which extend to AI systems within scope.
AI-specific risks like algorithmic bias, model interpretability, training data provenance, model drift, and AI ethics are not addressed by ISO 27001. These need ISO/IEC 42001 or an equivalent AI-specific framework.
ISO 27001 is the most widely adopted information security standard globally. Enterprise buyers require it. Insurance underwriters price against it. Extending it to cover AI is significantly cheaper than building parallel systems.
The academic literature on ISO 27001 AI is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“Effective data governance is important for minimizing data breach activity and mitigating bias”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“AI governance is a system of rules, practices and processes employed to ensure an organization's use of AI aligns with its strategies, objectives, and values.”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about ISO 27001 AI arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, ISO 27001 AI becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
No, though it helps considerably. The EU Cyber Resilience Act is product law: it demands a product-level conformity assessment, an SBOM, a vulnerability handling process tied to a support period, and CE marking. ISO 27001 governs the organisation’s information security management system, not the security of a product placed on a market. The controls overlap heavily and the evidence is reusable, but a certificate is not a declaration of conformity.
Both. ISO 27001 provides information security foundation. ISO/IEC 42001 adds AI-specific management. They integrate cleanly and are often certified together.
The Governance Framework Crosswalk™ in Appendix L of Volume III of The Operating Discipline for AI Library™ maps ISO 27001 controls to AI governance requirements.
A great deal, and it should not be undersold. Access control over models and training data. Cryptographic protection of data at rest and in transit. Supplier relationship controls that reach your AI vendors. Operations security across the AI pipeline. Logging, monitoring, and incident response. Business continuity. An organisation with a mature ISO 27001 AI scope has solved the confidentiality, integrity, and availability problems that a great many AI programs have not even identified.
Nothing in Annex A tells you whether the model is biased. Nothing tells you whether its output can be explained to a person it disadvantaged. Nothing addresses training data provenance, model drift, hallucination, or the question of who is accountable when the AI is confidently wrong. These are not security failures, so a security standard does not catch them. That is precisely the gap ISO/IEC 42001 exists to close.
The two standards share a management system structure, which is deliberate. Extend your existing ISO 27001 AI scope statement to name AI systems explicitly. Add AI-specific risks to the existing risk assessment rather than starting a second register. Fold AI incidents into the existing incident process. Then layer the AI-specific clauses of ISO/IEC 42001 on top. Organisations that build a parallel AI program alongside their security program end up maintaining two systems that disagree with each other.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning ISO 27001 AI that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including ISO 27001 and AI, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →