ISO 27001
FRAMEWORK · ISO/IEC 27001

ISO/IEC 27001 for organisations that run AI

ISO/IEC 27001 is the international standard for an information security management system: how an organisation decides what to protect, assesses the risks, chooses controls and keeps proving they work. It is voluntary and certifiable, and it is the security standard customers and procurement most often ask for. For an organisation that builds or deploys AI, it is where the security of training data, models and pipelines gets governed — and its clause structure is the same one ISO/IEC 42001 uses, so the two run as one management system.

Last reviewed · against the consolidated text and Commission guidance

118
clauses and controls
25
programme steps, each producing a record
6
gate-locked phases
14
records shared with the sibling programme
Legal basis
ISO/IEC 27001:2022
Published by
ISO and IEC
Status
Voluntary · certifiable
WHO IT APPLIES TO

Who adopts it

Nobody is required to. These are the organisations for which the standard answers a question someone is already asking.

Software and AI vendors

Anyone whose customers send a security questionnaire — an ISMS is the answer most of them expect, and a certificate ends the questionnaire.

Processors under the GDPR

Art. 28 and Art. 32 ask a processor to show appropriate technical and organisational measures; an ISMS is the usual evidence.

Providers of high-risk AI

EU AI Act Art. 15 asks for accuracy, robustness and cybersecurity across the lifecycle; the technological controls of Annex A are where that work is organised.

KEY DATES · STATUS

The dates that matter

Certified by an accredited certification body — never by Veritome (ISO/IEC 17021-1 §5.2.5 keeps the consultant and the certifier apart).

DateEventWhat it means
25.10.20222022 edition publishedISO/IEC 27001:2022 replaced the 2013 edition; Annex A was restructured into four themes.
31.10.2025Transition endedCertificates to the 2013 edition ceased to be valid; every current certificate is to the 2022 edition.
18.12.2023ISO/IEC 42001 publishedThe AI management system standard shares the Annex SL clause structure, which is why Veritome runs the two as one system.
WHAT IT ASKS

118 requirements, in the shape the framework gives them

Clauses 4 to 10 set out the management system — context, leadership, planning, support, operation, evaluation, improvement — and Annex A lists the 93 controls in four themes: organisational, people, physical and technological. A control is applied through the Statement of Applicability, so the standard asks you to decide, justify and evidence, not to switch everything on. Veritome's catalogue names each control; the standard's own text is licensed and is never reproduced.

25
clause requirements (clauses 4–10)
93
Annex A controls
  • Clause 4Context of the organisation4
  • Clause 5Leadership3
  • Clause 6Planning5
  • Clause 7Support5
  • Clause 8Operation3
  • Clause 9Performance evaluation3
  • Clause 10Improvement2
  • A.5Organisational controls37
  • A.6People controls8
  • A.7Physical controls14
  • A.8Technological controls34
HOW VERITOME RUNS IT

25 steps, 6 phases, one record each

6 phases: Establish · Plan · Support · Operate · Evaluate & improve · Certification audit, gate-locked in that order. 14 of the 25 steps are the same record as the ISO/IEC 42001 programme — one form, both programmes, and approving it re-plans the sibling. The Operate phase groups the 93 controls into organisational, people, physical and technological themes plus continuity and incident management, so a control is evidenced where the work happens rather than in 93 separate forms. The Statement of Applicability is generated from those records.

01

Establish

5 steps
  1. Context of the organisation
    Shared record
  2. Interested parties and their requirements
    Shared record
  3. Roles, responsibilities and authorities
    Shared record
  4. Scope of the ISMS
  5. Leadership commitment and information security policy
02

Plan

4 steps
  1. Risk methodology and AI risk assessment
    Shared record
  2. AI objectives and planning to achieve them
    Shared record
  3. Planning of changes
    Shared record
  4. Risk treatment and Statement of Applicability
03

Support

3 steps
  1. Resources and competence
    Shared record
  2. Awareness and communication
    Shared record
  3. Control of documented information
    Shared record
04

Operate

7 steps
  1. Operational planning and control
    Shared record
  2. Organisational controls
  3. People controls
  4. Physical controls
  5. Technological controls
  6. ICT continuity and backup verification
  7. Information security incident management
05

Evaluate & improve

4 steps
  1. Monitoring, measurement, analysis and evaluation
    Shared record
  2. Internal audit
    Shared record
  3. Management review
    Shared record
  4. Nonconformity, corrective action and continual improvement
    Shared record
06

Certification audit

2 steps
  1. Certification readiness review (optional workflow)
  2. Certification arrangements and outcome (optional)
ISO 27001ISO 27001 programme
25 steps · 25 records · 14 shared
01Establish
5 steps · Complete
02Plan
4 steps · In progress
03Support
3 steps · Locked
04Operate
7 steps · Locked
05Evaluate & improve
4 steps · Locked
06Certification audit
2 steps · Locked
Plan · the steps
  1. 01Risk methodology and AI risk assessmentShared recordApproved
  2. 02AI objectives and planning to achieve themShared recordIn draft
  3. 03Planning of changesShared recordTo do
  4. 04Risk treatment and Statement of ApplicabilityTo do
Phases and steps as the product generates them · progress shown is illustrative
WHERE IT OVERLAPS

Credited in both, or only related

The 14 records shared with ISO/IEC 42001 are credited in both programmes — the owner's verified matrix checked the clauses against both standards. Links from the security programme to the EU AI Act, the GDPR or the NIST AI RMF are related links: supporting reading beside a step, never coverage. GDPR Art. 32 and EU AI Act Art. 15 are the two the matrix relates most often.

WithRecords credited in bothRelated only — shown, never creditedPage
EU AI Act017EU AI Act
GDPR011GDPR
ISO 420011418ISO 42001
NIST AI RMF07NIST AI RMF

10 of the 25 steps carry a related link to an EU AI Act article. A related link is a supporting candidate the owner's verified matrix did not check against source text; the product shows it beside the step and never counts it as coverage. The full matrix for all five frameworks is on the frameworks page; the EU AI Act itself, article by article, is at /eu-ai-act.

The coverage matrix in Veritome — one row per requirement, one column per framework, credited cells apart from related ones
QUESTIONS PEOPLE ASK

ISO/IEC 27001, answered plainly

The answers below are the ones the page marks up for search engines and AI assistants — the same text, nothing hidden.

What is ISO/IEC 27001?

The international standard for an information security management system (ISMS), published by ISO and IEC. The current edition is 2022. It specifies how an organisation scopes, risk-assesses, controls and continually improves its information security, and it is certifiable by an accredited body.

Why does an AI company need ISO/IEC 27001?

Because its customers ask, and because three regimes point at the same work: GDPR Art. 32 asks for security appropriate to the risk, EU AI Act Art. 15 asks providers of high-risk systems for cybersecurity across the lifecycle, and ISO/IEC 42001 assumes the security clauses are already answered. One ISMS is the evidence for all three.

How many controls are in ISO/IEC 27001:2022?

93 Annex A controls in four themes — organisational, people, physical and technological — beside 25 clause requirements in clauses 4 to 10. Veritome's catalogue carries all 118.

What changed between the 2013 and 2022 editions?

Annex A went from 114 controls in fourteen domains to 93 in four themes, with eleven new controls covering threat intelligence, cloud services, ICT readiness for continuity, physical monitoring, configuration, information deletion, data masking, data-leakage prevention, monitoring, web filtering and secure coding. The clauses 4 to 10 changed little. Certificates to the 2013 edition ceased to be valid on 31.10.2025.

Can I run ISO/IEC 27001 and ISO/IEC 42001 together?

Yes. Both follow the Annex SL clause structure, so context, leadership, support and evaluation are one set of records. Veritome runs them as one management system with two scopes: 14 of the 25 steps here are shared with the ISO/IEC 42001 programme.

Does Veritome certify ISO/IEC 27001?

No. An accredited certification body audits and certifies; ISO/IEC 17021-1 keeps the party that helped build the ISMS apart from the party that certifies it. Veritome runs the programme, generates the Statement of Applicability and holds the evidence the auditor asks for.

The other four