ISO 27001 gives you a framework. It does not tell you how to apply it to systems that generate code, summarise board papers, process customer data at scale, and make decisions at a speed no human audit process was designed to keep up with. The standard is sound. The gap is in applying it to AI.
ISO 27001 is the most widely recognised information security management standard in the world. It provides a structured framework for identifying risks, implementing controls, and maintaining an ongoing programme of security improvement. For most organisations pursuing certification, it represents a significant and worthwhile investment in security maturity.
The problem is that ISO 27001 was not designed with AI in mind. The 2022 revision introduced controls that are more relevant to modern technology environments than its predecessor, but the standard remains largely silent on the specific risks that AI tools introduce. Organisations that are certified to ISO 27001 and that are deploying AI tools may find that their certification provides less assurance than they, or their clients, assume.
This piece works through the ISO 27001 control framework and identifies where AI creates gaps, what those gaps look like in practice, and how to address them without abandoning the framework that the standard provides.
Where ISO 27001 Works Well for AI
It is worth starting with what ISO 27001 does well before addressing where it falls short, because the framework provides genuine value even in an AI context and the goal is to extend it rather than replace it.
The risk assessment process at the heart of ISO 27001 is directly applicable to AI. The methodology for identifying assets, threats, vulnerabilities, and impacts applies to AI systems as much as to any other information asset. The discipline of conducting a structured risk assessment before deploying a new system is exactly what most AI deployments currently lack, and ISO 27001 provides a ready-made framework for doing it.
The supplier relationship controls introduced in ISO 27001:2022, particularly A.5.19 through A.5.22, provide a basis for managing AI vendor relationships. The requirement to assess supplier security, establish contractual protections, and monitor ongoing compliance maps directly onto the AI vendor assessment process covered in the preceding piece in this series.
Access control requirements under A.5.15 through A.5.18 provide the framework for applying least privilege to AI systems, as discussed in the access control piece earlier in this series. The standard does not tell you how to implement least privilege for AI agents specifically, but it establishes the principle and the obligation.
Where ISO 27001 Falls Short
The gaps in ISO 27001's coverage of AI risks fall into several categories. Understanding them is the first step to addressing them.
Model risk. ISO 27001 addresses risks to information confidentiality, integrity, and availability. It does not address the risk that an AI model will produce outputs that are inaccurate, biased, or harmful. Model hallucination, training data bias, and output manipulation through prompt injection are not risks that fit neatly into the standard's risk taxonomy, and there are no specific controls addressing them.
Data provenance and training data. ISO 27001 controls address how data is handled within the organisation's information systems. They do not address the security and integrity of data used to train AI models, whether those models are developed internally or procured from third parties. The risk that training data has been poisoned, manipulated, or drawn from sources that introduce legal or ethical exposure is outside the standard's scope.
Agentic system governance. The standard's controls assume that information processing is performed by systems that do what they are configured to do. Agentic AI systems that reason, plan, and act autonomously introduce a governance challenge that the standard's control framework was not designed to address. Questions of human oversight, action authorisation, and audit trail for autonomous AI decisions are not covered.
Prompt injection as a threat vector. The standard's threat taxonomy covers malware, unauthorised access, denial of service, and similar conventional threats. Prompt injection, the technique of embedding malicious instructions in content processed by an AI system, does not appear in the standard's guidance and is not addressed by any of its controls. Organisations relying on ISO 27001 as their primary security framework may have no formal treatment of this threat.
Shadow AI. The standard requires organisations to maintain an inventory of information assets and manage risks associated with those assets. It provides no specific guidance on discovering and governing unsanctioned AI tool usage, which as covered in the shadow AI piece in this series is one of the most widespread and least-managed AI risks in enterprise environments.
Extending the Framework: Practical Additions
The most practical approach to closing these gaps is to extend the existing ISO 27001 framework rather than treat AI as a separate domain requiring a separate management system. The following additions integrate with the standard's structure and can be incorporated into an existing ISMS without requiring recertification.
Extend the asset inventory to include AI systems. Every AI tool in use, whether sanctioned or discovered through shadow AI monitoring, should be recorded in the asset inventory with its risk classification, data access scope, and ownership. AI systems should be subject to the same asset management discipline as any other information asset.
Extend the risk assessment to cover AI-specific threats. Add prompt injection, model hallucination, training data poisoning, shadow AI usage, and agentic system misuse to the threat catalogue used in risk assessments. For each AI system in scope, assess the likelihood and impact of these threats and identify appropriate controls.
Create an AI-specific annex to the information security policy. The core information security policy applies to AI systems, but AI introduces specific obligations around data submission, approved tool usage, and handling of AI-generated outputs that benefit from explicit policy treatment. An AI usage policy that sits alongside the information security policy and is reviewed on the same cycle provides clear guidance without requiring the core policy to be restructured.
Add AI vendor assessment to the supplier management process. The supplier management controls in ISO 27001:2022 provide the framework. Extend the supplier assessment questionnaire and contract requirements to cover the AI-specific elements set out in the vendor assessment piece in this series: training opt-outs, data residency, audit rights, and incident notification.
Incorporate AI into the internal audit programme. Internal audits should include specific coverage of AI-related controls: shadow AI discovery and management, AI vendor contract compliance, access controls for AI systems, and the effectiveness of AI-specific training and awareness. Auditors conducting these reviews need sufficient understanding of AI to assess controls meaningfully.
Add AI incident scenarios to the incident response plan. The incident response plan should include specific scenarios for AI-related incidents: a shadow AI data exposure, a prompt injection attack on an agentic system, an AI vendor breach, and an incident involving AI-generated output that causes harm. Having worked through these scenarios in advance significantly reduces response time and improves decision quality when an incident occurs.
ISO 42001: The AI-Specific Standard
ISO 42001, published in 2023, is the international standard for AI management systems. It provides a framework specifically designed for the governance, risk management, and responsible use of AI, and is structured to be compatible with ISO 27001 and other management system standards.
For organisations with significant AI deployment or for whom AI governance is a material client or regulatory concern, ISO 42001 certification provides a level of assurance that cannot be obtained by extending ISO 27001 alone. It addresses model risk, algorithmic fairness, transparency, human oversight, and AI-specific incident management in a way that the information security standard does not.
The decision whether to pursue ISO 42001 alongside ISO 27001 depends on the materiality of AI in the organisation's operations and the expectations of its clients and regulators. For organisations in sectors where AI governance is becoming a procurement requirement, early adoption of ISO 42001 provides a competitive differentiator. For organisations where AI is a supporting tool rather than a core capability, extending ISO 27001 as described above may be the more proportionate approach.
The Certification Question
Organisations that are certified to ISO 27001 and that have deployed AI tools without explicitly extending their ISMS to cover AI-specific risks face a question about the integrity of their certification. The certification covers the ISMS as scoped and implemented. If AI systems are within scope and AI-specific risks have not been addressed, there is an argument that the ISMS does not adequately address all material risks and that the certification may not reflect the actual security posture of the organisation.
This is not an argument for abandoning certification or for treating AI as automatically outside scope. It is an argument for being honest about what the certification covers, extending the ISMS to address AI-specific risks, and ensuring that the next surveillance or recertification audit includes meaningful coverage of AI governance.
Clients and regulators who ask whether you are ISO 27001 certified are, in most cases, asking whether your organisation takes information security seriously and has implemented a structured approach to managing it. Extending your ISMS to cover AI is the most direct way to ensure that the answer to that question remains yes in an environment where AI is a material part of how information is processed.
If you hold ISO 27001 certification and are deploying AI tools, and you want to understand what extending your ISMS to cover AI-specific risks involves, or if you are considering ISO 42001 and want to understand what the implementation journey looks like, we can help.