ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It provides a systematic framework for managing information security risks through a risk-based approach: identify risks, select controls, implement, monitor, and continuously improve. The standard is published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), and the full text is commercially paywalled — only the structure and control list are publicly available.
The 2022 revision was the first major update since 2013. It restructured Annex A controls from 114 items in 14 domains to 93 controls in 4 themes: Organizational (37), People (8), Physical (14), and Technological (34). It also introduced 11 new controls addressing contemporary threats including cloud services, threat intelligence, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. Several of these new controls are directly relevant to AI system security.
ISO 27001 is certifiable — organizations can be audited by accredited certification bodies and receive a certificate valid for three years (with annual surveillance audits). This certification is recognized globally and is often required for international business, government contracts, and enterprise procurement. AI systems processing data must comply with the ISMS requirements, and the certifiable standard creates a compliance barrier to entry analogous to SOC 2 but with broader international acceptance.
The ISO 27001 standard is organized into two main parts: the mandatory management system clauses (Clauses 4–10) and the optional control set (Annex A). Organizations seeking certification must implement all mandatory clauses; Annex A controls are selected based on risk assessment — you implement controls that address identified risks and justify exclusions of controls that don't apply.
Clause 4 — Context of the Organization: Understand internal and external issues, stakeholder requirements, and define the scope of the ISMS. For AI systems, this means identifying AI-related risks, regulatory requirements (GDPR, EU AI Act, sector-specific), and stakeholder expectations regarding AI security and ethics.
Clause 5 — Leadership: Top management commitment, security policy, and roles/responsibilities. Leadership must demonstrate active involvement in information security — not just delegate it. AI governance decisions (model deployment, data usage) should involve senior leadership.
Clause 6 — Planning: Risk assessment, risk treatment, information security objectives, and action plans. This is where AI-specific risks are formally identified: training data poisoning, model adversarial attacks, data leakage through inference, and regulatory compliance for AI processing.
Clause 7 — Support: Resources, competence, awareness, communication, and documented information. Organizations must ensure staff have AI security competence and that AI-related security policies are communicated.
Clause 8 — Operation: Operational planning and control, risk assessment, and risk treatment implementation. The day-to-day execution of the ISMS, including AI system security operations.
Clause 9 — Performance Evaluation: Monitoring, measurement, analysis, internal audit, and management review. Organizations must measure ISMS effectiveness — including AI security metrics like incident rates, vulnerability counts, and control effectiveness.
Clause 10 — Improvement: Nonconformity, corrective actions, and continual improvement. The ISMS must evolve — as AI threats change, controls must be updated.
The risk-based approach means AI risks must be formally assessed. Clause 6 requires organizations to identify and assess information security risks. If an organization deploys AI systems, those systems' risks must be in the risk register — model security, training data protection, inference data handling, and regulatory compliance. An ISMS that ignores AI risks is non-conformant if AI systems are in scope.
Clause 9 (performance evaluation) creates AI measurement obligations. Organizations must monitor and measure ISMS effectiveness. For AI systems, this means defining security metrics: number of model-related incidents, data leakage events, unauthorized access to model APIs, and control effectiveness for AI-specific controls. Traditional security metrics (firewall blocks, patch compliance) don't capture AI-specific risks.
The 2022 revision restructured Annex A from 114 controls in 14 domains to 93 controls in 4 themes. This consolidation simplified control selection and better reflected modern technology environments, including cloud, DevOps, and AI-adjacent systems.
Organizational Controls (37): Policies, roles, asset management, supplier relationships, incident management, and compliance. Key AI-relevant controls: A.5.1 (policies for information security), A.5.9 (inventory of information assets — including AI models and training datasets), A.5.19 (information security in supplier relationships — cloud AI provider assessment), A.5.24-5.26 (incident management — AI security incident response), A.5.30 (ICT readiness for business continuity).
People Controls (8): Screening, terms of employment, awareness, and disciplinary processes. A.6.3 (information security awareness) should include AI-specific threats: prompt injection, data leakage via model interactions, and social engineering through AI-generated content.
Physical Controls (14): Physical security perimeters, entry controls, and equipment protection. Relevant for on-premise AI infrastructure: GPU clusters, training data storage, and inference servers. A.7.7 (clear desk and clear screen) extends to AI systems — no cardholder data or CUI visible on monitors running AI inference.
Technological Controls (34): Access control, cryptography, network security, system acquisition, and secure coding. The most AI-relevant theme: A.8.2 (privileged access rights — model API keys, training pipeline access), A.8.3 (information access restriction — role-based access to AI systems), A.8.4 (access to source code — model weights and training code), A.8.5 (secure authentication — MFA for AI system access), A.8.7 (protection against malware), A.8.9 (configuration management — AI infrastructure hardening), A.8.11 (data masking — tokenization before AI processing), A.8.12 (data leakage prevention — preventing CUI/cardholder data leakage through model outputs), A.8.25 (secure development life cycle — AI model development security), A.8.28 (secure coding — including ML code security).
New in 2022 (11 controls): A.5.7 (threat intelligence), A.5.23 (cloud services), A.8.9 (configuration management), A.8.10 (information deletion), A.8.11 (data masking), A.8.12 (data leakage prevention), A.8.16 (monitoring activities), A.8.23 (web filtering), A.8.25 (secure development lifecycle), A.8.29 (security testing in development), A.8.30 (outsourced development). Several of these — data masking, data leakage prevention, secure development lifecycle — are directly applicable to AI system security.
Data masking (A.8.11) and data leakage prevention (A.8.12) are the AI-relevant new controls. Data masking means tokenizing or anonymizing data before AI processing — the same scope-reduction strategy as PCI DSS tokenization. Data leakage prevention means preventing sensitive data from being exposed through AI system outputs — model responses, logs, and artifacts. These controls, new in 2022, reflect awareness that modern data processing (including AI) creates novel leakage vectors.
Secure development lifecycle (A.8.25) applies to AI model development. Organizations must implement secure development practices for AI systems — including secure training data pipelines, model weight protection, and adversarial robustness testing. The control doesn't say "AI" explicitly, but the risk assessment (Clause 6) should identify AI development as a process requiring security controls.
Threat intelligence (A.5.7) should include AI-specific threats. Organizations certified to ISO 27001 must gather and analyze threat intelligence. For organizations deploying AI, this includes monitoring for new adversarial attack methods, model extraction techniques, and AI-specific vulnerabilities. The threat landscape for AI systems evolves faster than traditional IT — ISMS threat intelligence processes must keep pace.
ISO 27001 certification is issued by accredited certification bodies (e.g., BSI, DNV, TÜV, Bureau Veritas) after a two-stage audit. Stage 1 reviews documentation and ISMS readiness. Stage 2 evaluates implementation and effectiveness. Successful certification is valid for three years, with annual surveillance audits and a recertification audit at the end of the cycle.
Certification costs vary widely based on organization size and scope: $10,000–$30,000 for small organizations, $30,000–$100,000+ for mid-size, and significantly more for large enterprises with global operations. These costs are recurring — surveillance audits and recertification carry ongoing fees. Internal costs (staff time, documentation, control implementation) typically exceed audit fees by 3–5x.
ISO 27001 certification is recognized in over 160 countries and is frequently required for: government contracts (especially in the EU and UK), enterprise procurement (often alongside or instead of SOC 2), healthcare partnerships, financial services vendor relationships, and international data transfer agreements. It serves as the global baseline for "this organization takes information security seriously."
ISO 27001 certification is a global compliance barrier for AI companies. Unlike SOC 2 (primarily US-focused), ISO 27001 is required for international business. AI companies seeking global enterprise sales need both SOC 2 (for US customers) and ISO 27001 (for international customers). The combined compliance cost and time investment creates a significant barrier to entry — particularly for small AI companies and open-source AI projects.
The three-year certification cycle creates a lag in AI security control updates. ISO 27001 certificates are valid for three years. If new AI threats emerge (e.g., a novel model extraction attack), the ISMS must be updated — but the certification audit only verifies controls annually. Between surveillance audits, control effectiveness is self-assessed. For rapidly evolving AI systems, this cadence may be too slow to catch security regressions.
The certifiable standard creates a market for compliance, not security. Organizations pursue ISO 27001 certification to pass procurement gates, not necessarily to improve security. The audit verifies that controls exist and operate — not that they effectively address AI-specific risks. A certified organization may have excellent documentation for traditional controls while leaving AI-specific vulnerabilities unaddressed. The certificate signals compliance, not AI security competence.
ISO 27001 is designed as a comprehensive ISMS that can encompass or map to other frameworks. Organizations often implement ISO 27001 as their primary security framework and use its controls to satisfy additional requirements: SOC 2 Trust Services Criteria, PCI DSS requirements, NIST SP 800-53 controls, and HIPAA Security Rule safeguards. This "umbrella" approach reduces duplication — one set of policies and controls can evidence compliance across multiple frameworks.
ISO 27001 vs SOC 2: ISO 27001 is certifiable (pass/fail certificate issued), while SOC 2 produces an auditor's opinion report (no certificate). ISO 27001 is prescriptive (you must implement the ISMS clauses), while SOC 2 is criteria-based (you design controls to meet the TSC). Many organizations obtain both — ISO 27001 for international recognition, SOC 2 for US enterprise sales.
ISO 27001 vs NIST SP 800-53: NIST 800-53 is a control catalog used by US federal agencies; ISO 27001 is an international management system standard. The control sets overlap significantly. Organizations certified to ISO 27001 can map their controls to NIST 800-53 to streamline FedRAMP or federal compliance efforts.
ISO 27001 vs ISO 42001: ISO/IEC 42001:2023 is the AI Management System standard — essentially "ISO 27001 for AI." Organizations certified to ISO 27001 can extend their management system to cover AI governance through ISO 42001. The two standards are designed to work together: 27001 for information security, 42001 for AI-specific governance.
The umbrella mapping means ISO 27001 can become the AI compliance foundation. If an organization builds its AI security controls within an ISO 27001 ISMS, those controls can simultaneously satisfy SOC 2, PCI DSS, and emerging AI-specific requirements. This makes ISO 27001 the strategic starting point for multi-framework AI compliance — but only for organizations that can afford the certification investment.
ISO 42001 extends the barrier to AI-specific governance. As ISO 42001 (AI Management System) gains adoption, organizations will face a new certification cost layer on top of ISO 27001. The combined requirement — 27001 for infosec, 42001 for AI governance — creates a higher barrier to entry for AI companies, particularly startups and open-source projects that lack compliance budgets.
Related frameworks: ISO/IEC 42001 (AI Management System standard — the AI-specific extension) · SOC 2 (US enterprise equivalent, often obtained alongside) · NIST SP 800-53 (US federal control catalog with significant overlap) · PCI DSS v4.0 (can be mapped under ISO 27001 ISMS) · GDPR (ISO 27001 supports GDPR compliance through security controls) · EU AI Act (ISO 27001 + ISO 42001 can support AI Act conformity)
Investigation tracks: The Compliance Trap (certification cost as market barrier) · The Infrastructure Play (cloud providers' inherited ISO 27001 certifications) · The Asymmetry (large AI companies' compliance portfolios vs startup barriers)