ISO/IEC 27001:2022
A certifiable management system standard for information security. It predates the AI standards and is the control set most organisations already hold, which is why some AI duties - security, incident handling, access - land on it rather than on an AI-specific standard.
- Duties mapped
- 3
- Mappings
- 3
- Jurisdictions
- 2
- Clauses used
- 2
- Evidence types
- 11
- Risk areas
- 9
- Recorded incidents
- 730
Duties are what the law asks; controls are what an organisation operates to meet them; evidence is how it shows it did. Incidents are the harms the AI Incident Database has recorded under the risk areas those controls address.
How it is structured
Requirements in clauses 4 to 10, with Annex A reference controls grouped into organisational, people, physical and technological themes.
Where an AI duty is really a security duty, existing ISO/IEC 27001 evidence may already satisfy it. This is the smallest crosswalk on the platform and is recorded for completeness rather than coverage.
Legal duties by clause
A duty appears under every clause its mapping cites, so the totals below exceed the 3 distinct duties. References that name no single clause are grouped at the end rather than dropped.
Clause 8 2 duties
-
Achieve appropriate accuracy, robustness and cybersecurity
EU AI Act · European Union · cites Clause 8 and Annex A security controls
Original editorial mapping for cybersecurity aspects.
-
Providers of systemic-risk GPAI models must secure the model and its infrastructure
EU AI Act · European Union · cites Clause 8.1; Annex A 5.15, A 8.24
Access control and cryptography applied to model assets.
Annex A 3 duties
-
Achieve appropriate accuracy, robustness and cybersecurity
EU AI Act · European Union · cites Clause 8 and Annex A security controls
Original editorial mapping for cybersecurity aspects.
-
Implement reasonable security safeguards and notify breaches
India DPDP Act · India · cites Annex A incident management controls
Original editorial mapping.
-
Providers of systemic-risk GPAI models must secure the model and its infrastructure
EU AI Act · European Union · cites Clause 8.1; Annex A 5.15, A 8.24
Access control and cryptography applied to model assets.
Controls that cite this standard
Each control is an original description of what an organisation operates. The reference is the clause it corresponds to, by number only.
| Control | Clause | Duties served | Evidence |
|---|---|---|---|
| AI incident management and regulatory reporting Process | Annex A 5.24 to 5.28 Information security incident management | 14 | AI incident response playbook, AI incident record, Incident report to an authority |
| Accuracy, robustness, fairness and security testing Technical measure | Clause 8.1; Annex A 8.29 Security testing in development | 15 | Pre-release test report, Test plan and acceptance criteria, Release test sign-off |
| Automatic event logging and record retention Technical measure | Annex A 8.15 Logging, 8.16 Monitoring activities | 8 | AI system event logs, Log schema and retention standard, Log integrity and retention check |
| Model release and change-management gate Process | Annex A 8.32 Change management | 5 | Release or change approval record, Release and change-classification procedure |
| Privacy and data-protection controls for AI Process | Annex A 5.34 Privacy and protection of PII | 13 | Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use |
| Vendor and third-party AI due diligence Process | Annex A 5.19 to 5.22 Supplier relationships | 6 | AI supplier due-diligence assessment, AI supplier and component register, Supplier onboarding decision |
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- What is ISO/IEC 27001:2022?
- A certifiable management system standard for information security. It predates the AI standards and is the control set most organisations already hold, which is why some AI duties - security, incident handling, access - land on it rather than on an AI-specific standard.
- Does ISO/IEC 27001 make an organisation legally compliant?
- No. Certification evidences a management practice, not compliance with any statute. A crosswalk shows where the two overlap so existing evidence can be reused; it does not transfer legal obligations.