AIPolicyTracker
Certifiable ISO and IEC · 2022

ISO/IEC 27001:2022

A certifiable management system standard for information security. It predates the AI standards and is the control set most organisations already hold, which is why some AI duties - security, incident handling, access - land on it rather than on an AI-specific standard.

Duties mapped
3
Mappings
3
Jurisdictions
2
Clauses used
2
Evidence types
11
Risk areas
9
Recorded incidents
730

Duties are what the law asks; controls are what an organisation operates to meet them; evidence is how it shows it did. Incidents are the harms the AI Incident Database has recorded under the risk areas those controls address.

How it is structured

Requirements in clauses 4 to 10, with Annex A reference controls grouped into organisational, people, physical and technological themes.

Where an AI duty is really a security duty, existing ISO/IEC 27001 evidence may already satisfy it. This is the smallest crosswalk on the platform and is recorded for completeness rather than coverage.

Legal duties by clause

A duty appears under every clause its mapping cites, so the totals below exceed the 3 distinct duties. References that name no single clause are grouped at the end rather than dropped.

Clause 8 2 duties

Annex A 3 duties

Controls that cite this standard

Each control is an original description of what an organisation operates. The reference is the clause it corresponds to, by number only.

Controls referencing ISO/IEC 27001
ControlClauseDuties servedEvidence
AI incident management and regulatory reporting
Process
Annex A 5.24 to 5.28 Information security incident management14AI incident response playbook, AI incident record, Incident report to an authority
Accuracy, robustness, fairness and security testing
Technical measure
Clause 8.1; Annex A 8.29 Security testing in development15Pre-release test report, Test plan and acceptance criteria, Release test sign-off
Automatic event logging and record retention
Technical measure
Annex A 8.15 Logging, 8.16 Monitoring activities8AI system event logs, Log schema and retention standard, Log integrity and retention check
Model release and change-management gate
Process
Annex A 8.32 Change management5Release or change approval record, Release and change-classification procedure
Privacy and data-protection controls for AI
Process
Annex A 5.34 Privacy and protection of PII13Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use
Vendor and third-party AI due diligence
Process
Annex A 5.19 to 5.22 Supplier relationships6AI supplier due-diligence assessment, AI supplier and component register, Supplier onboarding decision

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

What is ISO/IEC 27001:2022?
A certifiable management system standard for information security. It predates the AI standards and is the control set most organisations already hold, which is why some AI duties - security, incident handling, access - land on it rather than on an AI-specific standard.
Does ISO/IEC 27001 make an organisation legally compliant?
No. Certification evidences a management practice, not compliance with any statute. A crosswalk shows where the two overlap so existing evidence can be reused; it does not transfer legal obligations.