Clause 6.1.2
Information security risk assessment
Clause 6.1.2 requires a defined, repeatable risk assessment process: establish criteria, identify risks to the confidentiality, integrity, and availability of information within ISMS scope, analyze likelihood and consequence, and evaluate against the criteria. Results must be documented and drive the Clause 6.1.3 treatment plan and Statement of Applicability.
Business data flowing into external AI tools is a confidentiality risk squarely within scope, so a post-2022 risk assessment that never mentions AI is incomplete on its face. The inputs have to be real: LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage, and IBM found shadow AI involvement added an average of $670K to breach costs in 2025. A risk assessment built without visibility into actual AI usage understates both likelihood and impact, and the treatment plan built on it treats the wrong risks.
Annex A, Control 5.14
Information transfer
Control A.5.14 requires rules, procedures, and agreements for transferring information within the organization and to external parties, across all transfer types: electronic, physical, and verbal.
A prompt submitted to an external AI tool is an information transfer to an external party, made from a browser tab with no transfer agreement in sight. A.5.14 requires the organization to define which information may be transferred to which parties under what safeguards, which means AI tools need the same treatment as any other external recipient: defined rules on what data may go, and a mechanism that enforces those rules where the transfer actually happens, in the browser at the moment of submission.
Annex A, Control 8.12
Data leakage prevention
Control A.8.12, new in the 2022 edition, requires data leakage prevention measures to be applied to systems, networks, and other devices that process, store, or transmit sensitive information, in order to detect and prevent unauthorized disclosure and exfiltration.
This is the control that speaks most directly to AI prompts. Classic DLP tooling watches email and file transfers; text typed or pasted into an AI chat interface is a leakage channel those deployments often miss. IBM found in 2025 that only 17% of organizations have technical controls that redact or block sensitive data at the point of entry to AI tools. An auditor testing A.8.12 against a scope statement that includes browser-based work can reasonably ask what detects and prevents sensitive data leaving through AI prompts; a policy PDF is not a leakage prevention measure.
Annex A, Control 5.10
Acceptable use of information and other associated assets
Control A.5.10 requires rules for acceptable use and procedures for handling information and associated assets to be identified, documented, and implemented. Anyone using or handling the organization's information must know and follow them.
The acceptable-use policy is where organizations state which AI tools may be used and with what data, but A.5.10 says implemented, not just documented. With 71% of GenAI connections going through personal, non-corporate accounts (LayerX, 2025), the gap between the written rule and actual behaviour is the norm, not the exception. Evidence that the rules operate, such as records of sensitive data being caught before reaching unapproved tools, is what turns a policy document into an implemented control.
Annex A, Control 6.3
Information security awareness, education and training
Control A.6.3 requires personnel to receive appropriate security awareness, education, and training, including regular updates to the organization's policies and procedures relevant to their role.
Training now has to cover AI: what the approved tools are, which data types must never enter a prompt, and why. But awareness alone has known limits; people paste under deadline pressure. The strongest awareness mechanism is feedback at the moment of risk: a redaction that happens in front of the employee as they submit a prompt teaches the policy at exactly the point where training would otherwise fail, and gives A.6.3 evidence that awareness translates into behaviour.