Security & Audit Frameworks

ISO/IEC 27001

ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements

The world's leading certifiable standard for information security management, read here through an AI lens: what employee use of external AI tools means for your ISMS, your risk assessment, and controls like information transfer and data leakage prevention.

International (voluntary, certifiable)In force, certifiable; current edition published October 2022Verified 2026-08-31

What it means for AI and data privacy

ISO/IEC 27001 predates the generative AI wave, but its machinery covers it completely: an employee pasting client records into an external chatbot is an information transfer to an outside party, a data leakage event, and an acceptable-use violation all at once, and each of those maps to a specific Annex A control in the 2022 edition. The Clause 6.1.2 risk assessment that anchors the ISMS must now include AI data flows, because a risk register that ignores where 88% of employees with enterprise AI access also use personal AI tools (Gartner, 2026) is not describing the organization it claims to describe. Certification auditors increasingly ask how the ISMS handles AI usage, and certified organizations that treat AI as out of scope carry an undocumented gap through every surveillance audit. The practical reading: your existing ISO 27001 obligations already require you to see, assess, and control what data leaves for AI tools; no new standard is needed to make that mandatory.

Who it applies to

  • Any organization operating or pursuing an ISO 27001 certified information security management system
  • Organizations whose customers require ISO 27001 certification in procurement, contracts, or security questionnaires
  • Certified organizations whose employees use browser-based AI tools with business data, which puts AI inside ISMS scope
  • Organizations extending an existing ISMS toward AI governance, including ISO 42001 integration

Enforcement and penalties

ISO 27001 itself imposes no fines; it is a voluntary certifiable standard. The consequences are contractual and evidentiary: nonconformities found at audit can suspend or revoke a certificate that customer contracts depend on, and an organization that certified an ISMS while leaving known AI data flows unassessed has documented its own negligence for any later breach litigation or regulatory inquiry. Statutory penalties arrive through the privacy laws the ISMS is meant to help satisfy, such as GDPR, PIPEDA, and Quebec Law 25, where Law 25 fines reach C$25 million or 4% of worldwide turnover.

Key provisions for AI and data privacy

Clause 6.1.2

Information security risk assessment

Clause 6.1.2 requires a defined, repeatable risk assessment process: establish criteria, identify risks to the confidentiality, integrity, and availability of information within ISMS scope, analyze likelihood and consequence, and evaluate against the criteria. Results must be documented and drive the Clause 6.1.3 treatment plan and Statement of Applicability.

Business data flowing into external AI tools is a confidentiality risk squarely within scope, so a post-2022 risk assessment that never mentions AI is incomplete on its face. The inputs have to be real: LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage, and IBM found shadow AI involvement added an average of $670K to breach costs in 2025. A risk assessment built without visibility into actual AI usage understates both likelihood and impact, and the treatment plan built on it treats the wrong risks.

Annex A, Control 5.14

Information transfer

Control A.5.14 requires rules, procedures, and agreements for transferring information within the organization and to external parties, across all transfer types: electronic, physical, and verbal.

A prompt submitted to an external AI tool is an information transfer to an external party, made from a browser tab with no transfer agreement in sight. A.5.14 requires the organization to define which information may be transferred to which parties under what safeguards, which means AI tools need the same treatment as any other external recipient: defined rules on what data may go, and a mechanism that enforces those rules where the transfer actually happens, in the browser at the moment of submission.

Annex A, Control 8.12

Data leakage prevention

Control A.8.12, new in the 2022 edition, requires data leakage prevention measures to be applied to systems, networks, and other devices that process, store, or transmit sensitive information, in order to detect and prevent unauthorized disclosure and exfiltration.

This is the control that speaks most directly to AI prompts. Classic DLP tooling watches email and file transfers; text typed or pasted into an AI chat interface is a leakage channel those deployments often miss. IBM found in 2025 that only 17% of organizations have technical controls that redact or block sensitive data at the point of entry to AI tools. An auditor testing A.8.12 against a scope statement that includes browser-based work can reasonably ask what detects and prevents sensitive data leaving through AI prompts; a policy PDF is not a leakage prevention measure.

Annex A, Control 5.10

Acceptable use of information and other associated assets

Control A.5.10 requires rules for acceptable use and procedures for handling information and associated assets to be identified, documented, and implemented. Anyone using or handling the organization's information must know and follow them.

The acceptable-use policy is where organizations state which AI tools may be used and with what data, but A.5.10 says implemented, not just documented. With 71% of GenAI connections going through personal, non-corporate accounts (LayerX, 2025), the gap between the written rule and actual behaviour is the norm, not the exception. Evidence that the rules operate, such as records of sensitive data being caught before reaching unapproved tools, is what turns a policy document into an implemented control.

Annex A, Control 6.3

Information security awareness, education and training

Control A.6.3 requires personnel to receive appropriate security awareness, education, and training, including regular updates to the organization's policies and procedures relevant to their role.

Training now has to cover AI: what the approved tools are, which data types must never enter a prompt, and why. But awareness alone has known limits; people paste under deadline pressure. The strongest awareness mechanism is feedback at the moment of risk: a redaction that happens in front of the employee as they submit a prompt teaches the policy at exactly the point where training would otherwise fail, and gives A.6.3 evidence that awareness translates into behaviour.

Practical compliance steps

  1. 1Confirm your ISMS scope statement covers browser-based work and employee use of external AI tools, and record the decision
  2. 2Update the Clause 6.1.2 risk assessment with AI data flows as identified risks, using discovered usage rather than assumptions
  3. 3Extend the acceptable-use policy (A.5.10) with named approved AI tools and prohibited data types, and communicate it
  4. 4Apply A.5.14 transfer rules to AI tools: define what information may be submitted to which tools under what safeguards
  5. 5Deploy a data leakage prevention measure (A.8.12) that catches sensitive data in prompts at the point of entry, before submission
  6. 6Refresh A.6.3 training to cover AI usage rules, reinforced by in-the-moment feedback when sensitive data is caught
  7. 7File interception and usage reports as ISMS records so internal audits and certification audits can sample operating evidence

How Sanitized AI maps to this

A.8.12 (data leakage prevention)

Sensitive data in prompts is redacted before submission, applying leakage prevention to the AI-prompt channel that traditional DLP deployments watching email and file transfers commonly miss.

A.5.14 (information transfer) and A.5.10 (acceptable use)

Transfer and acceptable-use rules are enforced where the transfer happens: data types the policy prohibits are caught in the browser at the moment of submission, turning documented rules into implemented controls.

Clause 6.1.2 (risk assessment)

Administrator dashboards show which AI tools are in use and which categories of sensitive data were caught, giving the risk assessment real likelihood and impact inputs for AI data flows.

A.6.3 (awareness and training)

Employees see redactions as they happen, which reinforces training at the exact moment of risk and gives the ISMS evidence that awareness produces changed behaviour.

Frequently asked questions

Does ISO 27001 cover employee use of AI tools like ChatGPT?

Yes, through its existing machinery. Business data entered into an external AI tool is within ISMS scope as an information transfer (A.5.14), a potential leakage event (A.8.12), and an acceptable-use matter (A.5.10), and the Clause 6.1.2 risk assessment must account for it. No AI-specific standard is needed to make this mandatory for a certified organization.

Which ISO 27001 controls apply to data pasted into AI chatbots?

The core set is A.5.14 (information transfer rules for external parties), A.8.12 (data leakage prevention on channels carrying sensitive information), A.5.10 (acceptable use of information and assets), and A.6.3 (awareness and training). Depending on context, supplier controls and classification controls (A.5.12, A.5.13) also come into play.

Does ISO 27001:2022 require DLP for AI prompts?

Control A.8.12 requires data leakage prevention measures on systems that process or transmit sensitive information, and it does not exempt any channel. If employees can move sensitive information out through AI prompts and nothing detects or prevents it, that is a gap an auditor can raise. IBM found in 2025 that only 17% of organizations have technical controls redacting or blocking sensitive data at the point of entry.

Do we need to update our ISO 27001 risk assessment for AI?

Yes. Clause 6.1.2 requires the risk assessment to reflect the risks the organization actually faces, and employee AI usage is now one of them: Gartner reported in 2026 that 88% of employees with enterprise AI access also use personal AI tools. A risk register with no AI entries describes an organization that no longer exists, and the treatment plan built on it inherits the blind spot.

Is ISO 27001 enough for AI governance, or do we need ISO 42001 too?

ISO 27001 covers the information security side of AI use: data leaving through prompts, transfer rules, leakage prevention, awareness. ISO 42001 adds AI-specific governance the ISMS does not require, such as AI system impact assessments and lifecycle controls. The two share the same management-system structure, so organizations typically extend the existing ISMS rather than starting over. If your only AI exposure is employees using external tools, disciplined ISO 27001 execution covers most of the ground.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards