Standard

ISO/IEC 27001: the controls that touch AI traffic

ISO/IEC 27001 certifies a management system, not a product. That distinction is why an AI gateway helps here in two ways at once: it supports the controls that apply to your AI traffic, and it is itself an asset that belongs in the inventory.

The instrument
ISO/IEC 27001:2022 for the management system requirements, with the ISO/IEC 27002:2022 control guidance
Status
In force (third edition)
Who it applies to
Organisations running, or preparing for, an information security management system that covers AI systems.

Where AI-FW fits

AI-FW supports the technological and organisational controls that apply to the AI path, and it is itself an ISMS asset in scope. The management system, the risk treatment plan, the statement of applicability and the audit programme remain yours. What the product adds is enforcement with evidence attached, so a control you claim has something behind it on the day of the audit.

What stays with you

Read this list first. It is the boundary of what a product can do for you, and it is where the remaining work sits.

  • The management system itself: context, leadership, planning, support, operation, evaluation and improvement
  • The risk assessment and the risk treatment plan
  • The statement of applicability across the full control set
  • Organisational asset inventory and classification, where the product inventory is an input rather than the ISMS record
  • The internal audit programme, management review, and the certification audit with your chosen body

What the framework asks, and what the product does

The obligations that touch the AI path, paired with the capability that answers each one. Everything else in this framework is organisational work, listed above.

Asset inventory
What it asks

Know what information and associated assets you hold

What AI-FW does

A model inventory, an agent registry and a certificate inventory that give a system-level view of the AI path

Access control
What it asks

Limit access, and control privileged access

What AI-FW does

Role policies separating administrative from read-only access, per-agent identity, owner-scoped views, and audited access changes

Identity and authentication
What it asks

Manage identities and authentication information securely

What AI-FW does

A key registry with hashed, revocable, owner-scoped credentials, mutual TLS against trusted anchors, and Kerberos allowlists

Data masking
What it asks

Mask sensitive data where it is displayed or used

What AI-FW does

Personal, payment and health masking rules, a content-capture policy, and secret masking in configuration and reports

Data leakage prevention
What it asks

Prevent sensitive information from leaving

What AI-FW does

Inbound and outbound rules that stop sensitive content reaching model providers, plus a guard against unapproved endpoints

Logging and monitoring
What it asks

Record events, and monitor activity

What AI-FW does

Transaction and access records with actor, model, outcome and timestamp, dashboards for review, and drift findings

Configuration and change management
What it asks

Control configuration, and control change

What AI-FW does

Every rule and setting change audited with an actor, and configuration treated as reviewable data rather than a hidden file

Cryptography
What it asks

Use cryptography appropriately and protect keys

What AI-FW does

TLS everywhere, keys hashed at rest, and a tamper-evident usage ledger for integrity

Supplier and cloud controls
What it asks

Manage supplier relationships and cloud services

What AI-FW does

The model inventory enumerates every provider endpoint, and per-model configuration shows the data path for each

Vulnerability management
What it asks

Manage technical vulnerabilities and stay informed

What AI-FW does

Images pinned by tag and digest, dependency vulnerability review in release checks, and rule sets that can be updated as abuse patterns change

Independent review
What it asks

Review compliance with your own policies

What AI-FW does

Evidence packs give an auditor a point-in-time, reproducible view, and assessment history shows continuity between periods

A rule pack to start from

The enforcement that makes the controls real. Severity runs 1 to 5, and a rule that is switched off reports as a gap, so these are meant to be live from day one.

Personal, payment and health data classesInboundMaskSeverity 4

Data masking as a standing control rather than a project

Bulk identifiers or key material on the way outOutboundBlockSeverity 5

Data leakage prevention for the AI route

Prompt injection and abuse patternsInboundBlockSeverity 4

Protects the confidentiality of what you allow through

Unapproved model endpointInboundBlockSeverity 4

Supplier control, enforced rather than described

Script or payload content in promptsInboundBlockSeverity 3

Defence in depth where prompts reach tools and downstream systems

What the evidence pack contains

Per period, and without prompt or response content, which is what makes it safe to hand over.

  • Control statusesMapped to the controls your statement of applicability claims
  • Live rule statePresent, enabled, with the correct action and direction
  • Role and authentication configurationLeast privilege, and only the methods in use
  • Retention valuesAligned to your retention schedule
  • Asset inventoryModels, agents and certificate anchors, as an input to your own record

Customer responsibilities and sources

Yours to run
  • Operate the management system in full, including risk assessment and risk treatment.
  • Maintain the statement of applicability across the whole control set, including areas the AI path does not touch.
  • Own the organisational asset inventory and classification: the product inventory feeds it and does not replace it.
  • Run the internal audit programme and management review, and complete your certification audit with your chosen body.
  • Verify host-level items the product inherits, such as clock synchronisation.

Common questions

No, and no product can. The certification covers your management system and is assessed by your chosen certification body. What the product does is put something enforceable and reviewable behind the AI-relevant controls, which shortens the distance between the control described in your statement of applicability and the evidence an auditor samples.

Because it sits in the path of information flows that matter. It holds provider credentials, it sees requests and responses, and it decides what is allowed through. That makes it a security-relevant component that belongs in your inventory and your risk assessment, like any other.

They stay with you, which is normal: physical security, people controls, supplier contracts, business continuity and incident management are organisational. The useful thing is knowing where the boundary sits, so the statement of applicability does not claim coverage it does not have.

Validate it yourself with our Technical Plan

Ask us to run this framework against your own environment: the rules that would be created, what the assessment reports, and what the evidence pack contains for a real period.

This page maps product capabilities to published expectations. It is not legal, audit or certification advice, and it creates no compliance representation. Applicability and sufficiency are judgements for your counsel and, where relevant, your auditor, assessor or certification body. Framework details are current as reviewed; check the primary sources above, and the page itself, before relying on a date or a threshold.