ISO/IEC 27001: the controls that touch AI traffic
ISO/IEC 27001 certifies a management system, not a product. That distinction is why an AI gateway helps here in two ways at once: it supports the controls that apply to your AI traffic, and it is itself an asset that belongs in the inventory.
- The instrument
- ISO/IEC 27001:2022 for the management system requirements, with the ISO/IEC 27002:2022 control guidance
- Status
- In force (third edition)
- Who it applies to
- Organisations running, or preparing for, an information security management system that covers AI systems.
Where AI-FW fits
AI-FW supports the technological and organisational controls that apply to the AI path, and it is itself an ISMS asset in scope. The management system, the risk treatment plan, the statement of applicability and the audit programme remain yours. What the product adds is enforcement with evidence attached, so a control you claim has something behind it on the day of the audit.
What stays with you
Read this list first. It is the boundary of what a product can do for you, and it is where the remaining work sits.
- The management system itself: context, leadership, planning, support, operation, evaluation and improvement
- The risk assessment and the risk treatment plan
- The statement of applicability across the full control set
- Organisational asset inventory and classification, where the product inventory is an input rather than the ISMS record
- The internal audit programme, management review, and the certification audit with your chosen body
What the framework asks, and what the product does
The obligations that touch the AI path, paired with the capability that answers each one. Everything else in this framework is organisational work, listed above.
Know what information and associated assets you hold
A model inventory, an agent registry and a certificate inventory that give a system-level view of the AI path
Limit access, and control privileged access
Role policies separating administrative from read-only access, per-agent identity, owner-scoped views, and audited access changes
Manage identities and authentication information securely
A key registry with hashed, revocable, owner-scoped credentials, mutual TLS against trusted anchors, and Kerberos allowlists
Mask sensitive data where it is displayed or used
Personal, payment and health masking rules, a content-capture policy, and secret masking in configuration and reports
Prevent sensitive information from leaving
Inbound and outbound rules that stop sensitive content reaching model providers, plus a guard against unapproved endpoints
Record events, and monitor activity
Transaction and access records with actor, model, outcome and timestamp, dashboards for review, and drift findings
Control configuration, and control change
Every rule and setting change audited with an actor, and configuration treated as reviewable data rather than a hidden file
Use cryptography appropriately and protect keys
TLS everywhere, keys hashed at rest, and a tamper-evident usage ledger for integrity
Manage supplier relationships and cloud services
The model inventory enumerates every provider endpoint, and per-model configuration shows the data path for each
Manage technical vulnerabilities and stay informed
Images pinned by tag and digest, dependency vulnerability review in release checks, and rule sets that can be updated as abuse patterns change
Review compliance with your own policies
Evidence packs give an auditor a point-in-time, reproducible view, and assessment history shows continuity between periods
A rule pack to start from
The enforcement that makes the controls real. Severity runs 1 to 5, and a rule that is switched off reports as a gap, so these are meant to be live from day one.
Data masking as a standing control rather than a project
Data leakage prevention for the AI route
Protects the confidentiality of what you allow through
Supplier control, enforced rather than described
Defence in depth where prompts reach tools and downstream systems
What the evidence pack contains
Per period, and without prompt or response content, which is what makes it safe to hand over.
- Control statusesMapped to the controls your statement of applicability claims
- Live rule statePresent, enabled, with the correct action and direction
- Role and authentication configurationLeast privilege, and only the methods in use
- Retention valuesAligned to your retention schedule
- Asset inventoryModels, agents and certificate anchors, as an input to your own record
Customer responsibilities and sources
- Operate the management system in full, including risk assessment and risk treatment.
- Maintain the statement of applicability across the whole control set, including areas the AI path does not touch.
- Own the organisational asset inventory and classification: the product inventory feeds it and does not replace it.
- Run the internal audit programme and management review, and complete your certification audit with your chosen body.
- Verify host-level items the product inherits, such as clock synchronisation.
Common questions
No, and no product can. The certification covers your management system and is assessed by your chosen certification body. What the product does is put something enforceable and reviewable behind the AI-relevant controls, which shortens the distance between the control described in your statement of applicability and the evidence an auditor samples.
Because it sits in the path of information flows that matter. It holds provider credentials, it sees requests and responses, and it decides what is allowed through. That makes it a security-relevant component that belongs in your inventory and your risk assessment, like any other.
They stay with you, which is normal: physical security, people controls, supplier contracts, business continuity and incident management are organisational. The useful thing is knowing where the boundary sits, so the statement of applicability does not claim coverage it does not have.
Validate it yourself with our Technical Plan
Ask us to run this framework against your own environment: the rules that would be created, what the assessment reports, and what the evidence pack contains for a real period.
This page maps product capabilities to published expectations. It is not legal, audit or certification advice, and it creates no compliance representation. Applicability and sufficiency are judgements for your counsel and, where relevant, your auditor, assessor or certification body. Framework details are current as reviewed; check the primary sources above, and the page itself, before relying on a date or a threshold.