When AI security comes up, most of the conversation is about Microsoft features — DSPM, DLP, Insider Risk. All necessary. But the question I get from CISOs and audit committees is different and more durable: “How does any of this fit into our ISO 27001 program?”

As an ISO 27001 Lead Auditor who now spends most days on AI security, here’s how I bridge the two.

You don’t need a new ISMS — you need to extend the one you have

The instinct to bolt on a separate “AI security program” is usually a mistake. ISO 27001 is deliberately a management system: risk-based, control-driven, continually improved. Generative AI doesn’t break that model; it introduces new assets, new risks, and new controls that flow through the same machinery you already run.

Concretely, AI adoption shows up in your ISMS as:

  • New assets — Copilot, agents, connectors, the data they can reach, and the prompts/responses they generate.
  • New risks — oversharing amplification, prompt injection, shadow AI, data egress to third-party models.
  • New or adapted controls — many of which map cleanly onto Annex A.

Mapping AI controls to Annex A

The 2022 revision of ISO/IEC 27001 made this mapping easier than people expect. A few examples of how AI controls land against existing control themes:

  • Information classification & handling → sensitivity labels for GenAI and the protection of labelled content from AI grounding.
  • Access control → the permissions hygiene and oversharing remediation that determine what Copilot can surface.
  • Data leakage preventionPurview DLP runtime guardrails and shadow-AI controls.
  • Logging & monitoring → audit, eDiscovery, and retention for AI interactions.
  • Use of cryptography → encryption and usage rights that AI honours.
  • Threat intelligence & secure developmentprompt-injection defences and red-team validation of AI systems.
  • Supplier & cloud-service security → governance of third-party AI platforms and external model routing.

The point isn’t to invent new clauses. It’s to demonstrate, through your existing risk assessment and Statement of Applicability, that AI risk has been considered, treated, and evidenced.

Where ISO/IEC 42001 comes in

ISO 27001 governs information security. The newer ISO/IEC 42001 is an AI management system standard — it addresses how an organization governs AI itself: impact assessment, accountability, transparency, lifecycle management, and responsible-AI commitments that sit beyond pure security.

My practical guidance:

  • If your concern is securing AI adoption, ISO 27001 — extended thoughtfully — carries most of the load today.
  • If your organization is building or deploying AI as a core capability, ISO/IEC 42001 gives you a dedicated governance framework that complements (not replaces) 27001. The two interlock: 42001 for AI governance and accountability, 27001 for the security controls underneath.

For most enterprises adopting Copilot, the right first move is to bring AI into the 27001 ISMS now, and evaluate 42001 as AI use matures. When you get to that point, I’ve written a full ISO/IEC 42001 implementation path covering scope, impact assessment, Annex A and the Statement of Applicability — and how much of your existing ISMS you can reuse rather than rebuild.

Auditing AI: evidence beats assertions

When I audit an AI deployment against an ISMS, I’m not looking for a slide that says “we use Copilot securely.” I’m looking for the same things any good audit looks for: a risk assessment that names AI risks, controls that treat them, and evidence that the controls operate — DLP test results, audit searches that recovered seeded activity, connector approval records, red-team findings.

That’s the real value of mapping AI to ISO 27001: it forces AI security out of the realm of vendor demos and into the realm of governed, evidenced, continually-improved control — exactly where regulators and boards increasingly expect it to be.

This sits at the intersection of my two specialties — Microsoft AI security and ISO 27001/SOC 2 certification. If you’re working toward certification while adopting AI, or want your AI program to stand up to an audit, let’s talk. The broader rollout method is in the secure Copilot launch playbook.