AIXYRA
All Frameworks
Security & resiliencePublished (2022 revision). The most widely adopted certifiable security management standard.

ISO/IEC 27001

ISO/IEC 27001:2022 — Information Security Management System

The global standard for information security management — and the security backbone AI systems inherit, from access control to supplier risk.

118 individual requirements seeded and assessable in AIXYRA.

ISO/IEC 27001 defines a certifiable information security management system: risk-driven selection of controls across access, cryptography, operations, suppliers, and incident management. Most enterprises already hold or pursue certification — and their AI systems fall inside its scope, whether or not the ISMS documentation mentions them.

AI strains an ISMS in specific places: new asset types (models, agents, vector stores, MCP servers) missing from asset inventories, new supplier relationships (model providers, AI APIs), and new data flows. Auditors increasingly ask how the ISMS covers AI — starting with whether the asset register even lists it.

Who it applies to

Any organization operating an ISMS or pursuing ISO/IEC 27001 certification — which, for AI governance, means any security team whose scope now includes AI systems.

Key requirement themes

Asset inventory

Controls presume you know your assets — AI systems, models, and their dependencies must appear in the register.

Access control & identity

Least-privilege access, strong authentication, and joiner-mover-leaver discipline extended to AI platforms and tools.

Supplier & third-party risk

Model providers, AI APIs, and external tools are suppliers — with the assessment and monitoring duties that implies.

Logging, monitoring & incident response

Security events involving AI systems need the same detection, logging, and response paths as everything else.

Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.

How AIXYRA helps

  • The eight-entity registry extends the ISMS asset inventory to AI: agents, models, MCP servers, tools, and the platforms behind them
  • Governance approval before deployment, with SSO, MFA, and role-based access on the platform itself
  • Dependency graphs expose third-party AI services and tools for supplier-risk review
  • The tamper-evident audit trail and monitoring integrations feed security review and incident investigation

ISO/IEC 27001 FAQ

Does ISO/IEC 27001 cover AI systems?

Yes — an ISMS scopes information assets, and AI systems, their models, and their data are assets. The common gap is inventory: AI adopted by teams outside the ISMS process never reaches the asset register, so controls never attach to it.

How does AIXYRA fit an existing ISMS?

AIXYRA acts as the AI-aware asset inventory and governance layer: every AI entity registered, owned, approved, and risk-scored, with assessments against seeded ISO/IEC 27001 articles and audit-ready evidence your ISMS audit can draw on.

Assess your AI systems against ISO/IEC 27001

ISO/IEC 27001 ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.