ISO/IEC 27001 and AI flows

Regulation · ISO/IEC 27001

AI governance evidence can support an ISMS, but it is not the ISMS

This guide connects ISO/IEC 27001 to a bounded set of AI-flow facts, policies and decisions. DUBSAR is designed to organise that evidence; it does not provide certification or legal advice.

In 30 seconds

How ISO/IEC 27001 relates to connected AI flows.

Question addressed
Which facts and decisions could support work on ISO/IEC 27001?
Next decision
Confirm the applicable scope with qualified people, then assemble the evidence for one defined system.
Declared limit
The applicable scope and obligations must be established by qualified people. DUBSAR supports a defined evidence perimeter and does not issue a legal or certification verdict.

Current DUBSAR status

Evidence support, not automatic compliance

The applicable scope and obligations must be established by qualified people. DUBSAR supports a defined evidence perimeter and does not issue a legal or certification verdict.

ISO/IEC 27001 and AI flows

Start with the scope that actually applies

ISO/IEC 27001 requires an organisation-wide information security management system based on context, risk, leadership, controls and continual improvement. One AI gateway cannot satisfy that system by itself.

ISO/IEC 27001 and AI flows

Evidence the DUBSAR journey is designed to organise

DUBSAR records are designed to contribute evidence about selected AI assets, suppliers, access paths, policy decisions, exceptions and reviews to the organisation's existing ISMS.

  • AI assets and owners
  • Supplier and route records
  • Access, policy and exception evidence
  • Review, incident and improvement references

ISO/IEC 27001 and AI flows

Keep the legal and product boundary explicit

DUBSAR is not a certification body and does not certify ISO/IEC 27001. The organisation and its auditors decide whether evidence is sufficient for the chosen scope.

Use the resulting record as an input for qualified legal, security, compliance and audit work rather than as a self-issued verdict.

External sources

Check the official sources and current product claims.

Frequently asked questions

What to know before going further.

Does DUBSAR certify compliance with ISO/IEC 27001?

No. It is designed to organise evidence and apply policies on connected flows, but it is not a certification body or legal adviser.

What can a DUBSAR record contribute to work on ISO/IEC 27001?

A bounded view of the connected system, route, policy, decisions and human review. Governance, people, contracts and wider organisational controls remain necessary.