ISO/IEC 27001 and AI flows
Regulation · ISO/IEC 27001
AI governance evidence can support an ISMS, but it is not the ISMS
This guide connects ISO/IEC 27001 to a bounded set of AI-flow facts, policies and decisions. DUBSAR is designed to organise that evidence; it does not provide certification or legal advice.
In 30 seconds
How ISO/IEC 27001 relates to connected AI flows.
- Question addressed
- Which facts and decisions could support work on ISO/IEC 27001?
- Next decision
- Confirm the applicable scope with qualified people, then assemble the evidence for one defined system.
- Declared limit
- The applicable scope and obligations must be established by qualified people. DUBSAR supports a defined evidence perimeter and does not issue a legal or certification verdict.
Current DUBSAR status
Evidence support, not automatic compliance
The applicable scope and obligations must be established by qualified people. DUBSAR supports a defined evidence perimeter and does not issue a legal or certification verdict.
ISO/IEC 27001 and AI flows
Start with the scope that actually applies
ISO/IEC 27001 requires an organisation-wide information security management system based on context, risk, leadership, controls and continual improvement. One AI gateway cannot satisfy that system by itself.
ISO/IEC 27001 and AI flows
Evidence the DUBSAR journey is designed to organise
DUBSAR records are designed to contribute evidence about selected AI assets, suppliers, access paths, policy decisions, exceptions and reviews to the organisation's existing ISMS.
- AI assets and owners
- Supplier and route records
- Access, policy and exception evidence
- Review, incident and improvement references
ISO/IEC 27001 and AI flows
Keep the legal and product boundary explicit
DUBSAR is not a certification body and does not certify ISO/IEC 27001. The organisation and its auditors decide whether evidence is sufficient for the chosen scope.
Use the resulting record as an input for qualified legal, security, compliance and audit work rather than as a self-issued verdict.
External sources
Check the official sources and current product claims.
Frequently asked questions
What to know before going further.
Does DUBSAR certify compliance with ISO/IEC 27001?
No. It is designed to organise evidence and apply policies on connected flows, but it is not a certification body or legal adviser.
What can a DUBSAR record contribute to work on ISO/IEC 27001?
A bounded view of the connected system, route, policy, decisions and human review. Governance, people, contracts and wider organisational controls remain necessary.
Read next
Continue with another DUBSAR guide.
The portal remains in private testing. These guides explain what DUBSAR is proving — and what it does not yet claim.