← Back to Compliance
ISO

ISO/IEC 27001:2022

Information security management system. The 2022 revision introduced controls for cloud services, data leakage prevention, and threat intelligence — all directly impacted by unmonitored AI tool usage.

Current version — transition deadline October 2025

A.5.23 Information security for use of cloud services

Organisations must define and implement controls for the acquisition, use, management, and exit from cloud services, including documenting data transfers to cloud providers.

Captures every API call made to external AI providers (Anthropic, Google, OpenAI) including data transferred. Produces audit-ready logs of cloud service usage that satisfy A.5.23 evidence requirements.

A.8.12 Data leakage prevention

DLP measures must be applied to systems, networks, and devices that process, store, or transmit sensitive information. Organisations must detect and prevent unauthorised disclosure.

Policy engine acts as a DLP enforcement point for AI tool data flows — detecting sensitive data categories (PII, credentials, health data, confidential IP) in MCP server calls and blocking or alerting in real time.

A.5.19 Information security in supplier relationships

Security requirements for accessing organisational assets must be agreed with suppliers and documented, including third-party AI providers processing organisational data.

Provides continuous evidence of what data was shared with each AI provider — Anthropic, Google, OpenAI — at what time, by which user, and under which policy. Turns a static contractual control into a live operational one.

A.8.11 Data masking

Data masking, pseudonymisation, or anonymisation must be applied to sensitive data in processing or transfer where appropriate, based on access control policy.

Detects sensitive data categories in MCP server payloads before they reach external models. Policy engine can warn or block calls where unmasked PII or confidential data is detected. Audit trail shows which calls were governed.

Strengthen your ISO 27001 posture for AI

See how Svalin provides the evidence your auditors need for AI tool governance.

Request a Demo