Building an AI-Era Risk Program Beyond ISO 27001 Certification

Summary
OneTrust CISO Tim Mullen argues that ISO 27001 should be a foundation, not the finish line, for AI-era risk management. He recommends connecting risk decisions to business context, standardizing before automating, and continuously monitoring control effectiveness.
Key points
- The article cites OneTrust research reporting that 86% of organizations had at least one AI-related incident last year, while 27% slowed or paused AI rollout.
- Risk programs should identify critical processes, systems, data, risk scenarios, and accountable owners before selecting tools.
- Organizations should assess whether controls work and reduce risk, not just whether controls exist or meet compliance requirements.
- ISO 27001 and NIST frameworks can be mapped to shared controls and evidence to reduce parallel compliance work.
- AI systems with greater autonomy and access warrant stronger monitoring and intervention; inventories should include data, identities, permissions, dependencies, and affected business processes.
- Standardize processes before automating them, and document control exceptions with compensating measures, an owner, and a review or end date.
- Continuous control monitoring can detect configuration changes, security-setting drift, expired evidence, or ineffective controls so risk assessments can be updated between audits.
Article Details
- Topic
- Building an AI-aware risk management program on an ISO 27001 foundation