Building an AI-Era Risk Program Beyond ISO 27001 Certification

· Original article ↗

Summary

OneTrust CISO Tim Mullen argues that ISO 27001 should be a foundation, not the finish line, for AI-era risk management. He recommends connecting risk decisions to business context, standardizing before automating, and continuously monitoring control effectiveness.

Key points

  • The article cites OneTrust research reporting that 86% of organizations had at least one AI-related incident last year, while 27% slowed or paused AI rollout.
  • Risk programs should identify critical processes, systems, data, risk scenarios, and accountable owners before selecting tools.
  • Organizations should assess whether controls work and reduce risk, not just whether controls exist or meet compliance requirements.
  • ISO 27001 and NIST frameworks can be mapped to shared controls and evidence to reduce parallel compliance work.
  • AI systems with greater autonomy and access warrant stronger monitoring and intervention; inventories should include data, identities, permissions, dependencies, and affected business processes.
  • Standardize processes before automating them, and document control exceptions with compensating measures, an owner, and a review or end date.
  • Continuous control monitoring can detect configuration changes, security-setting drift, expired evidence, or ineffective controls so risk assessments can be updated between audits.

Article Details

Topic
Building an AI-aware risk management program on an ISO 27001 foundation