Where AI can help with ISO 27001 preparation
AI can help draft policies and organise evidence. People still need to make risk decisions, implement controls and verify that the records describe reality.
The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.
AI can reduce some of the writing and sorting involved in ISO 27001 preparation. It can turn interview notes into a draft procedure, organise existing documents and help identify missing information.
That is useful when the bottleneck is administration. It does not solve a missing backup, an unreviewed privileged account or a supplier contract nobody has assessed.
Start with facts about the business
A useful policy draft needs inputs: which systems the company uses, who approves access, where data is stored and how exceptions are handled. Without those facts, an AI tool fills the page with a plausible organisation that may not resemble yours.
Give each draft an accountable reviewer. They should verify the procedure against the actual workflow and identify anything the business cannot yet do. Record those gaps as work to complete, rather than approving the document and hoping practice catches up.
ISO/IEC 27001 concerns an operating information security management system. A well-written policy is only part of that system.
Automate collection carefully
A governance, risk and compliance tool can collect records from connected systems and remind owners about recurring reviews. This can make evidence easier to find.
An integration does not prove every control works. Check whether it covers all relevant accounts, whether collection succeeded and whether someone reviewed the result. A completed access-review task needs a record of the decision, not just a list exported from the directory.
Keep sensitive information within approved tools. Risk registers, incident records and account inventories may expose details the business would not publish.
Keep decisions with their owners
AI can suggest risk descriptions and treatment options. The organisation must decide which risks to accept, fund the controls and approve its policies. An internal audit also needs objective judgement about whether the system meets its requirements.
Those responsibilities set limits on how much a schedule can be compressed. A readiness timeline should reflect implementation and evidence needs as well as writing time.
Secured by FM CyberSecurity combines security operations and compliance preparation. The value of AI in that work should be judged by the quality and traceability of the records it helps produce, and by whether people can maintain the process afterwards.