A. General Information Security Standards
| Standard | Purpose | When to Use | Priority |
|---|---|---|---|
| ISO/IEC 27001:2022 | ISMS requirements | Baseline information security management framework | Critical |
| ISO/IEC 27002:2022 | Control guidance | Practical controls for policy, access, suppliers, logging, incidents | Very high |
| ISO/IEC 27005 | Risk management | Identification, assessment, and treatment of information security risk | Very high |
| ISO/IEC 27035-1 / -3 | Incident management | Classification, escalation, response, and lessons learned | High |
| ISO/IEC 27017 | Cloud security | Additional controls for cloud providers and cloud customers | High |
| ISO/IEC 27018 | Protection of PII in public cloud | Privacy controls for public cloud processors | High |
| ISO/IEC 27701 | Privacy information management | PIMS extension, accountability, and GDPR linkage | High |
B. AI-Specific Standards
| Standard | Purpose | When to Use | Priority |
|---|---|---|---|
| ISO/IEC 42001:2023 | AI management system (AIMS) | Use for AI governance system, policies, responsibilities, and control processes | Critical |
| ISO/IEC 23894:2023 | AI risk management | Use for identifying, assessing, and integrating AI risks into organisational processes | Critical |
| ISO/IEC 38507:2022 | Governance guidance for governing bodies | Use for board / executive AI governance | Very high |
| ISO/IEC 42005:2025 | AI impact assessment | Use for assessing impact on individuals, groups, and society | Very high |
| ISO/IEC 22989:2022 | Terminology | Use for consistent AI language and boundary definition | Medium |
| ISO/IEC 23053:2022 | ML framework | Use for architectural and process understanding of ML-based AI systems | Medium |
| ISO/IEC TR 24027 / 24028 / 24029 | Bias, trustworthiness, robustness | Use as supplementary guidance for model trustworthiness and testing | High |
Standardisation Note
The package of harmonised European standards linked to the AI Act is still being developed. For that reason, this standard should not be tied exclusively to future harmonised standards.
Until the harmonised standards are finalised, the practical internal baseline should rely on:
- ISO/IEC 42001,
- ISO/IEC 23894,
- ISO/IEC 38507,
- ISO/IEC 42005,
- and the ISO/IEC 27001 family.