A. General Information Security Standards

StandardPurposeWhen to UsePriority
ISO/IEC 27001:2022 ISMS requirements Baseline information security management framework Critical
ISO/IEC 27002:2022 Control guidance Practical controls for policy, access, suppliers, logging, incidents Very high
ISO/IEC 27005 Risk management Identification, assessment, and treatment of information security risk Very high
ISO/IEC 27035-1 / -3 Incident management Classification, escalation, response, and lessons learned High
ISO/IEC 27017 Cloud security Additional controls for cloud providers and cloud customers High
ISO/IEC 27018 Protection of PII in public cloud Privacy controls for public cloud processors High
ISO/IEC 27701 Privacy information management PIMS extension, accountability, and GDPR linkage High

B. AI-Specific Standards

StandardPurposeWhen to UsePriority
ISO/IEC 42001:2023 AI management system (AIMS) Use for AI governance system, policies, responsibilities, and control processes Critical
ISO/IEC 23894:2023 AI risk management Use for identifying, assessing, and integrating AI risks into organisational processes Critical
ISO/IEC 38507:2022 Governance guidance for governing bodies Use for board / executive AI governance Very high
ISO/IEC 42005:2025 AI impact assessment Use for assessing impact on individuals, groups, and society Very high
ISO/IEC 22989:2022 Terminology Use for consistent AI language and boundary definition Medium
ISO/IEC 23053:2022 ML framework Use for architectural and process understanding of ML-based AI systems Medium
ISO/IEC TR 24027 / 24028 / 24029 Bias, trustworthiness, robustness Use as supplementary guidance for model trustworthiness and testing High

Standardisation Note

The package of harmonised European standards linked to the AI Act is still being developed. For that reason, this standard should not be tied exclusively to future harmonised standards.

Until the harmonised standards are finalised, the practical internal baseline should rely on:

  • ISO/IEC 42001,
  • ISO/IEC 23894,
  • ISO/IEC 38507,
  • ISO/IEC 42005,
  • and the ISO/IEC 27001 family.