Skip to main content

How to Integrate AI Risk into Your Existing ISMS and Risk Register

AI introduces new risks your ISMS was never designed to handle. Here’s the clear, practical method to integrate AI risk into your existing ISO 27001 risk register ; without reinventing your entire governance model.

Christophe MazzolaChristophe Mazzola· Practicing CISO · Founder of Cyber Academy5 min read
How to Integrate AI Risk into Your Existing ISMS and Risk Register

AI didn’t break your ISMS ; it simply exposed its blind spots.

Most organisations try to manage AI risk using the same templates and thinking they use for IT systems. It doesn’t work. AI brings new failure modes, new dependencies, new governance expectations, and new forms of harm.

The solution isn’t to replace your ISMS. It’s to upgrade it ; by integrating AI risk into your existing structure.

Here’s how to do it properly.

Your ISMS already knows how to deal with risk. It just needs new inputs.

AI risk fits naturally into ISO 27001, ISO 27005, and ISO 31000 ; as long as you:

  • define AI assets
  • understand AI failure modes
  • expand your risk criteria
  • add AI-specific controls
  • update your evidence and monitoring
  • link AI risks to traditional information security

You don’t need a parallel AI risk system. You need to plug AI into the one you already have.

Let’s break down the method step by step.

1. Start by Identifying AI Assets (This Is the Missing Step)

AI risk begins with visibility. Most companies don’t know where AI sits in their architecture.

List four AI asset categories:

  1. AI Models LLMs, classifiers, recommendation engines, scoring models.
  2. AI Pipelines & Data Flows Training data, inference data, preprocessing steps.
  3. AI Integrated Systems Chatbots, decision-support tools, HR/finance/customer-facing AI features.
  4. Third-Party / GPAI Services Azure OpenAI, Claude, Gemini, API-based models, embedded AI in SaaS.

You cannot assess AI risk until you know:

  • what AI you use
  • where it sits
  • how it affects processes
  • what data it touches
  • what decisions it influences

Inventory before analysis ; always.

2. Classify Each AI Asset Using AI-Specific Dimensions

Traditional asset classification (confidentiality, integrity, availability) is not enough.

AI introduces new dimensions:

  • autonomy (how independent the model is)
  • impact on decisions (advisory vs. critical)
  • data sensitivity (training + inference)
  • model criticality (business impact if wrong)
  • model drift potential
  • explainability needs
  • bias exposure
  • regulatory category (AI Act: minimal / limited / high-risk)

These classifications allow you to prioritise risks later.

A chatbot used internally = low criticality. A fraud detection model in banking = high-risk. An HR screening model = regulated. A customer-facing LLM = medium-to-high impact.

Your ISMS needs these categories to adjust risk criteria intelligently.

3. Enrich Your Risk Criteria with AI Failure Modes

This is where most risk registers fail. AI risks don’t look like traditional risks.

Add these AI-specific failure modes to your criteria:

Data-Related Risks

  • training data poisoning
  • leakage through prompts
  • unintentional memorisation
  • exposure of sensitive data in outputs
  • incorrect data labeling

Model-Related Risks

  • hallucinations
  • bias & discrimination
  • model drift
  • loss of explainability
  • miscalibration
  • adversarial attacks
  • over-reliance / automation bias

Operational Risks

  • incorrect outputs in critical processes
  • unsupervised changes in model behaviour
  • cloud AI service outages
  • vendor lock-in
  • hidden subprocessors

Governance Risks

  • lack of human oversight
  • undocumented model decisions
  • unverified datasets
  • lack of version control
  • misuse of models by employees
  • regulatory non-compliance (EU AI Act)

These become part of your risk dictionary.

Once you define them, AI risk becomes manageable ; just like cyber risk or privacy risk.

4. Add AI Scenarios to Your Existing ISO 27005 Risk Method

AI risks fit perfectly into classical scenario-based risk assessment.

Example structure:

Threat: Model hallucination in customer supportVulnerability: No human review mechanismImpact: Wrong advice → customer harm → liabilityLikelihood: Medium (based on use case)Control: Human oversight workflowResidual risk: Low

Another scenario:

Threat: Model drift changes fraud detection accuracyVulnerability: No monitoring of performance over timeImpact: Financial lossControl: Drift monitoring + retraining triggers

AI does not require a new method ; just new scenarios, new threats, new controls.

5. Integrate AI Risk Into the Risk Register Using Existing Columns

Your risk register doesn’t need new fields ; but it needs extended logic.

Use the same structure:

  • asset
  • threat
  • vulnerability
  • likelihood
  • impact
  • controls
  • risk owner
  • residual risk
  • treatment plan

Just add AI-specific elements into the analysis.

Examples you can plug in directly:

Risk: “LLM returns wrong legal advice.” Risk: “AI screening model discriminates against protected groups.” Risk: “GPAI provider changes terms or model behaviour without notice.” Risk: “AI-generated code introduces security vulnerabilities.” Risk: “Dataset bias damages fairness and trust.” Risk: “Uncontrolled prompts lead to data leakage.”

They follow the same architecture ; just new content.

AI risks map naturally to existing controls:

  • Access control → prevents prompt/data leakage
  • Change management → covers model updates
  • Logging and monitoring → covers model behaviour
  • Secure development → applies to training pipelines
  • Supplier management → covers GPAI dependency
  • Business continuity → covers AI service outages

This is why ISO 27001 doesn’t need rewriting for AI ; its controls already support the foundations.

You simply add AI-specific interpretations.

Example: Control 8.28 (Secure Coding) → now includes AI-generated code review. Control 5.7 (Threat Intelligence) → now includes AI threat intelligence. Control 8.16 (Monitoring) → now includes monitoring for model drift.

You extend the control environment ; not rebuild it.

7. Add AI Governance Measures from ISO 42001 (Optional but Smart)

ISO 42001 is the AI governance twin of ISO 27001. You don’t need full certification ; but you should borrow its logic.

Add these governance elements:

  • human oversight rules
  • dataset governance
  • lifecycle documentation
  • explainability expectations
  • roles for AI owners
  • model versioning
  • incident reporting for AI failures

These integrate smoothly into your ISMS and risk management model.

8. Update Your Risk Treatment Plans with AI Controls

Typical treatments include:

  • adding human-in-the-loop checkpoints
  • implementing dataset quality checks
  • restricting prompts
  • adding access controls for AI systems
  • introducing explanation mechanisms
  • limiting autonomy for critical processes
  • drift monitoring
  • technical anti-hallucination techniques
  • testing against bias
  • improving the training dataset
  • documenting model lineage

These are the AI equivalents of patching, segmentation, or logging in cybersecurity.

9. Build AI Risk Monitoring Into Your ISMS Processes

AI risk must be monitored continuously because AI systems change over time.

Add monitoring tasks into:

  • risk reviews
  • change management
  • internal audits
  • incident management
  • supplier reviews
  • training programs
  • continuous improvement loops

Your ISMS already has these processes ; AI risk simply becomes part of them.

10. Make AI Risk Visible to Executives

Executives must understand:

  • AI risks
  • impact on operations
  • governance requirements
  • regulatory exposure (EU AI Act)
  • dependencies on GPAI vendors

Add AI as a section in:

  • Board risk reports
  • quarterly ISMS reviews
  • management reviews

The message for executives is simple:AI increases both opportunity and exposure ; and the organisation must govern it.

Final Thought

AI risk is not a new discipline. It is an extension of existing risk management.

Once you define AI assets, add new threat types, and integrate AI controls, your ISMS becomes future-proof ; ready for AI Act obligations, market expectations, and internal governance.

AI doesn’t require tearing your ISMS apart. It requires teaching your ISMS a new muscle.

This is the evolution of modern governance.

If you want to integrate AI risk into ISO 27001, ISO 27005, and your existing risk register (without complexity) that’s exactly what we teach in the Cyber Academy AI Risk Manager and ISO42001 Lead Auditor and Lead Implementer. Join the next session and future-proof your governance.

Want the next field note in your inbox?

The GRC Brief newsletter. Five links and one short take, every Monday at 8am CET. Three-minute read.