AI didn’t break your ISMS ; it simply exposed its blind spots.
Most organisations try to manage AI risk using the same templates and thinking they use for IT systems. It doesn’t work. AI brings new failure modes, new dependencies, new governance expectations, and new forms of harm.
The solution isn’t to replace your ISMS. It’s to upgrade it ; by integrating AI risk into your existing structure.
Here’s how to do it properly.
Your ISMS already knows how to deal with risk. It just needs new inputs.
AI risk fits naturally into ISO 27001, ISO 27005, and ISO 31000 ; as long as you:
- define AI assets
- understand AI failure modes
- expand your risk criteria
- add AI-specific controls
- update your evidence and monitoring
- link AI risks to traditional information security
You don’t need a parallel AI risk system. You need to plug AI into the one you already have.
Let’s break down the method step by step.
1. Start by Identifying AI Assets (This Is the Missing Step)
AI risk begins with visibility. Most companies don’t know where AI sits in their architecture.
List four AI asset categories:
- AI Models LLMs, classifiers, recommendation engines, scoring models.
- AI Pipelines & Data Flows Training data, inference data, preprocessing steps.
- AI Integrated Systems Chatbots, decision-support tools, HR/finance/customer-facing AI features.
- Third-Party / GPAI Services Azure OpenAI, Claude, Gemini, API-based models, embedded AI in SaaS.
You cannot assess AI risk until you know:
- what AI you use
- where it sits
- how it affects processes
- what data it touches
- what decisions it influences
Inventory before analysis ; always.
2. Classify Each AI Asset Using AI-Specific Dimensions
Traditional asset classification (confidentiality, integrity, availability) is not enough.
AI introduces new dimensions:
- autonomy (how independent the model is)
- impact on decisions (advisory vs. critical)
- data sensitivity (training + inference)
- model criticality (business impact if wrong)
- model drift potential
- explainability needs
- bias exposure
- regulatory category (AI Act: minimal / limited / high-risk)
These classifications allow you to prioritise risks later.
A chatbot used internally = low criticality. A fraud detection model in banking = high-risk. An HR screening model = regulated. A customer-facing LLM = medium-to-high impact.
Your ISMS needs these categories to adjust risk criteria intelligently.
3. Enrich Your Risk Criteria with AI Failure Modes
This is where most risk registers fail. AI risks don’t look like traditional risks.
Add these AI-specific failure modes to your criteria:
Data-Related Risks
- training data poisoning
- leakage through prompts
- unintentional memorisation
- exposure of sensitive data in outputs
- incorrect data labeling
Model-Related Risks
- hallucinations
- bias & discrimination
- model drift
- loss of explainability
- miscalibration
- adversarial attacks
- over-reliance / automation bias
Operational Risks
- incorrect outputs in critical processes
- unsupervised changes in model behaviour
- cloud AI service outages
- vendor lock-in
- hidden subprocessors
Governance Risks
- lack of human oversight
- undocumented model decisions
- unverified datasets
- lack of version control
- misuse of models by employees
- regulatory non-compliance (EU AI Act)
These become part of your risk dictionary.
Once you define them, AI risk becomes manageable ; just like cyber risk or privacy risk.
4. Add AI Scenarios to Your Existing ISO 27005 Risk Method
AI risks fit perfectly into classical scenario-based risk assessment.
Example structure:
Threat: Model hallucination in customer supportVulnerability: No human review mechanismImpact: Wrong advice → customer harm → liabilityLikelihood: Medium (based on use case)Control: Human oversight workflowResidual risk: Low
Another scenario:
Threat: Model drift changes fraud detection accuracyVulnerability: No monitoring of performance over timeImpact: Financial lossControl: Drift monitoring + retraining triggers
AI does not require a new method ; just new scenarios, new threats, new controls.
5. Integrate AI Risk Into the Risk Register Using Existing Columns
Your risk register doesn’t need new fields ; but it needs extended logic.
Use the same structure:
- asset
- threat
- vulnerability
- likelihood
- impact
- controls
- risk owner
- residual risk
- treatment plan
Just add AI-specific elements into the analysis.
Examples you can plug in directly:
Risk: “LLM returns wrong legal advice.” Risk: “AI screening model discriminates against protected groups.” Risk: “GPAI provider changes terms or model behaviour without notice.” Risk: “AI-generated code introduces security vulnerabilities.” Risk: “Dataset bias damages fairness and trust.” Risk: “Uncontrolled prompts lead to data leakage.”
They follow the same architecture ; just new content.
6. Link AI Risks to Existing ISO 27001 / 27002 Controls
AI risks map naturally to existing controls:
- Access control → prevents prompt/data leakage
- Change management → covers model updates
- Logging and monitoring → covers model behaviour
- Secure development → applies to training pipelines
- Supplier management → covers GPAI dependency
- Business continuity → covers AI service outages
This is why ISO 27001 doesn’t need rewriting for AI ; its controls already support the foundations.
You simply add AI-specific interpretations.
Example: Control 8.28 (Secure Coding) → now includes AI-generated code review. Control 5.7 (Threat Intelligence) → now includes AI threat intelligence. Control 8.16 (Monitoring) → now includes monitoring for model drift.
You extend the control environment ; not rebuild it.
7. Add AI Governance Measures from ISO 42001 (Optional but Smart)
ISO 42001 is the AI governance twin of ISO 27001. You don’t need full certification ; but you should borrow its logic.
Add these governance elements:
- human oversight rules
- dataset governance
- lifecycle documentation
- explainability expectations
- roles for AI owners
- model versioning
- incident reporting for AI failures
These integrate smoothly into your ISMS and risk management model.
8. Update Your Risk Treatment Plans with AI Controls
Typical treatments include:
- adding human-in-the-loop checkpoints
- implementing dataset quality checks
- restricting prompts
- adding access controls for AI systems
- introducing explanation mechanisms
- limiting autonomy for critical processes
- drift monitoring
- technical anti-hallucination techniques
- testing against bias
- improving the training dataset
- documenting model lineage
These are the AI equivalents of patching, segmentation, or logging in cybersecurity.
9. Build AI Risk Monitoring Into Your ISMS Processes
AI risk must be monitored continuously because AI systems change over time.
Add monitoring tasks into:
- risk reviews
- change management
- internal audits
- incident management
- supplier reviews
- training programs
- continuous improvement loops
Your ISMS already has these processes ; AI risk simply becomes part of them.
10. Make AI Risk Visible to Executives
Executives must understand:
- AI risks
- impact on operations
- governance requirements
- regulatory exposure (EU AI Act)
- dependencies on GPAI vendors
Add AI as a section in:
- Board risk reports
- quarterly ISMS reviews
- management reviews
The message for executives is simple:AI increases both opportunity and exposure ; and the organisation must govern it.
Final Thought
AI risk is not a new discipline. It is an extension of existing risk management.
Once you define AI assets, add new threat types, and integrate AI controls, your ISMS becomes future-proof ; ready for AI Act obligations, market expectations, and internal governance.
AI doesn’t require tearing your ISMS apart. It requires teaching your ISMS a new muscle.
This is the evolution of modern governance.
If you want to integrate AI risk into ISO 27001, ISO 27005, and your existing risk register (without complexity) that’s exactly what we teach in the Cyber Academy AI Risk Manager and ISO42001 Lead Auditor and Lead Implementer. Join the next session and future-proof your governance.
