Skip to main content

ISO 27001 for AI and software companies

ISO 27001 is the international standard for running an information security management system. European and regulated buyers ask for it by name.

Which edition this covers

ISO/IEC 27001:2022, including Amendment 1:2024 (climate action changes)

Checked against the source on 2026-09-13 · read the source

Not covered

  • ISO/IEC 27001:2013 and its 114-control Annex A. The 2022 edition reorganised those into 93 controls and added eleven; a mapping to one is not a mapping to the other.
  • ISO/IEC 27002, the implementation guidance, which is a separate document.
  • National adoptions that add requirements beyond the ISO text.

What Trooth witnesses

Read on a schedule, republished with the date

  • Annex A control signals that can be read from your live stack
  • Asset and sub-processor disclosure, including model and data dependencies
  • Supplier relationships through your published sub-processor list
  • Change and access signals from the providers you connect

What Trooth does not do

Said plainly, so nobody guesses

  • Issue a certification, attestation, or audit opinion. Only a licensed auditor can do that.
  • Stand in for a certification body, a Stage 1/Stage 2 audit, or your risk treatment plan.
  • Give legal advice or tell you whether you are compliant. That call is yours and your counsel's.

Why this is worth anything to a buyer

A questionnaire answer is a claim typed once and never checked again. ISO 27001 here is the rulebook, not the product: what Trooth publishes for it is read from your live systems on a schedule and republished with the date it was last seen, so a buyer checking your company can tell the difference between what was true a year ago and what is true this morning. That is a smaller promise than an audit, and it is one we can actually keep. The full method is on the methodology page.