ISO/IEC 27001 and AI Coding
Last updated: 2026-07-173 min read
ISO/IEC 27001:2022 governs an ISMS, not a named AI-tool list. For AI coding, the defensible work is to define scope, assess risk, select and implement controls, and retain relevant evidence. A policy, technical check, or evidence report may support that work; none is a certification or audit result.
Contents
Start with the standard's actual boundary
ISO’s current public record identifies ISO/IEC 27001:2022 as the third-edition ISMS requirements standard, published in October 2022, with Amendment 1:2024. ISO also says organizations may implement the standard without seeking certification. Certification is a separate external conformity-assessment route. Checked 17 July 2026; the full licensed standard, the organization’s scope, and the assessor’s criteria remain authoritative.
Therefore this article does not claim that ISO/IEC 27001 or TISAX categorically permits or forbids AI coding. It maps AI-tool risk questions to management-system work. Your ISMS owner selects the applicable controls; your certification body or TISAX audit provider evaluates the agreed scope.
A practical implementation example
For one repository, define which assistants and model endpoints are approved, which data classifications may reach them, how identities and access are managed, which checks are required before merge, who can approve exceptions, and how the decision is reviewed. The 2024 BSI/ANSSI guidance on AI coding assistants is a useful risk input, but it is guidance-not a certification decision or a prescribed ISO control set.
Do not collapse the assurance layers
| What it is | AI-coding example | What it does not prove | |
|---|---|---|---|
| ISMS requirement | ISMS requirementLayer distinction · 2026-07-17Plain-language orientation, not normative terminology. | A requirement the organization addresses in its scoped management systemImplementation exampleThe organization selects controls from its own risk treatment and requirements. | That a particular tool or control is mandatoryClaim boundary · 2026-07-17External assessors and certification bodies make their own scoped determinations. |
| Internal policy | Internal policyLayer distinction · 2026-07-17Plain-language orientation, not normative terminology. | Approved rules for tools, data classes, accounts, and checksImplementation exampleThe organization selects controls from its own risk treatment and requirements. | That the rule is implemented or effectiveClaim boundary · 2026-07-17External assessors and certification bodies make their own scoped determinations. |
| Implemented control | Implemented controlLayer distinction · 2026-07-17Plain-language orientation, not normative terminology. | Managed identity, data-path restriction, review gate, or exception processImplementation exampleThe organization selects controls from its own risk treatment and requirements. | That every risk is treated or every run followed itClaim boundary · 2026-07-17External assessors and certification bodies make their own scoped determinations. |
| Evidence artifact | Evidence artifactLayer distinction · 2026-07-17Plain-language orientation, not normative terminology. | Configuration record, approval, log, test result, or verification reportImplementation exampleThe organization selects controls from its own risk treatment and requirements. | That the ISMS conforms or an audit will passClaim boundary · 2026-07-17External assessors and certification bodies make their own scoped determinations. |
| External audit work | External audit workLayer distinction · 2026-07-17Plain-language orientation, not normative terminology. | Sampling and evaluation against the defined scope and criteriaImplementation exampleThe organization selects controls from its own risk treatment and requirements. | A certification result before the auditor concludesClaim boundary · 2026-07-17External assessors and certification bodies make their own scoped determinations. |
| Certification decision | Certification decisionLayer distinction · 2026-07-17Plain-language orientation, not normative terminology. | A scoped decision by the certification bodyImplementation exampleThe organization selects controls from its own risk treatment and requirements. | Security of every product, change, supplier, or future operationClaim boundary · 2026-07-17External assessors and certification bodies make their own scoped determinations. |
TISAX is a separate assessment path
The ENX Participant Handbook describes TISAX assessment objectives, the applicable VDA ISA requirements, self-assessment, audit-provider work, and resulting labels. A customer’s requested objective, the current ISA version, locations, protection needs, and assessment scope determine what is evaluated. An ISO/IEC 27001 certificate, a TISAX label, and an internal AI-tool policy are related evidence contexts, not interchangeable outcomes.
Where Reality Graph fits
Reality Graph can retain one bounded chain from written task to selected checks and observed results. How that chain is computed into one outcome, and what is written down when part of it is missing, is documented on the product side. That may support a control owner or auditor when it is relevant, authentic, and inside the defined scope. It does not select the organization’s controls, operate the whole ISMS, certify conformity, or replace external assessment. See the broader distinction in audit trails for AI code.
This workflow can record
- The approved task, scope, and selected checks
- Observed command results and changed files for one governed run
- The operator decision and preserved evidence boundary
It cannot establish
- Organization-wide conformity with ISO/IEC 27001:2022
- A TISAX assessment result or label
- Certification, audit success, control effectiveness beyond the evidence, or legal compliance
FAQ
- Does ISO/IEC 27001:2022 allow or prohibit AI coding tools?
- ISO/IEC 27001:2022 defines requirements for an information security management system; the public ISO description does not decide a named AI coding tool. An organization determines scope, assesses risk, selects and implements controls, evaluates effectiveness, and retains evidence. Applicability and conformity remain organization- and assessor-specific.
- Does an AI coding policy prove ISO/IEC 27001 conformity?
- No. A policy states an approved rule. A technical or organizational control implements part of that rule, and an evidence artifact records an observed event. Those are inputs to an ISMS and an audit, not a certification decision by themselves.
- Does a verification report count as audit evidence?
- It can be one evidence artifact if it is authentic, scoped, retained, and relevant to a selected control. The auditor still evaluates the defined ISMS scope, control design, implementation, operation, and other evidence. A report does not certify the organization or the tool.
- Is TISAX the same as ISO/IEC 27001 certification?
- No. ENX describes TISAX as an assessment and exchange mechanism based on the VDA ISA, with assessment objectives defining applicable requirements. ISO/IEC 27001 is an ISMS requirements standard; certification is a separate conformity-assessment route. Check the current TISAX objective, ISA version, scope, and partner request.
- What should an AI-coding control owner document?
- Document the risk and decision first: approved tools and configurations, permitted data classes, identities and access, supplier and model endpoints, required checks, exceptions, owners, retention, and review cadence. Then retain evidence that the selected controls operated. This is an implementation pattern, not a prescribed ISO control set.
Keep reading
Sources
- ISO - ISO/IEC 27001:2022 requirements, status and optional certification route (checked 2026-07-17)
- ISO - management-system certification uses an external certification body (checked 2026-07-17)
- BSI/ANSSI - secure use of AI coding assistants (2024, German; checked 2026-07-17)
- ENX - TISAX Participant Handbook and assessment process (checked 2026-07-17)