ISO/IEC 27001 — 93 controls as themes, one management system
Information security, modelled as one management system with ISO/IEC 42001 where the clauses are the same. The 93 Annex A controls are worked as four guided theme records, not empty rows.
ISO/IEC 27001:2022 is the information-security management system standard: the same clause 4–10 skeleton as ISO/IEC 42001, plus 93 Annex A controls in four themes — organisational (A.5), people (A.6), physical (A.7) and technological (A.8). Voluntary; certifiable by an accredited body under ISO/IEC 17021-1, exactly as ISO/IEC 42001 is.
One management system, not two
Clauses 4–10 of the two standards ask for the same things — context and interested parties, leadership and roles, a risk method, objectives, competence and awareness, documented information, operational control, monitoring, internal audit, management review, corrective action. Veritome models them as one record with two placements: a shared step carries an information-security section beside its AI-management questions, and completing it once counts in both programmes. If ISO/IEC 42001 is already on, those shared steps arrive already done.
The 93 controls
The Annex A controls are worked as four theme records — organisational, people, physical and technological control records — rather than 93 empty rows. Each theme step asks the questions an auditor asks and produces the record; dedicated steps cover ICT continuity and backup, the information-security incident procedure, the ISMS scope and the information-security policy. The programme's risk treatment and Statement of Applicability step is where you compare your chosen controls with Annex A for omissions and document, per control, whether it applies and why — the sentence the standard requires for every exclusion.
What it does not give you
An ISMS certificate is not a presumption of conformity with the EU AI Act, and it does not stand in for Art. 15's accuracy, robustness and cybersecurity requirement on a high-risk system — it evidences the organisation's security management, which is one input to that requirement. Veritome labels it voluntary and never renders a certificate as conformity.
In Veritome
Switch it on under Frameworks: six phases with gates, the shared records, the theme steps, a readiness report and a certification record where an admin enters the body, the certificate reference and the surveillance date. The evidence is generated from the programme; the certificate, as with every standard, comes from an accredited body — never from us.
Price and timing. ISO/IEC 27001 is €199 a month on Govern and already part of Manage and Enterprise — the one programme sold separately, with no bundle. It is not going out with the launch: while the cross-mapping is switched off the programme is absent from the rail, and the pricing page states the date it lands.