ISO 27001, 27701 and 31700 (framework self-assessment) v0.1.0
framework-iso27k · 1 sections
Metadata
Scales, categories & audiences
Scales: maturity5 (5 levels) · Categories: isms pims pbd · Audiences: lead owner exec
Edit these in the raw JSON editor below — they change rarely and carry structure (levels, signals, deep-dive wiring) that a form would mangle.
27k elements core
Everyone answers these. The ISMS and PIMS owners (whoever holds the 27001 and 27701 certifications), the privacy lead, and the product or engineering lead who signs off design gates. The AI governance lead sits alongside.
| Id | Question | Type | Category | Scale | |
|---|---|---|---|---|---|
| 27k-1 | What do you already certify, and who holds those certificates? When AI came up, did anyone ask whether it could sit inside what you have, or did it start as a new programme? | scored_text · scored | isms | maturity5 | |
| 27k-2 | Show me your context and scope statement. Does it name the people your AI affects and the regulators watching it? When you assess an AI risk, do you use the same method as for a security risk, or a different one? | scored_text · scored | isms | maturity5 | |
| 27k-3 | If I picked one AI system, could you show me which of your existing security controls already cover it, and which ones you had to add? Who keeps that mapping current? | scored_text · scored | isms | maturity5 | |
| 27k-4 | When was AI last on an internal audit? Did it go to the same management review as security, or somewhere else? Where would an AI nonconformity be written down? | scored_text · scored | isms | maturity5 | |
| 27k-5 | Which edition of 27701 are you on? For each thing you process, could you tell me whether you are the controller or the processor, and where that is written down? | scored_text · scored | pims | maturity5 | |
| 27k-6 | Walk me through one AI system that touches personal data. Where is that processing recorded, who signed it off, and what would happen if the model started drawing on a new data source? | scored_text · scored | pims | maturity5 | |
| 27k-7 | Which of your systems make or shape decisions about people using their data? What will you tell those people from December 2026, and which of your privacy controls does that rest on? | scored_text · scored | pims | maturity5 | |
| 27k-8 | Take me to the last AI project that went live. At which points did someone check privacy, what did they look at, and who signed? What would have happened if they had said no? | scored_text · scored | pbd | maturity5 | |
| 27k-9 | If a designer sets a privacy requirement for a new model, where does it land in your privacy management system, and who checks the AI data controls match? Is that one document or three? | scored_text · scored | pbd | maturity5 |
+ Add question to “27k elements”
Add section
Advanced — raw JSON
Full pack document, validated on save (schema yarn-pack/2). This is where scales, audiences, structured conditions and adaptive config live.