YARN Studiopack-driven assessments · Agile Insights · v0.1.0

ISO 27001, 27701 and 31700 (framework self-assessment) v0.1.0

framework-iso27k · 1 sections

⚡ Generate from source material ⬇ Export .yarnpack.json
Advanced: raw JSON

Metadata

Scales, categories & audiences

Scales: maturity5 (5 levels) · Categories: isms pims pbd · Audiences: lead owner exec

Edit these in the raw JSON editor below — they change rarely and carry structure (levels, signals, deep-dive wiring) that a form would mangle.

27k elements core

Everyone answers these. The ISMS and PIMS owners (whoever holds the 27001 and 27701 certifications), the privacy lead, and the product or engineering lead who signs off design gates. The AI governance lead sits alongside.

IdQuestionTypeCategoryScale
27k-1 What do you already certify, and who holds those certificates? When AI came up, did anyone ask whether it could sit inside what you have, or did it start as a new programme? scored_text · scored isms maturity5
27k-2 Show me your context and scope statement. Does it name the people your AI affects and the regulators watching it? When you assess an AI risk, do you use the same method as for a security risk, or a different one? scored_text · scored isms maturity5
27k-3 If I picked one AI system, could you show me which of your existing security controls already cover it, and which ones you had to add? Who keeps that mapping current? scored_text · scored isms maturity5
27k-4 When was AI last on an internal audit? Did it go to the same management review as security, or somewhere else? Where would an AI nonconformity be written down? scored_text · scored isms maturity5
27k-5 Which edition of 27701 are you on? For each thing you process, could you tell me whether you are the controller or the processor, and where that is written down? scored_text · scored pims maturity5
27k-6 Walk me through one AI system that touches personal data. Where is that processing recorded, who signed it off, and what would happen if the model started drawing on a new data source? scored_text · scored pims maturity5
27k-7 Which of your systems make or shape decisions about people using their data? What will you tell those people from December 2026, and which of your privacy controls does that rest on? scored_text · scored pims maturity5
27k-8 Take me to the last AI project that went live. At which points did someone check privacy, what did they look at, and who signed? What would have happened if they had said no? scored_text · scored pbd maturity5
27k-9 If a designer sets a privacy requirement for a new model, where does it land in your privacy management system, and who checks the AI data controls match? Is that one document or three? scored_text · scored pbd maturity5
+ Add question to “27k elements”

Add section

Advanced — raw JSON

Full pack document, validated on save (schema yarn-pack/2). This is where scales, audiences, structured conditions and adaptive config live.