{
  "schema": "yarn-pack/2",
  "id": "framework-iso27k",
  "version": "0.1.0",
  "name": "ISO 27001, 27701 and 31700 (framework self-assessment)",
  "engagement": "AISG — framework self-assessment: workshop prep, workshop, or diagnostic strand",
  "intro": "A guided conversation against ISO 27001, 27701 and 31700, not a form. Answer in your own words and name the document or record that shows it if you can. About 18 minutes. Assesses how an organisation extends the security and privacy management systems it already holds (27001, 27701, 31700) to cover AI. It does not assess bias, explainability or the AI-specific controls of 42001 itself.",
  "tone_default": "professional",
  "prefill_fields": {
    "department": [
      "Executive",
      "Finance",
      "Operations",
      "Customer / Sales",
      "Technology / IT",
      "Data & Analytics",
      "People & Culture",
      "Risk & Compliance",
      "Marketing",
      "Product"
    ]
  },
  "scales": [
    {
      "id": "maturity5",
      "name": "Maturity (distilled model)",
      "levels": [
        {
          "value": 1,
          "label": "Does not exist",
          "gloss": "No capability. Absent, or purely ad hoc / accidental."
        },
        {
          "value": 2,
          "label": "Partially exists",
          "gloss": "Emerging and inconsistent. Pockets of activity, not joined up."
        },
        {
          "value": 3,
          "label": "Fully exists",
          "gloss": "Defined, documented and operating across the organisation."
        },
        {
          "value": 4,
          "label": "Fully exists & optimised",
          "gloss": "Measured, refined and improving against targets."
        },
        {
          "value": 5,
          "label": "Fully exists & adaptive",
          "gloss": "Continuously self-adjusting; a source of advantage."
        }
      ],
      "signals": {
        "1": [
          "no ",
          "not ",
          "none",
          "never",
          "don't",
          "do not",
          "nothing",
          "absent",
          "unaware",
          "haven't",
          "ad hoc",
          "ad-hoc",
          "nonexistent",
          "no idea",
          "not really"
        ],
        "2": [
          "some ",
          "starting",
          "beginning",
          "emerging",
          "pilot",
          "trial",
          "informal",
          "inconsistent",
          "pockets",
          "a bit",
          "occasionally",
          "early",
          "experiment",
          "trying",
          "patchy"
        ],
        "3": [
          "documented",
          "defined",
          "standard",
          "standardised",
          "established",
          "policy",
          "framework",
          "process",
          "consistent",
          "across the",
          "in place",
          "formal",
          "governed",
          "rolled out"
        ],
        "4": [
          "measured",
          "metrics",
          "optimis",
          "improving",
          "kpi",
          "monitored",
          "reviewed",
          "refined",
          "benchmarked",
          "targets",
          "tracked",
          "mature",
          "regularly review"
        ],
        "5": [
          "continuous",
          "adaptive",
          "self-",
          "automated end",
          "best in class",
          "best-in-class",
          "competitive advantage",
          "industry leading",
          "always",
          "real-time monitoring",
          "feedback loop"
        ]
      }
    }
  ],
  "categories": [
    {
      "id": "isms",
      "name": "The ISMS and its AI extension",
      "order": 1,
      "target_default": 3
    },
    {
      "id": "pims",
      "name": "The PIMS and privacy for AI",
      "order": 2,
      "target_default": 3
    },
    {
      "id": "pbd",
      "name": "Privacy by design for AI systems",
      "order": 3,
      "target_default": 3
    }
  ],
  "audiences": [
    {
      "id": "lead",
      "name": "Governance / risk lead",
      "desc": "Owns the policy, the register or the risk framework",
      "deep_dive_sections": []
    },
    {
      "id": "owner",
      "name": "System or use-case owner",
      "desc": "Runs an AI system or use case day to day",
      "deep_dive_sections": []
    },
    {
      "id": "exec",
      "name": "Executive / sponsor",
      "desc": "Accountable for the outcome, not the mechanics",
      "deep_dive_sections": []
    }
  ],
  "sections": [
    {
      "id": "core",
      "title": "27k elements",
      "blurb": "Everyone answers these. The ISMS and PIMS owners (whoever holds the 27001 and 27701 certifications), the privacy lead, and the product or engineering lead who signs off design gates. The AI governance lead sits alongside.",
      "optional": false,
      "questions": [
        {
          "id": "27k-1",
          "type": "scored_text",
          "category": "isms",
          "name": "Existing management systems as the base",
          "text": "What do you already certify, and who holds those certificates? When AI came up, did anyone ask whether it could sit inside what you have, or did it start as a new programme?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No inventory of certified management systems; AI governance is being scoped as a greenfield AIMS with no link to the existing ISMS or PIMS.",
            "3": "A written list of certified systems and their scopes exists; the AI governance scope states it extends the existing IMS, and that decision is endorsed.",
            "5": "Each new obligation (AI, privacy, security) is scoped into the one IMS by default; the inventory updates at every recertification without a separate exercise."
          },
          "help": "Evidence that would show it: Certificates and scope statements for 27001, 27701, 9001 or 14001; AI governance scope document stating the extension decision; Management review minutes endorsing the integrated approach.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "27k-2",
          "type": "scored_text",
          "category": "isms",
          "name": "Clauses 4 to 7 written once, serving all",
          "text": "Show me your context and scope statement. Does it name the people your AI affects and the regulators watching it? When you assess an AI risk, do you use the same method as for a security risk, or a different one?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "Separate context analyses, policies and risk methods per standard, or none for AI; training data, models, pipelines and infrastructure sit outside the ISMS scope.",
            "3": "One stakeholder analysis naming AI stakeholders, data subjects and regulators; one policy set; one risk method expanded for AI; AI assets inside the ISMS scope.",
            "5": "A change in scope, stakeholders or risk in one domain flows through the shared clauses to the others; the policy set and risk method revise together, not in parallel."
          },
          "help": "Evidence that would show it: Context and scope statement covering AI, security and privacy; Integrated policy set under a single leadership structure; Risk methodology showing the security, privacy and AI expansion; ISMS asset inventory listing training data, models and pipelines.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "27k-3",
          "type": "scored_text",
          "category": "isms",
          "name": "Annex A mapped to 42001, one integrated SoA",
          "text": "If I picked one AI system, could you show me which of your existing security controls already cover it, and which ones you had to add? Who keeps that mapping current?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No gap analysis of existing controls against 42001 Annex A; AI controls are drafted from scratch, or nobody can say which existing controls already cover AI.",
            "3": "A gap analysis shows which 27001 controls carry across and which AI-specific controls and the impact-assessment process are added; each standard keeps its own SoA.",
            "5": "The control mapping is kept as a living crosswalk; a change to one control set triggers a review of the others, and the SoAs are updated together."
          },
          "help": "Evidence that would show it: Gap analysis of existing Annex A controls against 42001 Annex A; Statement of Applicability per standard, cross-referenced; AI impact-assessment process added to the operational controls; Supplier, access and incident controls extended to AI systems.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "27k-4",
          "type": "scored_text",
          "category": "isms",
          "name": "Combined audits, reviews and improvement",
          "text": "When was AI last on an internal audit? Did it go to the same management review as security, or somewhere else? Where would an AI nonconformity be written down?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "AI is not on the internal-audit programme or in management review; nonconformities from AI systems have no route into the improvement process.",
            "3": "The audit programme and management review cover AI alongside security and privacy; AI nonconformities are logged and closed through the same process.",
            "5": "Audits are combined across standards; findings in one domain reshape the audit plan for the others; the certification body assesses the integrated system in one visit."
          },
          "help": "Evidence that would show it: Internal-audit programme listing AI scope items; Management review minutes with AI on the agenda; Nonconformity log with AI entries and closure evidence; Combined certification audit report or plan.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "27k-5",
          "type": "scored_text",
          "category": "pims",
          "name": "PIMS status under 27701:2025",
          "text": "Which edition of 27701 are you on? For each thing you process, could you tell me whether you are the controller or the processor, and where that is written down?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No PIMS, or a 2019-edition extension nobody has reviewed since 27701 became standalone in October 2025; controller and processor roles are not written down.",
            "3": "A PIMS with clauses 4 to 10 for privacy is in place, aligned to 27001:2022; controller and processor duties are assigned per processing activity; the edition is current.",
            "5": "PIMS scope and duties are revisited whenever a processing activity, cloud service or jurisdiction changes; the 2025 edition transition is closed and evidenced."
          },
          "help": "Evidence that would show it: 27701 certificate or transition plan naming the 2025 edition; Register of processing activities with controller or processor role per row; PIMS Statement of Applicability aligned to 27001:2022.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "27k-6",
          "type": "scored_text",
          "category": "pims",
          "name": "AI-related processing under the PIMS",
          "text": "Walk me through one AI system that touches personal data. Where is that processing recorded, who signed it off, and what would happen if the model started drawing on a new data source?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "The PIMS does not mention AI; personal data in training sets, prompts or retrieval corpora is not on the processing register, and nobody owns the privacy of it.",
            "3": "AI-related processing is on the processing register with its controls; cloud, biometric and health data uses are identified; the PIMS controls apply to the AI pipeline.",
            "5": "New AI uses enter the processing register at intake by default; PIMS controls are tested against the live pipeline and adjusted as models and data sources change."
          },
          "help": "Evidence that would show it: Processing register entries for AI training, prompting and inference data; Intake form capturing personal data with biometric or health flags; Model documentation stating data sources and privacy controls; Approved tooling list stating residency and retention per tool.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "27k-7",
          "type": "scored_text",
          "category": "pims",
          "name": "Regulatory reach: ADM and the EU AI Act",
          "text": "Which of your systems make or shape decisions about people using their data? What will you tell those people from December 2026, and which of your privacy controls does that rest on?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No link between the PIMS and the ADM transparency obligation or EU AI Act duties; automated decisions affecting individuals are not identified or disclosed.",
            "3": "Automated decisions using personal information are identified; PIMS controls are mapped to the ADM obligation and any EU AI Act data duties; disclosure is in place.",
            "5": "Regulatory changes are tracked against the control map; a new obligation is absorbed by extending the mapped controls rather than opening a new compliance stream."
          },
          "help": "Evidence that would show it: Control map from 27701 AI-processing controls to the ADM obligation; Disclosure mechanism covering automated decision-making; Human oversight decisions per use case, with rationale.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "27k-8",
          "type": "scored_text",
          "category": "pbd",
          "name": "Privacy by design at every design gate",
          "text": "Take me to the last AI project that went live. At which points did someone check privacy, what did they look at, and who signed? What would have happened if they had said no?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "“Privacy by design” is a slogan; no design gate checks for it, no sign-off records exist, and privacy is retrofitted after a model is deployed.",
            "3": "PbD checks are built into the SDLC; each design gate records a privacy check and a named sign-off, and the checks reference the 31700-1 requirements.",
            "5": "Gate checks are updated from incidents, audits and 31700-2 use cases; a failed check stops progression, and the evidence answers a regulator’s “show me” unprompted."
          },
          "help": "Evidence that would show it: SDLC or lifecycle SOP with a privacy check at each gate; Stage-gate records showing the privacy sign-off and signer; Verification log of gate checks performed.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "27k-9",
          "type": "scored_text",
          "category": "pbd",
          "name": "The privacy-for-AI stack joined up",
          "text": "If a designer sets a privacy requirement for a new model, where does it land in your privacy management system, and who checks the AI data controls match? Is that one document or three?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "The three are held by different teams with no cross-reference; a privacy requirement set at design has no matching PIMS control or 42001 A.7 data control.",
            "3": "A crosswalk links 31700 design requirements, 27701 controls and 42001 A.7 data controls for each AI system; one evidence set serves all three.",
            "5": "A change in any layer (a design requirement, a PIMS control, an A.7 data control) propagates to the other two; the crosswalk is reviewed with the SoA."
          },
          "help": "Evidence that would show it: Crosswalk of 31700, 27701 and 42001 A.7 for AI systems; Model documentation citing the design requirement and its controls; Controls library with privacy controls mapped across the three.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        }
      ]
    }
  ],
  "grids": {},
  "outputs": [
    "Level per element and per category, gated",
    "Contested-element view (spread of 2 or more)",
    "Coverage of evidence: confirmed, stated, inferred",
    "Where to start, foundations first",
    "Printable client report"
  ],
  "report_defaults": [
    "rpt-maturity-standard"
  ],
  "playbook": {
    "sequence": [
      "isms",
      "pims",
      "pbd"
    ],
    "sequence_note": "Foundations first: confirm what is certified and extend it. Then bring AI-related processing into the PIMS. Then make privacy by design show at the gates. Extend the IMS; do not build an AIMS.",
    "actions": {
      "isms": {
        "to_3": [
          "Inventory the certified systems and scopes; write the AI scope as an extension of the existing IMS",
          "Run a gap analysis of existing Annex A controls against 42001 Annex A; add only the AI-specific controls",
          "Expand the one risk methodology for security, privacy and AI; update the integrated SoA"
        ],
        "to_5": [
          "Combine internal audits and certification across the standards; keep the control crosswalk living"
        ]
      },
      "pims": {
        "to_3": [
          "Confirm the 27701:2025 edition; assign controller and processor duties per processing activity",
          "Bring AI training, prompting and inference data onto the processing register with its controls"
        ],
        "to_5": [
          "Map the AI-processing controls to the Privacy Act ADM obligation and EU AI Act data duties; track changes"
        ]
      },
      "pbd": {
        "to_3": [
          "Build 31700-1 privacy checks into the SDLC with a named sign-off at each design gate"
        ],
        "to_5": [
          "Cross-reference 31700, 27701 and 42001 A.7 per AI system; let a change in one layer propagate to the others"
        ]
      }
    }
  }
}