Auditing AI systems with ISO 27001: evidence, controls and continuous improvement

An audit checks how things work, not intentions

Saying a system is secure or responsible is no substitute for evidence. An audit has to verify that scope, risks, controls and responsibilities are documented and actually work in practice.

Auditing AI is not about checking whether the model looks accurate: it is about being able to show which data, controls and decisions sit behind every output.

Prepare a record sheet per system

  • Purpose, owner and users.
  • Data sources, model, connectors and supplier.
  • Risk classification and approved measures.
  • Permissions, logs and retention.
  • Changes, tests, incidents and corrective actions.

Check controls where they happen

Review a sample of access grants, prompt or model changes, evaluation results and incident closures. A policy is necessary, but a dated piece of evidence proves it was applied.

Audit suppliers and the supply chain

Check the contract, data location and processing, sub-processors, continuity, export, change notification and exit plan. Model and automation providers are part of the risk, even when AI is consumed as a service.

Turn findings into improvement

Classify non-conformities, determine root causes and assign an action, an owner and a date. Monitoring AI in production provides signals that help check whether a corrective measure is working.

Conclusion: audit to improve control, not just to comply

A useful AI audit combines technical evidence, security controls and a review of the decision-making processes. The result should help correct risks and sustain trust before the system scales.

If you need to audit AI systems, prepare evidence for ISO 27001 and strengthen control over your models, at Impulsa3 we support you with a practical, data-driven strategy.