Skip to content

Blog

What ISO 27001 tells you about an AI vendor

ISO 27001 is a security claim you can verify before signing. What the certificate covers, what it leaves out, and which questions to ask an AI vendor.

Documents and a checklist on a desk.

ISO/IEC 27001 sets out the requirements for an information security management system. A certificate is evidence about one named organisation and about the scope printed on it, and it says nothing about whether a particular AI answer is right or whether a piece of software is well built.

It’s useful, but narrow. If you’re buying a platform that will hold your document estate, the value is in reading the certificate, not in noting that one exists.

What an ISO 27001 certificate does tell you

It tells you an information security management system is in scope, because the standard is about how an organisation establishes, runs, maintains and improves that system. It tells you a certification body has assessed whatever the certificate says it assessed, so check who issued it, whether they are accredited, and whether the issue and expiry dates are current. Ask for the current file rather than accepting an undated logo in a footer.

Mostly it tells you to read the scope statement. Every certificate has one, and it names which parts of the business and which services the certification covers. Anything the scope doesn’t name isn’t covered by it.

What ISO 27001 doesn’t tell you

It doesn’t tell you the product is secure by design. The standard covers how the organisation manages security, and a certified company can still ship software with weak access controls, so you still need the product answers: how data is isolated, who can see what, and what gets logged.

It doesn’t tell you what happens to your data in AI terms either. The standard predates the current wave of AI products and says nothing about whether your documents are used to train models, whether prompts are retained, or whether your documents are kept separate from another customer’s. Ask those questions separately, and get the answers in writing.

It also doesn’t do your hosting and residency diligence for you. Where the data physically lives, which jurisdiction that puts it under, and who the sub-processors are all remain your questions to ask.

The questions to put to any AI vendor claiming ISO 27001

  1. Can you share the certificate and its scope statement, and does the scope cover the service I’m buying?
  2. Is my organisation’s data isolated from other customers’, and how, technically?
  3. Are my documents or prompts used to train shared models, and where is that stated contractually?
  4. What gets logged, and can my administrators see the log?
  5. Where is the data hosted, and what are the residency options if that isn’t acceptable?

A vendor who’ll take those questions in a room with your security team is telling you more than the certificate does.

OpenKit Ltd operates Marella AI, so put the same five questions to us. Then test the product-level controls separately against the deployment architecture you would actually run, starting with the Marella AI security review.

Ibrahim Mizi

Written by Ibrahim Mizi, Co-founder & CEO at Marella AI.

Share this article