Terug naar de blog
Platform

Your ISO 27001 controls were right when you wrote them. Are they right now?

Whether they still match what the standard requires today is a different question, and most systems never check. That check only works if the AI doing it has actually read the standard, not a summary of it. Most compliance AI hasn't: it's reasoning over blog posts and training data, not the licensed text itself.

24.08.26
8'
Maurice Müller

Maurice Müller

Senior Content Manager

Maurice Müller is a journalist and content strategist with experience across print and digital media. At Formalize, he translates complex compliance and regulatory topics into clear, practical content for compliance, risk, and security professionals across Europe.

Key takeaways:

  • There's a real difference between AI trained about a standard and AI grounded in it.

  • Formalize embeds the official ISO/IEC 27001:2022 text directly in the platform, through a collaboration with UNE, Spain's national standards body.

  • That grounding lets Formalize IQ link a control to the exact clause it satisfies, and flag it when the two drift apart.

  • Coverage today is ISO 27001:2022 and ISO 22301:2019, each through its own Compliance Blueprint, stated plainly rather than stretched.

What's the difference between AI trained about a standard and AI grounded in it?

Most AI in this category has learned about ISO 27001 the way it's learned about everything else. Secondary sources. Summaries. Forum posts. Someone else's interpretation of the clause, several steps removed from the clause itself. That's a workable starting point for a general question. It's a meaningfully weaker one for a compliance answer that has to hold up later, in front of someone whose job is to check it.

Reasoning over the actual, current, licensed text of the standard is a different exercise entirely. It means the answer traces back to the clause itself. It doesn't trace back to whatever a training set happened to absorb about that clause secondhand.

What does "grounded in the standard" actually mean at Formalize?

Formalize embeds the official ISO/IEC 27001:2022 standard directly into the platform. That's the result of a collaboration with UNE, Spain's national standards body, licence signed 15 April 2026. Formalize IQ's underlying logic is part of an official AI pilot sanctioned by ISO and UNE. As the approved framing puts it: while competitors offer generic AI, Formalize's logic is being co-developed with the creators of the standards.

Two things are worth stating precisely here, rather than folding into one broad claim. Formalize is the first GRC provider in Spain, and a pioneer in the European Union, to secure a direct strategic collaboration with ISO/IEC representatives. Separately, Formalize is the only platform running an official AI development project in collaboration with UNE. Both are specific, checkable claims. Neither one stretches into "the only ones in Europe." That's a different, broader statement, and this piece isn't making it.

A note on the language here, since precision matters more in this section than almost anywhere else on the site. This is a collaboration, not a partnership. Formalize's data and IP handling was assessed by ISO/IEC representatives, which is a narrower claim than being ISO-certified, and a deliberately different one. Both distinctions are legal, not stylistic. Both apply specifically to ISO standards, not to every framework Formalize supports.

What does this unlock in practice?

The most concrete version of this is a hyperlink that actually means something. Link a policy or a control directly to the relevant clause of the standard. Formalize IQ flags it the moment that policy drifts from what the clause currently expects, not just once at setup and never again.

A static hyperlink can point at a clause. It can't tell you when the clause and the policy stop agreeing with each other. It keeps no record of when anyone last checked, either. A linked and monitored version does both jobs at once: a drift flag when something moves, and a timestamp showing exactly when it was last verified. That second part matters more than it sounds like it should. It's the difference between a nicer link and something an auditor can actually rely on, months later, without anyone remembering the original conversation.

Picture a specific case. A policy links to the access-control clause of ISO/IEC 27001:2022 when it's written. Eighteen months later, the underlying process has quietly changed, the way most processes do over time, but nobody updated the policy to match. A static link still points at the same clause and still looks fine on a dashboard. A monitored one flags the gap the moment the two stop lining up, instead of waiting for an auditor to find it first.

Which standards does this ISO 27001 AI tool actually cover today?

Confirmed today: ISO 27001:2022 and ISO 22301:2019. That's a separate addition to your account, not something every plan includes by default. That’s the honest scope, and it's worth stating as a deliberate choice rather than an apology. Some vendors already claim grounding across a broader set of ISO standards, including ISO 42001, without the same depth of verification behind the claim. Formalize's answer is narrower on purpose. It's tied to a specific, checkable collaboration, not a general assertion about "AI plus ISO."

If your compliance work runs on DORA, NIS2, or another framework instead, Formalize IQ still grounds its answers in your own attributed record. That's a genuinely different mechanism, not a smaller version of this one. It's covered separately for teams outside ISO 27001.

Ready to see it against your own ISO 27001 program?

Book a demo of Formalize and bring your own ISO 27001 program to it. We'd rather show you against your own controls than talk about it in the abstract.

Frequently asked questions

Boek een demo