Where it applies, and to whom.
Any organisation wanting to protect information assets; broadly applicable across sectors.
How Prefactor maps to ISO 27001.
ISO/IEC 27001 Information Security Management, issued by International Organization for Standardization, applies to organizations seeking formal isms certification. This page covers what affects AI agent teams specifically and how to map controls to it.
Source: official ISO 27001 reference. This page is practical guidance — confirm interpretation with your counsel.
What it requiresManage and least-privilege access rights
How Prefactor addresses itPer-agent scoped identity with least privilege, enforced at runtime.
What it requiresLog events and monitor for anomalies
How Prefactor addresses itImmutable trace logs of agent activity with drift and anomaly detection and alerting.
What it requiresClassify data and prevent leakage
How Prefactor addresses itPII and sensitive-data detection and classification in trace data, with redaction or blocking.
What it requiresControl changes to systems
How Prefactor addresses itVersioned agents with eval history; regression gates catch quality changes before they ship.
What it requiresManage threats and technical vulnerabilities
How Prefactor addresses itGuardrails defend against prompt injection and out-of-policy actions, backed by anomaly detection.
What it requiresDetect, report and respond to incidents
How Prefactor addresses itAlerting plus flagged sessions linked to full traces for fast investigation.
The detail, in full.
Frequently asked questions
Does using a 'compliant' provider make us compliant?
Can Prefactor make us compliant?
Key provisions for AI agents
- Annex A controls (93 controls in 2022 revision)
- Risk-based approach to ISMS
- Continuous improvement requirement
- Documented information across lifecycle
Who is affected
Organizations seeking formal ISMS certification
Evidence collection
Auditors and reviewers typically expect:
- Continuous, dated evidence — not point-in-time snapshots
- Override and intervention records — proof humans actually retained control
- Eval results tied to specific agent versions
- Risk decisions tied to changes
- Incident records, even minor ones
- Plain-language documentation
Common gaps in ISO 27001 for AI agents
1. Logs not tamper-evident — application database isn't audit evidence.
2. Human oversight is theoretical — system allows override but nobody uses it.
3. Post-market monitoring is reactive — only investigated when something breaks.
4. No change management — prompts edited in production with no record.
5. Retrieval corpus not in scope of data governance — only training data is considered.
Implementation timeline
30 days: Inventory agents in scope. Begin technical documentation. Enable comprehensive tamper-evident logging.
90 days: Operate risk management. Stand up human oversight. Establish post-market monitoring cadence. First self-assessment.
180 days: Complete documentation. Pre-conformity review. Incident reporting workflow. Full readiness.