AI Governance Institute
← All news

Annex A

Annex A is the foundational section of ISO/IEC 27001 that outlines 14 control objectives and 93 specific information security controls covering areas like asset management, access control, cryptography, and incident management. Organizations pursuing ISO/IEC 27001 certification must implement and demonstrate compliance with these controls as part of their information security management system. For AI governance, Annex A controls are critical because they establish the security baseline necessary to protect AI systems, training data, and model outputs from unauthorized access and compromise.

1 item