EVIDENCE
DATED
REPEATABLE
Compliance / ISO 27001

The auditor asks: "how do you know?"

Your ISMS says AI tool usage is controlled. The auditor's follow-up is always the same question, and "we asked the department heads" is the answer that turns a checkmark into a finding. This page is about producing the other kind of answer.

Produce the evidence free
The two answers

Self-declared register vs observed evidence

Both look like an AI inventory in the ISMS. Under audit questioning they behave very differently.

"We maintain a register"

  • Sourced from asking teams what they use. Complete on the day people answered honestly and remembered everything, which is no day.
  • Silent on embedded AI features nobody thinks of as tools.
  • No timestamps, no method statement, no way to re-derive it.
  • Auditor's next question: "How would this register learn about a tool adopted last month?" There is no good answer.

"We measure quarterly from logs"

  • Sourced from the organization's own DNS, proxy or firewall exports, matched against a register of 20,399 classified AI domains.
  • Each report states its window, line counts and register size: a method statement built in.
  • Repeatable on demand: the same procedure regenerates the evidence for any period.
  • Auditor's next question: "Can I see last quarter's?" You hand over a PDF. The interview moves on.

The distinction auditors care about is not effort, it is evidentiary class: assertion versus observation. Log-derived inventories are observations with dates on them.

Control mapping

Where AI usage evidence lands in an ISMS

Generic-safe mapping: your ISMS scoping decides the exact control references. These are the conversations where the report keeps appearing.

ISMS conversationThe auditor's angleWhat the report supplies
Asset and service inventoryAre cloud services in use identified and owned?The observed AI service list, per period, with per-team attribution.
Supplier relationshipsAre third parties handling data assessed?Dated training verdicts and sovereignty flags per vendor found in use.
Acceptable use and awarenessIs the policy real or decorative?The sanctioned split: policy versus observed behavior, quantified.
Data leakage preventionWhat stops data leaving through unapproved channels?Detection cadence plus blocked-attempt evidence from the filter, verified by re-runs.
Change and continual improvementDoes the ISMS learn?Quarter-over-quarter deltas: tools found, blocked, sanctioned, drifted verdicts.
The interview

Six auditor questions, answered from the report

A composite of how the interview actually goes when the evidence exists. Sample dialogue, real structure.

"How do you identify AI services in use?"

"Quarterly log-based audit: network exports matched against a daily-maintained register of classified AI domains. Here are the last four reports."

"How current is the reference data?"

"The register updates daily, roughly 300,000 domains screened per day, and each report states the register size at run time."

"How do you assess these vendors?"

"Each found tool carries a training verdict with the date the vendor's terms were checked, drawn from an ongoing review of 13,000+ terms documents. High-tier findings feed our supplier process."

"What happens with findings?"

"Triage into sanction, control or block, minuted in this decision table, with the block list verified by the following quarter's run."

"Who sees personal data during this?"

"The audit consumes hostnames, identities and timestamps. Uploads are discarded after each run and reports are deletable; here is the data-handling note."

"Can you demonstrate it now?"

"Yes, the free preview runs in minutes on any export. Would you like to pick the window?"

Auditors reward systems that survive the "show me now" question. This one is designed to be demonstrated live.

Evidence hygiene

Filing the reports so they work as evidence

The document is built for filing; four habits keep the chain tidy.

File unedited

The PDF's scope line and evidence statement are worded to stand alone. Editing or excerpting reintroduces the assertion problem you were solving.

Fix the window

Same 30-day window each quarter, noted in the ISMS procedure. Consistent method is half of what "repeatable" means to an auditor.

Minute the triage

The report shows findings; a one-page decision table shows governance. Together they close the plan-do-check-act loop on paper.

Keep the CSVs

The machine-readable table lets internal audit re-sort and sample without new requests. Auditors notice when checking is easy.

Retention detail for the ISMS note: reports live 90 days in the account and can be deleted earlier; the filed PDFs and CSVs are your permanent record, under your control.

Common findings

Three nonconformity patterns this closes

Generic-safe composites of where AI-related findings actually come from in certification cycles.

The stale register

An AI inventory last touched before the audit announcement. The quarterly cadence with dated PDFs makes staleness structurally impossible to hide and easy to avoid.

The unassessed supplier

A tool in heavy use with no vendor assessment on file. Training verdicts per found tool mean the assessment queue is generated, not remembered.

The decorative policy

An acceptable-use clause about AI with no measurement behind it. The sanctioned split is the measurement, and its trend is the improvement story.

The exact PDF your auditor would receive

Scope line, findings, per-user attribution, control evidence statement: the sample report shows the whole evidentiary shape on sample data.

Open the sample report
Certification calendar

Slotting the audit into the ISO year

Quarterly: the runs

Four reports a year, same window, filed with minutes. Plans with monthly allowances cover organizations that want tighter cadence; see pricing.

Pre-audit: the rehearsal

Before the certification or surveillance visit, re-read the last two reports and the decision tables. The interview script above is your rehearsal sheet.

Post-finding: the correction

If a visit does produce an AI-related finding, the corrective action is often literally "adopt the cadence": measurable, dated, and closable at the next surveillance.

Internal audit can run the whole loop themselves: export, upload, read. No vendor meeting required, which is why this control survives budget seasons.

FAQ

ISO 27001 evidence questions

Does ISO 27001 require AI usage monitoring?

It requires that your ISMS controls match your risks, and unmanaged AI services are a risk most scoping now includes. The evidence question follows automatically.

Is a log-based audit acceptable evidence?

Dated, repeatable, method-stated observations are the strongest class of operational evidence an ISMS produces. That is precisely the report's construction.

How many periods of evidence do we need?

Start now and you have one period now; certification conversations improve with every quarter filed. Four consecutive reports read as a functioning control.

Can internal audit verify the findings?

Yes: re-run the same window and compare, or sample the CSV against raw logs. Repeatability is the design goal.

What about tools the network never sees?

State the scope honestly: the audit covers the logged network. Off-network use is a policy and awareness matter, and auditors respect stated boundaries far more than silent ones.

Does this replace supplier assessments?

No, it queues and prioritizes them. Verdicts identify which vendors need the full assessment first; the assessment itself stays your process.

Have the answer before the question

"How do you know?" deserves a PDF, not a pause. The first one takes an afternoon.

Run the free audit