Compliance decisions
ISO 27001 evidence for employee AI DLP
Start from the control selected within your organisation’s ISMS scope, then document the input path, expected behaviour, actual observation and review decision. An AI security event can support that evidence, but one test does not certify the ISMS or demonstrate every control. Use the applicable standard and Statement of Applicability for formal mapping.
For ISMS managers, security engineers and internal control reviewers
The packet supplies safe inputs and decisions to make, not fabricated test results.
All personal data is invented. Every product observation is not run; the control ID is not an ISO Annex A reference or a certification claim.01
Define the control in the organisation’s own terms
The example control, AI-DLP-EX-01, is organisation-defined: protect specified sensitive inputs before employees submit them on a selected AI path and retain proportionate review evidence. It is not an ISO Annex A control number or an assertion that the organisation has adopted a particular Statement of Applicability.
Use the applicable licensed standard, actual ISMS scope and risk-treatment decision for the formal mapping. The packet below demonstrates a concrete evidence design without inventing normative wording or claiming that a vendor certificate establishes the customer’s implemented control.
Source context: UKAS: Validating management-system certificates
02
Specify the path and meaningful test cases
Record the installed client, operating system, application, input type, configuration and policy version. A browser prompt and a file upload can behave differently; a result on one path does not establish every application or format. Agree the intended sensitive category before interpreting a test.
The safe fixture pair contrasts a general support message with an invented personal record using an example.invalid address. A third fixture puts the same invented information in an appendix. These test the selected scope, not a promise that a particular detector recognises every possible identifier.
Source context: NIST SP 800-53A Rev. 5: Control-assessment overview
03
Keep design evidence separate from test evidence
A policy definition and deployment record describe intended design. An actual test observation shows what happened under specified conditions. The NIST assessment overview supports tailored assessment plans and analysis of results; it is a method reference here, not a substitute for the organisation’s ISO mapping.
Record the actual response, relevant event fields and any difference between the source and exported evidence. Retain only the information needed for the review. Do not turn the safe fixture or an expected block into a statement that an installed Aona control passed.
Source context: NIST SP 800-53A Rev. 5: Control-assessment overview
04
Use explicit review outcomes
The reviewer can accept the evidence for its tested scope, reject it because the expected behaviour was not observed, or leave the conclusion unresolved where coverage or observation is missing. Record the reason and next action. These are distinct outcomes, not a default green status.
The populated packet marks every runtime result as not run. Its authored review decision is therefore “not accepted as operating evidence”. That is an honest, useful starting point: the evaluator has the inputs, the expected comparison and the information needed to complete the test.
Source context: NIST SP 800-53A Rev. 5: Control-assessment overview
05
Tie the evidence to changes and follow-up
Keep the evidence with the relevant control owner and risk-treatment record. A client, policy, application or file-processing change can affect the earlier result. Decide what needs retesting rather than extending an old observation to a changed configuration.
Use actual findings to improve the control or narrow its claimed coverage. The packet is not a certification checklist, an auditor’s conclusion or proof that every employee AI route is protected. The organisation and its assurance process determine how the evidence supports their scoped control.
Source context: NIST SP 800-53A Rev. 5: Control-assessment overview
Put it into practice
Synthetic AI DLP control-test packet
AI-DLP-EX-01 is an organisation-defined teaching control. The packet supplies concrete safe fixtures, planned outcomes and a review record with no invented execution.
All personal data is invented. Every product observation is not run; the control ID is not an ISO Annex A reference or a certification claim.
Control
AI-DLP-EX-01, organisation-defined
Input pair
Generic wording versus invented personal record
Observed
Not run
Review
Not accepted as operating evidence
Complete the actual scoped test.
| Test or evidence | Expected comparison | Observation and review |
|---|---|---|
| Control definition | Protect the agreed sensitive category on the selected installed path. | Design example only; map to the actual ISMS control separately. |
| Fixture A: generic text | The agreed benign input should follow the permitted route. | Not run; no operating-effectiveness conclusion. |
| Fixture B: invented personal record | Apply the agreed protective policy for the selected category. | Not run; verify the actual response and event. |
| Fixture C: appendix content | Evaluate the same category in the selected file/content path. | Not run; do not infer file coverage from the prompt result. |
| Evidence reconciliation | Compare client action, event meaning and exported record. | Not run; record missing fields or mismatched scope. |
| Reviewer disposition | Accept only supported observations, reject a demonstrated failure, or leave missing evidence unresolved. | Current packet: not accepted as operating evidence because tests were not run. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
isms-ai-dlp-evidence-packet.mdInspect
# Synthetic AI DLP control-test packet
All personal data is invented. Every product observation is not run; the control ID is not an ISO Annex A reference or a certification claim.
AI-DLP-EX-01 is an organisation-defined teaching control. The packet supplies concrete safe fixtures, planned outcomes and a review record with no invented execution.
| Test or evidence | Expected comparison | Observation and review |
| --- | --- | --- |
| Control definition | Protect the agreed sensitive category on the selected installed path. | Design example only; map to the actual ISMS control separately. |
| Fixture A: generic text | The agreed benign input should follow the permitted route. | Not run; no operating-effectiveness conclusion. |
| Fixture B: invented personal record | Apply the agreed protective policy for the selected category. | Not run; verify the actual response and event. |
| Fixture C: appendix content | Evaluate the same category in the selected file/content path. | Not run; do not infer file coverage from the prompt result. |
| Evidence reconciliation | Compare client action, event meaning and exported record. | Not run; record missing fields or mismatched scope. |
| Reviewer disposition | Accept only supported observations, reject a demonstrated failure, or leave missing evidence unresolved. | Current packet: not accepted as operating evidence because tests were not run. |
## Review steps
- Record the exact test scope: Name client, OS, application, input type, policy version and intended sensitive category.
- Capture actual behaviour: Keep expected outcomes separate from observed response, event and exported evidence.
- Document a reasoned decision: Accept only the tested scope, or record failure/missing evidence and the required follow-up.
## Control record
ID: AI-DLP-EX-01, organisation-defined teaching identifier.
Risk: unnecessary sensitive employee input reaches an external AI service.
Intended scope: the application, client and input path chosen by the evaluator.
ISO mapping: use the organisation’s applicable standard and Statement of Applicability; no Annex A number is asserted here.
## Planned runtime outcome
Observation: not run.
Reviewer decision: not accepted as operating evidence.
Reason: no installed-client observation accompanies this authored test plan.
Next action: run the authorised synthetic cases and record scope, response and evidence.
This is a populated assessment plan, not a successful product test or certification result.
## Source and scope
Guide: https://aona.ai/resources/guides/iso27001-ai-dlp-evidence/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- NIST SP 800-53A Rev. 5: Control-assessment overview: https://csrc.nist.gov/pubs/sp/800/53/a/r5/final
- UKAS: Validating management-system certificates: https://www.ukas.com/accreditation/about/validating-ms-certificates/
Download isms-ai-dlp-evidence-packet.mdisms-ai-dlp-evidence-packet.csvInspect
Test or evidence,Expected comparison,Observation and review
Control definition,Protect the agreed sensitive category on the selected installed path.,Design example only; map to the actual ISMS control separately.
Fixture A: generic text,The agreed benign input should follow the permitted route.,Not run; no operating-effectiveness conclusion.
Fixture B: invented personal record,Apply the agreed protective policy for the selected category.,Not run; verify the actual response and event.
Fixture C: appendix content,Evaluate the same category in the selected file/content path.,Not run; do not infer file coverage from the prompt result.
Evidence reconciliation,"Compare client action, event meaning and exported record.",Not run; record missing fields or mismatched scope.
Reviewer disposition,"Accept only supported observations, reject a demonstrated failure, or leave missing evidence unresolved.",Current packet: not accepted as operating evidence because tests were not run.
Download isms-ai-dlp-evidence-packet.csvfixture-a-generic.txtInspect
SYNTHETIC TEST A
Please make this generic support message clearer: Contact our team if you need help arranging a meeting. Do not add personal information.
Download fixture-a-generic.txtfixture-b-invented-personal-record.txtInspect
SYNTHETIC TEST B: NO REAL PERSON
Name: Alex Example
Email: alex.example@example.invalid
Employee reference: TEST-EMP-27
Request: Summarise this invented employee support record.
Download fixture-b-invented-personal-record.txtfixture-c-appendix.mdInspect
# Synthetic appendix test
The main text contains a generic support request.
## Appendix: invented personal details
Alex Example, alex.example@example.invalid, TEST-EMP-27.
This is safe authored text, not a claim that a particular file format or detector was tested.
## Source and scope
Guide: https://aona.ai/resources/guides/iso27001-ai-dlp-evidence/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- NIST SP 800-53A Rev. 5: Control-assessment overview: https://csrc.nist.gov/pubs/sp/800/53/a/r5/final
- UKAS: Validating management-system certificates: https://www.ukas.com/accreditation/about/validating-ms-certificates/
Download fixture-c-appendix.mdBefore you proceed
Keep these distinctions clear
- A fixture is not a passed control
- Record actual execution before claiming operating evidence.
- A control ID is not an Annex A mapping
- Use the applicable standard and the organisation’s real Statement of Applicability.
Apply it to employee AI use
Bring your actual data path.
Aona can be evaluated for sensitive-input policies and relevant event evidence on supported installed paths.
Aona does not certify the customer’s ISMS or establish universal application, file or policy coverage from a single test.
Use the safe fixture pack to agree the specific input category and path, then record the actual outcome and limitations.
Review your use caseFAQ
Questions for this decision
Is AI-DLP-EX-01 an ISO control number?
Why are the result fields marked not run?
Can one successful prompt test prove file protection?
Does completing the packet establish ISO certification?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- NIST SP 800-53A Rev. 5: Control-assessment overview
The public overview describes tailored security/privacy control assessment plans and analysis of results. It does not establish an ISO Annex A mapping or an Aona result.
standard · checked 2026-09-21 - UKAS: Validating management-system certificates
Independent checks of certificate authenticity, certification-body accreditation and the relevant verification route.
standard · checked 2026-09-21