30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

ISO 27001 evidence for employee AI DLP

Start from the control selected within your organisation’s ISMS scope, then document the input path, expected behaviour, actual observation and review decision. An AI security event can support that evidence, but one test does not certify the ISMS or demonstrate every control. Use the applicable standard and Statement of Applicability for formal mapping.

For ISMS managers, security engineers and internal control reviewers

Aona field notesC27
Evidence needs an observation
Expected ≠ observed

The packet supplies safe inputs and decisions to make, not fabricated test results.

All personal data is invented. Every product observation is not run; the control ID is not an ISO Annex A reference or a certification claim.

01

Define the control in the organisation’s own terms

The example control, AI-DLP-EX-01, is organisation-defined: protect specified sensitive inputs before employees submit them on a selected AI path and retain proportionate review evidence. It is not an ISO Annex A control number or an assertion that the organisation has adopted a particular Statement of Applicability.

Use the applicable licensed standard, actual ISMS scope and risk-treatment decision for the formal mapping. The packet below demonstrates a concrete evidence design without inventing normative wording or claiming that a vendor certificate establishes the customer’s implemented control.

Source context: UKAS: Validating management-system certificates

02

Specify the path and meaningful test cases

Record the installed client, operating system, application, input type, configuration and policy version. A browser prompt and a file upload can behave differently; a result on one path does not establish every application or format. Agree the intended sensitive category before interpreting a test.

The safe fixture pair contrasts a general support message with an invented personal record using an example.invalid address. A third fixture puts the same invented information in an appendix. These test the selected scope, not a promise that a particular detector recognises every possible identifier.

Source context: NIST SP 800-53A Rev. 5: Control-assessment overview

03

Keep design evidence separate from test evidence

A policy definition and deployment record describe intended design. An actual test observation shows what happened under specified conditions. The NIST assessment overview supports tailored assessment plans and analysis of results; it is a method reference here, not a substitute for the organisation’s ISO mapping.

Record the actual response, relevant event fields and any difference between the source and exported evidence. Retain only the information needed for the review. Do not turn the safe fixture or an expected block into a statement that an installed Aona control passed.

Source context: NIST SP 800-53A Rev. 5: Control-assessment overview

04

Use explicit review outcomes

The reviewer can accept the evidence for its tested scope, reject it because the expected behaviour was not observed, or leave the conclusion unresolved where coverage or observation is missing. Record the reason and next action. These are distinct outcomes, not a default green status.

The populated packet marks every runtime result as not run. Its authored review decision is therefore “not accepted as operating evidence”. That is an honest, useful starting point: the evaluator has the inputs, the expected comparison and the information needed to complete the test.

Source context: NIST SP 800-53A Rev. 5: Control-assessment overview

05

Tie the evidence to changes and follow-up

Keep the evidence with the relevant control owner and risk-treatment record. A client, policy, application or file-processing change can affect the earlier result. Decide what needs retesting rather than extending an old observation to a changed configuration.

Use actual findings to improve the control or narrow its claimed coverage. The packet is not a certification checklist, an auditor’s conclusion or proof that every employee AI route is protected. The organisation and its assurance process determine how the evidence supports their scoped control.

Source context: NIST SP 800-53A Rev. 5: Control-assessment overview

Put it into practice

Synthetic AI DLP control-test packet

AI-DLP-EX-01 is an organisation-defined teaching control. The packet supplies concrete safe fixtures, planned outcomes and a review record with no invented execution.

All personal data is invented. Every product observation is not run; the control ID is not an ISO Annex A reference or a certification claim.

A test plan is not a result
01

Control

AI-DLP-EX-01, organisation-defined

02

Input pair

Generic wording versus invented personal record

03

Observed

Not run

04

Review

Not accepted as operating evidence

Complete the actual scoped test.

Synthetic AI DLP control-test packet
Test or evidenceExpected comparisonObservation and review
Control definitionProtect the agreed sensitive category on the selected installed path.Design example only; map to the actual ISMS control separately.
Fixture A: generic textThe agreed benign input should follow the permitted route.Not run; no operating-effectiveness conclusion.
Fixture B: invented personal recordApply the agreed protective policy for the selected category.Not run; verify the actual response and event.
Fixture C: appendix contentEvaluate the same category in the selected file/content path.Not run; do not infer file coverage from the prompt result.
Evidence reconciliationCompare client action, event meaning and exported record.Not run; record missing fields or mismatched scope.
Reviewer dispositionAccept only supported observations, reject a demonstrated failure, or leave missing evidence unresolved.Current packet: not accepted as operating evidence because tests were not run.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

isms-ai-dlp-evidence-packet.mdInspect
# Synthetic AI DLP control-test packet

All personal data is invented. Every product observation is not run; the control ID is not an ISO Annex A reference or a certification claim.

AI-DLP-EX-01 is an organisation-defined teaching control. The packet supplies concrete safe fixtures, planned outcomes and a review record with no invented execution.

| Test or evidence | Expected comparison | Observation and review |
| --- | --- | --- |
| Control definition | Protect the agreed sensitive category on the selected installed path. | Design example only; map to the actual ISMS control separately. |
| Fixture A: generic text | The agreed benign input should follow the permitted route. | Not run; no operating-effectiveness conclusion. |
| Fixture B: invented personal record | Apply the agreed protective policy for the selected category. | Not run; verify the actual response and event. |
| Fixture C: appendix content | Evaluate the same category in the selected file/content path. | Not run; do not infer file coverage from the prompt result. |
| Evidence reconciliation | Compare client action, event meaning and exported record. | Not run; record missing fields or mismatched scope. |
| Reviewer disposition | Accept only supported observations, reject a demonstrated failure, or leave missing evidence unresolved. | Current packet: not accepted as operating evidence because tests were not run. |

## Review steps

- Record the exact test scope: Name client, OS, application, input type, policy version and intended sensitive category.
- Capture actual behaviour: Keep expected outcomes separate from observed response, event and exported evidence.
- Document a reasoned decision: Accept only the tested scope, or record failure/missing evidence and the required follow-up.

## Control record

ID: AI-DLP-EX-01, organisation-defined teaching identifier.
Risk: unnecessary sensitive employee input reaches an external AI service.
Intended scope: the application, client and input path chosen by the evaluator.
ISO mapping: use the organisation’s applicable standard and Statement of Applicability; no Annex A number is asserted here.

## Planned runtime outcome

Observation: not run.
Reviewer decision: not accepted as operating evidence.
Reason: no installed-client observation accompanies this authored test plan.
Next action: run the authorised synthetic cases and record scope, response and evidence.

This is a populated assessment plan, not a successful product test or certification result.

## Source and scope

Guide: https://aona.ai/resources/guides/iso27001-ai-dlp-evidence/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- NIST SP 800-53A Rev. 5: Control-assessment overview: https://csrc.nist.gov/pubs/sp/800/53/a/r5/final
- UKAS: Validating management-system certificates: https://www.ukas.com/accreditation/about/validating-ms-certificates/
Download isms-ai-dlp-evidence-packet.md
isms-ai-dlp-evidence-packet.csvInspect
Test or evidence,Expected comparison,Observation and review
Control definition,Protect the agreed sensitive category on the selected installed path.,Design example only; map to the actual ISMS control separately.
Fixture A: generic text,The agreed benign input should follow the permitted route.,Not run; no operating-effectiveness conclusion.
Fixture B: invented personal record,Apply the agreed protective policy for the selected category.,Not run; verify the actual response and event.
Fixture C: appendix content,Evaluate the same category in the selected file/content path.,Not run; do not infer file coverage from the prompt result.
Evidence reconciliation,"Compare client action, event meaning and exported record.",Not run; record missing fields or mismatched scope.
Reviewer disposition,"Accept only supported observations, reject a demonstrated failure, or leave missing evidence unresolved.",Current packet: not accepted as operating evidence because tests were not run.
Download isms-ai-dlp-evidence-packet.csv
fixture-a-generic.txtInspect
SYNTHETIC TEST A
Please make this generic support message clearer: Contact our team if you need help arranging a meeting. Do not add personal information.
Download fixture-a-generic.txt
fixture-b-invented-personal-record.txtInspect
SYNTHETIC TEST B: NO REAL PERSON
Name: Alex Example
Email: alex.example@example.invalid
Employee reference: TEST-EMP-27
Request: Summarise this invented employee support record.
Download fixture-b-invented-personal-record.txt
fixture-c-appendix.mdInspect
# Synthetic appendix test

The main text contains a generic support request.

## Appendix: invented personal details

Alex Example, alex.example@example.invalid, TEST-EMP-27.

This is safe authored text, not a claim that a particular file format or detector was tested.

## Source and scope

Guide: https://aona.ai/resources/guides/iso27001-ai-dlp-evidence/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- NIST SP 800-53A Rev. 5: Control-assessment overview: https://csrc.nist.gov/pubs/sp/800/53/a/r5/final
- UKAS: Validating management-system certificates: https://www.ukas.com/accreditation/about/validating-ms-certificates/
Download fixture-c-appendix.md

Before you proceed

Keep these distinctions clear

A fixture is not a passed control
Record actual execution before claiming operating evidence.
A control ID is not an Annex A mapping
Use the applicable standard and the organisation’s real Statement of Applicability.

Apply it to employee AI use

Bring your actual data path.

Aona can be evaluated for sensitive-input policies and relevant event evidence on supported installed paths.

Aona does not certify the customer’s ISMS or establish universal application, file or policy coverage from a single test.

Use the safe fixture pack to agree the specific input category and path, then record the actual outcome and limitations.

Review your use case

FAQ

Questions for this decision

Is AI-DLP-EX-01 an ISO control number?
No. It is an organisation-defined identifier for this teaching packet. Formal mapping must use the applicable standard, ISMS scope and actual Statement of Applicability.
Why are the result fields marked not run?
No installed-product test was performed when authoring the packet. The files are ready for an authorised evaluation, but expected outcomes are not observations.
Can one successful prompt test prove file protection?
No. Record and test the relevant input paths and formats. Do not extend a result beyond the client, configuration and action actually observed.
Does completing the packet establish ISO certification?
No. It supplies scoped evidence for the organisation’s control and assurance process. Certification and overall ISMS effectiveness require their own applicable assessment.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. NIST SP 800-53A Rev. 5: Control-assessment overview

    The public overview describes tailored security/privacy control assessment plans and analysis of results. It does not establish an ISO Annex A mapping or an Aona result.

    standard · checked 2026-09-21
  2. UKAS: Validating management-system certificates

    Independent checks of certificate authenticity, certification-body accreditation and the relevant verification route.

    standard · checked 2026-09-21
ISO 27001 evidence for employee AI DLP | Aona