Beyond CIA: why AI demands a new language of risk

For decades, information security has had three keywords: Confidentiality, Integrity, Availability. The CIA triad. Not an academic abstraction: it was the simplest and most robust way to describe what an information system protects, and why. With artificial intelligence, that triad doesn't disappear — but it's no longer enough.
The triad that held everything together
The idea is elegant: every piece of data or system has a value. That value can be compromised in three ways — accessing it without authorisation (confidentiality), altering it (integrity) or making it unavailable (availability). Three axes, three types of controls, three families of measures. ISO/IEC 27001 built a complete management system on this structure, adopted by thousands of organisations worldwide.
CIA works because the systems it described were fundamentally containers: databases, servers, networks. Entities that store and transmit information. The risk was — and is — that someone tampers with them, steals from them or blocks them.
What happens when information starts reasoning
AI systems are not containers. They are interpreters. They receive data, weigh it, correlate it, produce output — and that output has consequences. A recruitment system doesn't just store CVs: it evaluates them. A credit scoring system doesn't transmit data: it makes decisions.
This is where CIA starts to crack. If a machine learning model systematically produces lower scores for candidates from a particular demographic group, what is the violation? Not confidentiality. Not integrity in the classical sense — the data has not been altered. Not availability. Yet something goes very wrong.
CIA has no words for bias. No words for "the decision is not explainable". No words for "the output amplifies a pre-existing inequality". This is not a gap in ISO 27001: it is simply outside its perimeter. CIA describes risks related to information. AI systems introduce risks related to decisions and their effects.
The new vocabulary: ISO 42001 Annex A
ISO/IEC 42001:2023 is the first international standard specifically dedicated to AI management systems. Structurally it resembles ISO 27001 — a management system with objectives, controls, Annex A. But the content is different.
Annex A organises 38 controls across 9 domains. Many address risks that CIA knows well: governance, documentation, supply chain. But some introduce concepts that CIA has never named.
| Control | Domain | Concept introduced |
|---|---|---|
| A.5.4–A.5.5 | Impact Assessment | Impact on individuals and groups; social effects |
| A.6.1.2 | Life Cycle — Design | Responsible development objectives: fairness, transparency, robustness, privacy, safety |
| A.6.2.3 | Life Cycle — Development | Traceability of design decisions |
| A.7.5 | Data Management | Data provenance: what has happened to the dataset over time |
| A.8.2 | Interested Parties | User disclosure: known limits and failure modes |
| A.9.2 | Responsible Use | Explicit human oversight expectations |
These are not good intentions: they are system requirements. An ISO 42001-certified organisation must document how it assessed the social impact of its AI system, how it ensures human oversight, how it communicates limits to users. This is material for CISOs, DPOs and risk managers — not just data scientists.
Two standards, side by side
ISO 27001 and ISO 42001 don't overlap: they complement each other.
ISO 27001 covers CIA: it ensures that information is confidential, integral and available. It is the right framework for infrastructure security, access management and operational continuity.
ISO 42001 adds the AI dimension: fairness, transparency, impact, oversight. It is the framework for governing what AI systems do — not just how they are built, but what effects they produce.
Those managing AI systems without ISO 42001 have half the picture. Those with ISO 42001 but without ISO 27001 have the other half. The most exposed organisations are those using AI to make decisions affecting people — in HR, credit, healthcare, compliance — who have not yet structured their AI governance.
What this means in practice
For those who already have ISO 27001, ISO 42001 requires genuinely new processes. It is not an update to the existing checklist.
The impact assessment(A.5) requires systematically analysing the effects of the AI system on individuals and groups — before deployment and during the lifecycle. It is not a security assessment: it is closer to a rights-impact assessment, similar to the GDPR's DPIA.
Responsible use (A.9) requires formalising who supervises the AI system, how often, with what powers of intervention. Human oversight is not an option: it is a stated requirement.
User disclosure (A.8.2) requires communicating the known limits of the system — the failure modes the organisation has identified. Transparency as a system obligation, not a communication choice.
These are processes that do not exist in classical security frameworks. Building them requires a gap analysis against the organisation's current state — and that is exactly the first conversation to have.
Sources
Does your AI governance go beyond the CIA triad?
Tomato helps SMEs build the AI governance ISO 42001 requires — impact assessment, human oversight, disclosure — integrating what ISO 27001 already covers.
Talk to us →