News in ISO 16 Sep 2024

Changes in ISO/IEC 27701:2024: Managing privacy in the context of artificial intelligence, better alignment with ISO 42001.

Changes in ISO/IEC 27701:2024: Managing privacy in the context of artificial intelligence, better alignment with ISO 42001.

ISO/IEC 27701:2019 is an extension of the ISO/IEC 27001 standard, focused on privacy information management systems (PIMS) and the protection of personally identifiable information (PII). However, with the rapid advancement of technologies like artificial intelligence (AI), significant updates to this standard have become necessary. The draft version of ISO/IEC 27701:2024 (DIS 27701:2024) introduces important changes aimed at addressing the growing impact of AI on privacy and data protection. Additionally, the new version of the standard seeks to more closely align with ISO 42001, which provides guidelines for managing AI systems.

Key Differences Between ISO/IEC 27701:2019 and ISO/IEC DIS 27701:2024

A Broader Focus on AI and Privacy

  • 27701:2019: Focused on extending privacy management in the context of processing PII based on ISO/IEC 27001 and 27002 standards.
  • DIS 27701:2024: Introduces new controls directly addressing privacy risks posed by AI systems, reflecting the increasing need to monitor AI's impact on privacy.

Enhanced Risk Management Approaches

  • 27701:2019: Extended ISO/IEC 27001’s risk-based approach to deal with privacy-related risks associated with personal data.
  • DIS 27701:2024: Introduces AI-related risk management, inspired by ISO 42001. This requires AI system impact assessments, evaluating potential effects on individuals, groups, and society.

Applicability Across Different Sectors

  • 27701:2019: Primarily focused on traditional IT systems, emphasizing privacy and security management in standard technological contexts.
  • DIS 27701:2024: Expands the scope to accommodate privacy management in AI systems across various sectors, aligning with ISO 42001, which applies to organizations using or developing AI systems in multiple domains.

AI-Specific Governance and Control Mechanisms

  • DIS 27701:2024: The new version introduces governance structures and controls tailored to AI environments, particularly in areas such as leadership roles, responsibilities, and AI-specific policies. These changes support the leadership requirements in ISO 42001, encouraging organizations to integrate AI management with privacy management.

Integration with ISO 42001

One of the main goals of the DIS 27701:2024 update is to better align the standard with the guidelines provided in ISO 42001, which covers responsible AI system management. This alignment will help organizations better manage privacy in the context of AI, minimizing risks and improving compliance with international standards.

Conclusion

Although the ISO/IEC 27701:2024 draft is still under development, the anticipated changes provide organizations with a unique opportunity to adjust privacy management to the challenges posed by artificial intelligence. These changes, which include AI-related risk management and closer integration with ISO 42001, signal the need for a more comprehensive approach to managing personal data and artificial intelligence in a world where AI is playing an increasingly significant role.

For more information on the new version of the standard and purchasing options, visit the ISO website: ISO/IEC DIS 27701:2024.

Share this article

Recommended from this category