AI-powered iso 27001 ai MCP server for agents. Supports audit isms, risk assessment, gap ana...
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Inspect callable tools, capabilities, and parameters exposed to AI agents by Iso 27001 Ai Mcp.
audit_ismsAudits your ISMS against all 93 Annex A controls. Returns per-theme compliance status (PASS/PARTIAL/FAIL), gap identification, critical gap flagging for high-priority controls (A.5.1, A.5.15, A.8.5, A.8.24, etc.), and certification readiness assessment.
risk_assessmentPerforms ISO 27005 information security risk assessment. Evaluates 10 AI-relevant threat categories (adversarial attacks, model theft, training data breach, supply chain compromise, insider threat, etc.), calculates likelihood Γ impact risk scores, and produces a treatment plan with specific Annexβ¦
gap_analysisCompares your current controls to ISO 27001 requirements. Supports three targets: "full" (all 93 controls), "core" (critical subset), or "ai-focused" (AI-relevant controls only). Returns prioritized remediation roadmap in 3 phases: Critical (0β30 days), Standard (30β90 days), Remaining (90β180 daysβ¦
crosswalk_to_aiMaps ISO 27001 controls to ISO 42001 AI-specific requirements. Shows how existing ISMS controls extend to AI governance (model security, training data protection, AI incident management) and identifies where AI-specific controls are needed.
generate_soaGenerates a Statement of Applicability per clause 6.1.3(d). Documents all 93 controls as Implemented, Excluded (with justification), or Not Yet Addressed. Required artifact for ISO 27001 certification audits.
incident_classificationClassifies security incidents per controls A.5.24βA.5.28. Determines severity (LOWβCRITICAL), priority (P1βP3), notification requirements, and response procedures. Includes AI-specific incident categories: adversarial attacks, data poisoning, model theft, prompt injection, bias incidents.
βοΈ Built by MEOK AI Labs / CSOAI. Need this applied to your system fast? Book a 30-min Founder Office Hour (Β£29) β https://meok.ai/work Β· Full governance platform β https://meok.ai
MEOK AI Labs MCP Server
MEOK AI Labs MCP Server
This MCP server is built with EU AI Act compliance built-in:
Need help getting compliant? Book a free 15-min diagnostic β
Need custom development, SLA guarantees, or white-label deployment?
View Pricing β | Contact Sales β
This server is part of the MEOK AI Labs ecosystem β 300+ MCP servers for sovereign AI governance.
| Domain | Purpose |
|---|---|
| councilof.ai | EU AI Act compliance marketplace |
| safetyof.ai | AI safety & monitoring |
| meok.ai | Sovereign AI platform |
| cobolbridge.ai | Legacy modernization |
MIT Β© CSOAI-ORG
Built with π by MEOK AI Labs Β· UK Companies House 16939677
mcp-name: io.github.CSOAI-ORG/iso-27001-ai-mcpISO/IEC 27001:2022 compliance assessment for AI systems β 93 Annex A controls across 4 themes, ISO 27005 risk assessment, Statement of Applicability generation, incident classification, and ISO 42001 bridge.
ISO/IEC 27001:2022 is the international standard for Information Security Management Systems (ISMS). Its Annex A contains 93 controls organized into 4 themes: Organizational (37 controls), People (8), Physical (14), and Technological (34). Certification requires demonstrating that your ISMS meets clauses 4β10 and that your Statement of Applicability (SoA) addresses all relevant controls.
For AI systems, ISO 27001 is foundational β but it needs extension. This server audits your ISMS against all 93 controls, performs ISO 27005 risk assessments with AI-specific threat scenarios, generates gap analyses with prioritized remediation roadmaps, produces SoAs, classifies security incidents, and bridges to ISO 42001 for AI-specific governance.
| Tool | Description | Parameters |
|---|---|---|
audit_isms | Audits your ISMS against all 93 Annex A controls. Returns per-theme compliance status (PASS/PARTIAL/FAIL), gap identification, critical gap flagging for high-priority controls (A.5.1, A.5.15, A.8.5, A.8.24, etc.), and certification readiness assessment. | organization_context, scope_description, controls_implemented |
risk_assessment | Performs ISO 27005 information security risk assessment. Evaluates 10 AI-relevant threat categories (adversarial attacks, model theft, training data breach, supply chain compromise, insider threat, etc.), calculates likelihood Γ impact risk scores, and produces a treatment plan with specific Annex A control recommendations. | system_description, assets, threat_scenarios, existing_controls |
gap_analysis | Compares your current controls to ISO 27001 requirements. Supports three targets: "full" (all 93 controls), "core" (critical subset), or "ai-focused" (AI-relevant controls only). Returns prioritized remediation roadmap in 3 phases: Critical (0β30 days), Standard (30β90 days), Remaining (90β180 days). | current_controls, target_certification, focus_themes |
crosswalk_to_ai | Maps ISO 27001 controls to ISO 42001 AI-specific requirements. Shows how existing ISMS controls extend to AI governance (model security, training data protection, AI incident management) and identifies where AI-specific controls are needed. | controls, focus_area |
generate_soa | Generates a Statement of Applicability per clause 6.1.3(d). Documents all 93 controls as Implemented, Excluded (with justification), or Not Yet Addressed. Required artifact for ISO 27001 certification audits. | organization_name, controls_implemented, controls_excluded, exclusion_justifications |
incident_classification | Classifies security incidents per controls A.5.24βA.5.28. Determines severity (LOWβCRITICAL), priority (P1βP3), notification requirements, and response procedures. Includes AI-specific incident categories: adversarial attacks, data poisoning, model theft, prompt injection, bias incidents. | incident_description, affected_assets, detection_method, data_breach, ai_system_involved |
Expected output: Overall coverage ~12% (11/93 controls). Critical gaps flagged in A.5.34 (PII protection), A.8.12 (data leakage prevention), A.8.25 (secure SDLC). Certification NOT ready β 82 gaps to address.
Expected output: Risk register with 10 threat assessments. Highest risks: training data breach (likely Γ high = risk score 16), model theft (possible Γ critical = 20). Treatment plan recommends implementing A.8.12, A.8.16, A.5.12 for the highest-priority gaps.
Expected output: 25 AI-critical controls evaluated. ~40% coverage. Phase 1 critical gaps: A.8.8 (vulnerability management), A.8.12 (data leakage), A.5.34 (PII protection). Estimated remediation: 3β6 months.
Expected output: Severity HIGH (P1), AI incident category: adversarial attack. Immediate response: activate incident plan (A.5.24), contain model, preserve inference logs, assess model integrity. AI-specific controls: A.5.7, A.8.8, A.8.16.
Add to claude_desktop_config.json:
Or install via Smithery:
Add to .cursor/mcp.json:
Add to .vscode/mcp.json:
| Server | Purpose |
|---|---|
| iso-42001-ai | AI management system β Annex A controls and Annex B risk assessment |
| gdpr-compliance-ai | GDPR DPIA, data subject rights, breach notification |
| eu-ai-act-compliance | EU AI Act risk classification and Annex IV documentation |
| soc2-compliance-ai | SOC 2 Trust Service Criteria and control matrix |
| csoai-governance-crosswalk | 12 compliance frameworks mapped through 52 articles |
MIT Β© MEOK AI Labs
| Tier | Price | What you get | Stripe |
|---|---|---|---|
| Smoke test | Β£1 | Signed sample MCP-Hardening report + Article 50 PDF | https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j |
| Quick Kit | Β£9 | EU AI Act Article 50 implementation guide (C2PA + EU-Icon) | https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j |
| Founder Call | Β£29 | 30-min 1-on-1 with the founder | https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j |
Refundable. UK Stripe β VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/iso-27001-ai-mcp)<a href="https://allmcps.com/mcp/iso-27001-ai-mcp"><img src="https://allmcps.com/api/badge/iso-27001-ai-mcp?style=directory" alt="Iso 27001 Ai Mcp on AllMCPs" /></a>