Two different standards, two different purposes — and they are designed to run together
As organizations adopt AI faster, one question comes up again and again: "We're already certified to ISO 27001 — do we also need ISO 42001?" The short answer: they are two different standards with two different purposes, and they are designed to be run together. Understand the difference and you can operate both efficiently, without duplicating effort.
ISO 42001 vs ISO 27001 at a glance
| ISO/IEC 27001 | ISO/IEC 42001 | |
|---|---|---|
| Subject | Information assets | AI systems |
| Core goal | Confidentiality, integrity, and availability of information | Responsible development and operation of AI |
| Risk lens | Information security threats | AI-specific risks (bias, opacity, malfunction) |
| First published | 2013 (revised 2022) | 2023 |
| Maturity | Widely adopted, well established | Early but growing quickly |
What they share: the same management-system structure
Both standards follow the same ISO harmonized high-level structure (Annex SL). That means Clauses 4 to 10 line up:
- Context of the organization
- Leadership and commitment
- Planning (including risk assessment)
- Support (resources, competence, awareness)
- Operation
- Performance evaluation
- Improvement
Because the skeleton is identical, you can share a large part of your documentation, internal audit process, and management review between the two systems rather than building a second machine from scratch.
Where they differ: the nature of the risk
ISO 27001 is about protecting information assets from external threats — hacking, leakage, access-control failures. ISO 42001 is about the risks an AI system carries intrinsically:
- Bias in AI models
- Opacity in how decisions are reached (the black-box problem)
- Malfunction driven by poor data quality
- Accountability for AI-generated outcomes
- Human oversight of automated decisions
Put simply: ISO 27001 says "protect information from the outside," while ISO 42001 says "make sure the AI behaves correctly and responsibly." (For the full picture of the AI management system, see our overview of ISO/IEC 42001.)
What ISO 42001 adds that ISO 27001 doesn't
ISO 42001 introduces concepts that have no equivalent in ISO 27001:
- An AI policy. A statement of the principles by which the organization develops and operates AI — fairness, transparency, and explainability, not just security.
- AI system impact assessment. A process for evaluating, in advance, how an AI system affects individuals, groups, and society. It also connects directly to the EU AI Act's risk classification. (See ISO/IEC 42005.)
- AI supply chain management. When you use third-party AI — a model API, a cloud AI service — you have to consider the provider's AI governance too.
- Human oversight. A documented mechanism for people to intervene in and control automated decisions.
How to run them together
If you already operate ISO 27001, you do not need to build ISO 42001 from zero. The efficient approach is to extend your existing system:
- Integrate common documentation. Add AI risk items to your risk procedure, run AI governance into the same management review, fold AI ethics and safety into your competence and training records.
- Extend the scope of risk assessment. Register AI systems as a distinct asset type in your existing inventory, and add AI-specific risks — bias, malfunction, lack of explainability — to your assessment criteria. (Our overview of ISO/IEC 23894 covers AI risk sources in depth.)
- Build one combined internal audit team. Auditors qualified in both standards can check both systems in a single internal audit.
- Choose a certification body that offers combined audits. A combined audit cuts both the schedule and the cost — confirm this with the body in advance.
For the control-by-control version of this — which ISO 27001 outputs you reuse, extend, or build new — see extending an ISO 27001 ISMS to ISO 42001.
Can you get ISO 42001 without ISO 27001?
Yes. ISO 42001 does not require ISO 27001 as a prerequisite. In practice, though, most organizations operating AI also have information security to manage, so preparing both together tends to be more efficient over the medium term. In tightly regulated sectors — finance, healthcare, the public sector — the ISO 27001 + ISO 42001 combination is likely to become a baseline expectation.
Checklist for ISO 27001-certified organizations preparing ISO 42001
- Map your current AI systems — which AI is used, and for what?
- Check whether AI items can be added to your existing risk assessment process
- Draft an AI policy
- Perform an AI system impact assessment for each AI system
- Define and document a human-oversight mechanism
- Review your third-party AI provider management process
- Plan how to build ISO 42001 internal audit competence
The bottom line
ISO 27001 and ISO 42001 are not competitors — they are complementary. Think of it as placing AI governance on top of an information-security foundation, and integration starts to feel natural. For any organization using AI seriously, running the two together is becoming less of a choice and more of a strategic necessity.
Want to know where you stand? Our free AI governance readiness assessment shows how prepared you are for ISO/IEC 42001 — a useful first step whether or not you already hold ISO 27001.
Written by a certified ISO/IEC 42001 Lead Auditor and principal consultant at ITG insights.
ITG insights specializes in ISO/IEC 42001 and ISO/IEC 20000 certification consulting, risk management, and governance framework design. Consulting and training inquiries: info@ai42001.ai
ai42001.ai is an AI governance platform structured around ISO/IEC 42001.
Related
🔧 Ready to extend? The control-by-control path: extending an ISO 27001 ISMS to ISO 42001.
⚖️ The regulatory picture: how ISO 42001, the EU AI Act, and NIST AI RMF fit together.
📘 The standard itself: the ISO/IEC 42001 reference overview.
🗺 The whole portfolio: part of our SC 42 AI Standards Map — the international AI standards portfolio, explained.