Skip to content

ISO 42001 vs ISO 27001: differences and how to integrate them

If you already hold ISO 27001 and are being asked about ISO 42001 (or the other way round), the good news is that you do not start from zero: they share the same skeleton. The bad news is that they are not interchangeable: one manages information security, the other manages the risks specific to AI. Here is where they overlap, where they do not, and how to run both without duplicating work.

What each standard is, in one line

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS): it protects the confidentiality, integrity and availability of an organisation’s information, whether or not AI is used.

ISO/IEC 42001:2023 is the international standard for an AI Management System (AIMS): it manages the risks specific to building, operating or using artificial intelligence — bias, transparency, human oversight, impact on people, traceability of training data.

Both follow the common high-level structure used by ISO management-system standards (like ISO 9001): policy, roles and responsibilities, risk assessment, objectives, internal audit, nonconformities and management review. That shared structure is the key to this article.

Where they overlap (and where they do not)

If you are already ISO 27001 certified, an important part of the work for ISO 42001 is already done. The clearest overlaps:

  • Access management: controlling who can reach which information asset also applies to AI systems and training data.
  • Supplier and third-party management: the due diligence you already do on IT providers extends to model providers, AI APIs and external datasets.
  • Incident management: the security incident process can be extended to AI incidents (unexpected behaviour, detected bias, training data leakage).
  • Risk management structure: the method (identify, analyse, treat, review) is the same machinery; what changes is the catalogue of risks assessed.

What does not overlap, and where ISO 42001 demands new work even with ISO 27001, is everything tied to the AI lifecycle: classifying systems by risk, technical documentation of the model, effective human oversight, bias and fairness management, and transparent communication to affected users.

Do you need both, or is one enough?

It depends on what you manage. If your organisation does not build or operate AI systems in any relevant way, ISO 27001 alone may be enough. If you have high-risk AI systems under the AI Act, or simply want to show customers and regulators you manage AI seriously, consider ISO 42001 (it is not mandatory, but it can help demonstrate it) with ISO 27001 as a base, because:

  1. You reduce AIMS implementation effort by reusing controls already certified in the ISMS.
  2. You may be able to run a combined audit with the same certification body, cutting cost and operational load.
  3. You avoid two committees, two risk policies and two review calendars for what is in practice a single organisational risk management system.

How to build an integrated management system

If you already have ISO 27001

Run a gap analysis of ISO 42001 Annex A against your current ISMS. Identify which controls you already cover (access, suppliers, incidents) and document that cross-coverage explicitly instead of duplicating it. New work concentrates on: inventory and classification of AI systems, technical documentation per system and the human oversight process. See how to build an AI inventory.

If you start from zero with both

Build the common core first (policy, governance committee, risk method, document control) designed from day one to serve both standards, then add the layers specific to each. It is more efficient than certifying ISO 27001 first and patching in ISO 42001 later without having planned the integration.

Fit with the AI Act and the GDPR

ISO 42001 Annex A aligns with a good part of AI Act Articles 9 (risk management), 10 (data governance), 11 (technical documentation) and 14 (human oversight). ISO 27001, for its part, is the usual basis for showing the security measures of GDPR Article 32. An integrated system covering both leaves much of the compliance documentation already built, although an ISO certification does not by itself mean compliance with the AI Act or the GDPR, nor give a presumption of conformity.

Practical conclusion

They are not competitors; they are complementary and share a skeleton. If you already have ISO 27001, do not start ISO 42001 from scratch: do the gap analysis first, reuse what is certified and certify only what is new. If you have neither and need both, design the integration from day one; it will save you an entire recertification of duplicated work. For the next step, see the ISO 42001 certification checklist.

Informational and indicative content; it is not legal advice. Review your case with a qualified professional.

Continuous evidence, not a one-off snapshot Governance Audit Dashboard: 10 KPIs in Excel aligned with AI Act Art. 10 and ISO 42001 as support. €69.
View product

What's your Data Governance maturity?

Free assessment with your priority gaps, plus the self-assessment quiz and savings calculator on the Data Governance path.

Take the free assessment See Data Governance templates Calculate my savings