All insights
AI security & compliance2 min read

ISO 42001 vs ISO 27001: how the two management systems interlock

What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.

By FORTE/CYBERx AdvisoryReviewed by FORTE/CYBERx Advisory27 July 2026

Two standards, one operating spine

ISO/IEC 27001 specifies an information security management system: context, leadership, risk assessment and treatment, controls, competence, monitoring, internal audit, management review and improvement. ISO/IEC 42001 specifies an AI management system using the same structure.

That shared structure is the opportunity. If an ISO 27001 system already works, the incremental effort for ISO 42001 is largely about extending scope, adding AI-specific risk criteria and impact assessment, and adding AI-specific controls — not building a second bureaucracy.

Where the coverage genuinely differs

ISO 27001 is concerned with confidentiality, integrity and availability of information. It does not ask whether an automated decision is fair, whether its purpose is appropriate, whether affected people are informed, or whether human oversight is adequate.

ISO 42001 adds those questions: AI policy and objectives, roles and accountability for AI, AI system impact assessment, data quality and provenance for AI, lifecycle management from design through retirement, transparency to affected parties, and supplier obligations specific to AI.

What to integrate first

Integrate the risk register so AI risks sit alongside security risks with the same appetite and escalation path. Integrate supplier management so an AI vendor passes through one due-diligence process that covers both security and AI obligations.

Integrate incident management so an AI failure — a harmful output, a data exposure through retrieval, an agent taking an incorrect action — is triaged through the same process, with AI-specific severity criteria added.

Apply this to your organisation

Want this assessed against your environment?

Send us the specifics and a senior advisor will respond within one business day.

Native secure submission. Your details are never sold or shared.

A realistic sequence for an SME

Stabilise information security first if it is weak; AI governance built on shaky access control and asset management will not hold. Then extend scope to AI, build the AI inventory and impact assessment, and add oversight and transparency requirements.

Pursue certification when a customer, insurer, regulator or board actually requires it. Until then, run the framework for the decision quality it produces.

Evidence expectations

Auditors look for consistency between what the policy says, what the risk assessment concluded, what the controls actually do and what the records show. The most common failure is an articulate policy with no operating evidence behind it.

Keep the AI inventory, impact assessments, approval decisions, evaluation results, supplier assessments, incident records and management review minutes current. That set answers most audit questions.

Sources and further reading

This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.

Related reading

Start a useful conversation

Talk to a senior advisor

Tell us the decision, constraint or opportunity. A senior operator responds within one business day.

Native secure submission. No embedded HubSpot branding.