ISO 42001 vs ISO 27001: how the two management systems interlock
What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.
Two standards, one operating spine
ISO/IEC 27001 specifies an information security management system: context, leadership, risk assessment and treatment, controls, competence, monitoring, internal audit, management review and improvement. ISO/IEC 42001 specifies an AI management system using the same structure.
That shared structure is the opportunity. If an ISO 27001 system already works, the incremental effort for ISO 42001 is largely about extending scope, adding AI-specific risk criteria and impact assessment, and adding AI-specific controls — not building a second bureaucracy.
Where the coverage genuinely differs
ISO 27001 is concerned with confidentiality, integrity and availability of information. It does not ask whether an automated decision is fair, whether its purpose is appropriate, whether affected people are informed, or whether human oversight is adequate.
ISO 42001 adds those questions: AI policy and objectives, roles and accountability for AI, AI system impact assessment, data quality and provenance for AI, lifecycle management from design through retirement, transparency to affected parties, and supplier obligations specific to AI.
What to integrate first
Integrate the risk register so AI risks sit alongside security risks with the same appetite and escalation path. Integrate supplier management so an AI vendor passes through one due-diligence process that covers both security and AI obligations.
Integrate incident management so an AI failure — a harmful output, a data exposure through retrieval, an agent taking an incorrect action — is triaged through the same process, with AI-specific severity criteria added.
Want this assessed against your environment?
Send us the specifics and a senior advisor will respond within one business day.
A realistic sequence for an SME
Stabilise information security first if it is weak; AI governance built on shaky access control and asset management will not hold. Then extend scope to AI, build the AI inventory and impact assessment, and add oversight and transparency requirements.
Pursue certification when a customer, insurer, regulator or board actually requires it. Until then, run the framework for the decision quality it produces.
Evidence expectations
Auditors look for consistency between what the policy says, what the risk assessment concluded, what the controls actually do and what the records show. The most common failure is an articulate policy with no operating evidence behind it.
Keep the AI inventory, impact assessments, approval decisions, evaluation results, supplier assessments, incident records and management review minutes current. That set answers most audit questions.
Sources and further reading
- ISO/IEC 42001 AI management systems
- ISO/IEC 27001 information security management systems
- NIST AI Risk Management Framework
This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.
Related reading
Securing enterprise AI adoption: a practical AI security control set
The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.
Read articleAI risk assessment: how to assess an AI system before it ships
A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.
Read articleThe AI governance operating model: roles, gates and evidence
How to design an AI governance framework that approves useful work quickly and stops harmful work early, without a committee bottleneck.
Read article