On this page
ISO standard

ISO 27001 + ISO 42001

How much of your ISMS carries over, and what an AI management system adds

Reviewed by the ISO42k editorial team · Last reviewed October 9, 2026

Bottom line

If you already hold ISO 27001, you have the hardest part of ISO 42001 running: the management system itself. Both standards follow ISO's harmonized structure, so context, leadership, risk treatment, internal audit and management review extend rather than start over. The new work concentrates in AI risk and impact assessment, the AI system lifecycle, data quality and provenance, and a second Statement of Applicability against 42001's 38 Annex A controls. Many certification bodies can audit both in one integrated program.[1][2]

ISO 27001 in brief

ISO/IEC 27001 is the international standard for an information security management system (ISMS). It requires an organization to assess information security risks, treat them with controls, and continually improve. Its Annex A lists 93 reference controls in four themes: organizational, people, physical and technological.[1]

ISO/IEC 42001 uses the same harmonized clause structure (clauses 4 to 10) but points it at a different object: AI systems and the decisions they influence, rather than the confidentiality, integrity and availability of information.[2]

Current edition
ISO/IEC 27001:2022 (Amd 1:2024)
Protects
Information assets (confidentiality, integrity, availability)
Annex A
93 controls in 4 themes
Certifiable
Yes, accredited third-party certification
Certificate cycle
3 years with annual surveillance audits
Relationship to 42001
Shared structure; complementary, neither replaces the other

Where they overlap

Read this table from the ISMS you already run. Each row is an ISO 27001 element and how it carries into an ISO 42001 AI management system (AIMS).

Reuse(5)Extend(9)Net new(2)
ISO 27001ISO 42001Coverage
Cl. 4 Context, interested parties, scope
Cl. 4.1–4.4
Same clause. Add your AI roles (provider, producer, customer including user, partner) and which AI systems are in scope.
Reuse
Cl. 5 Leadership and information security policy
Cl. 5, A.2 Policies related to AI
Leadership commitment and roles carry over. Add an AI policy aligned with existing policies (A.2.3).
Extend
Cl. 6.1.2 Information security risk assessment
Cl. 6.1.2 AI risk assessment
Reuse the method and risk register. Add AI risk sources: bias, opacity, misuse, model drift, data quality.
Extend
Cl. 6.1.3 Risk treatment and Statement of Applicability
Cl. 6.1.3, Annex A (38 controls)
Near-identical mechanics. You produce a second SoA justifying inclusion or exclusion of each 42001 control.
Reuse
Cl. 8 Operation
Cl. 8.1–8.4
Operational planning and risk assessment at intervals carry over. 8.4, impact assessment at planned intervals, has no ISO 27001 counterpart.
Extend
Cl. 7 Support: competence, awareness, documented information
Cl. 7, A.4 Resources for AI systems
Same processes. Extend competence and awareness to AI roles; document data, tooling and compute resources.
Reuse
Cl. 9 Internal audit and management review
Cl. 9.2, 9.3
Run one audit program and one management review covering both systems.
Reuse
Cl. 10 Nonconformity and continual improvement
Cl. 10
Same corrective action process.
Reuse
A.5.19–5.23 Supplier relationships and cloud services
A.10 Third-party and customer relationships
Supplier due diligence carries over. Add allocation of AI responsibilities and obligations to customers.
Extend
A.5.24–5.28 Incident management
A.8.4, A.6.2.6
Reuse the incident process. Add AI incidents that aren't security events, such as harmful or biased outputs.
Extend
A.8.15–8.16 Logging and monitoring
A.6.2.6, A.6.2.8
Log infrastructure carries over. Add AI system event logs and performance monitoring in operation.
Extend
A.8.25–8.29 Secure development and testing
A.6 AI system life cycle
SDLC gates carry over. Add responsible-AI objectives, requirements, verification and validation, deployment criteria.
Extend
A.5.12, A.5.34 Classification, privacy and PII
A.7 Data for AI systems
Data handling carries over. Add data quality, provenance and preparation for training and evaluation data.
Extend
No equivalent
Cl. 6.1.4, A.5 Assessing impacts of AI systems
Assess impacts on individuals, groups and society. The largest genuinely new process for most ISMS teams; ISO/IEC 42005:2025 gives guidance.
Net new
No equivalent
A.8.2, A.8.3, A.8.5
User-facing system documentation, external reporting, and information for interested parties.
Net new
A.5.10 Acceptable use of information
A.9 Use of AI systems
Acceptable-use rules carry over. Add objectives, processes and intended-use limits for responsible AI use.
Extend

Reuse: the process carries over with scope changes. Extend: the mechanics carry over but AI-specific content is required. Net new: no ISO 27001 equivalent. Editorial assessment based on the published clause and control structures.

What ISO 42001 won't cover

ISO 42001 is not a security standard. Adding it does not replace the controls or the certificate your customers ask for under ISO 27001.

Information security controls

ISO 42001 has no equivalent of 27001's 93 Annex A controls for access, cryptography, network and physical security. Security of AI infrastructure still sits in the ISMS.[1][2]

Privacy management

Neither standard is a privacy management system. ISO/IEC 27701:2025 is a standalone privacy information management system standard, certifiable without ISO 27001.[3]

AI-specific attack techniques

Prompt injection, model extraction and data poisoning need technical controls. ISO 42001 requires you to assess and treat these risks but does not prescribe how.

A security certificate

An ISO 42001 certificate says nothing about your ISMS. Buyers who require ISO 27001 will still ask for it separately.

Using ISO 42001 to get there

  1. 1

    Extend scope and context

    Inventory AI systems, record your role for each (provider, producer, customer, partner), and set the AIMS scope alongside the ISMS scope.

  2. 2

    Add an AI policy to the policy set

    Write the AI policy (A.2) and cross-reference it from the information security policy rather than duplicating content.

  3. 3

    Extend the risk method

    Add AI risk sources and criteria to the existing methodology, then stand up the AI system impact assessment as a new, linked process.

  4. 4

    Produce the second Statement of Applicability

    Map each of the 38 Annex A controls to existing ISMS evidence where it exists, and to new procedures where it doesn't.

  5. 5

    Build lifecycle and data controls

    Extend SDLC gates with AI requirements, verification and validation, and deployment criteria. Add data quality and provenance checks.

  6. 6

    Integrate assurance

    Run one internal audit program and one management review, then book an integrated audit with a certification body accredited for both standards (for 42001, under ISO/IEC 42006).

Frequently asked questions

Do I need ISO 27001 before ISO 42001?

No. ISO 42001 is standalone and certifiable on its own. Having an ISMS in place makes it faster because the management-system clauses are already running.

Can one audit cover both standards?

Yes. Many certification bodies offer integrated audits under IAF MD 11 that cover shared clauses once. For ISO 42001 the body must be accredited under ISO/IEC 17021-1 together with ISO/IEC 42006:2025. You typically receive a certificate for each standard, each with its own scope.

Does ISO 42001 certification cover information security?

No. ISO 42001 requires you to consider security as an AI risk, but it is not an information security standard. Customers who require ISO 27001 will still ask for it.

How much faster is ISO 42001 with ISO 27001 in place?

It varies with the number and complexity of AI systems in scope. The time saved comes from clauses 4 to 10 and supporting processes; the AI risk assessment, impact assessment and Annex A work remain new effort.

Should the AIMS and ISMS share one scope?

They can share an organizational boundary, but the AIMS scope is defined by AI systems and your role in each. Most organizations keep two scope statements that reference each other.

This page is general information, not legal advice. Laws change; confirm obligations with counsel.