ISO 42001 or ISO 27001 for your AI product?

Stacked documents and folders

ISO 42001 vs ISO 27001: what each standard covers, where they overlap, which one AI product companies usually need first, and how to run both together.

Bhaskar Bhatt7 min read

ISO 42001 vs ISO 27001 comes down to scope. ISO/IEC 27001 manages information security risk across your whole organisation. ISO/IEC 42001 manages the risks of building, providing or using AI systems, including harms to people that have nothing to do with security.

On this page
  1. What does ISO/IEC 27001 cover?
  2. What does ISO/IEC 42001 cover?
  3. How do the two standards compare?
  4. Which one does your AI product need first?
  5. How can you run ISO 42001 and ISO 27001 together?
  6. What does a readiness plan look like?
  7. When isn’t certification the right approach?
  8. Frequently asked questions

Most AI products end up needing the first and benefiting from the second. This post explains what each standard covers, where they overlap, who tends to ask for which, and how to run them as one programme instead of two. The order you do them in matters more than most teams expect.

What does ISO/IEC 27001 cover?

ISO/IEC 27001 specifies requirements for an information security management system (ISMS): how you identify risks to the confidentiality, integrity and availability of information, choose controls, and prove they work. It applies to any organisation and any technology, AI or not. It’s the certificate enterprise buyers most often ask a software vendor for.

The current edition is ISO/IEC 27001:2022, with a 2024 amendment on climate action that asks you to consider whether climate change is a relevant issue for your ISMS. Annex A lists reference controls grouped into organisational, people, physical and technological themes. You select the ones that fit your risks and justify the rest in a Statement of Applicability.

What 27001 doesn’t do is ask whether your model is fair, explainable or fit for its purpose. A perfectly secure AI system can still make discriminatory decisions, and 27001 has nothing to say about that.

What does ISO/IEC 42001 cover?

ISO/IEC 42001 specifies requirements for an AI management system (AIMS): policies, objectives and processes for the responsible development, provision or use of AI systems. It covers AI risk assessment, AI system impact assessment, data and lifecycle controls, transparency, and monitoring. It applies to organisations that build, sell or only use AI.

ISO/IEC 42001:2023 was the first international management system standard for AI. Like 27001, it has an Annex A of reference controls, here focused on AI: impact assessment, data quality and provenance, system lifecycle, information for users and third-party relationships. Its other annexes give implementation guidance and list AI risk sources such as lack of transparency and bias.

The impact assessment is the part with no real equivalent in 27001. It asks you to consider the effects of an AI system on individuals, groups and society, not just on your organisation. Certification bodies auditing 42001 work to an additional standard, ISO/IEC 42006:2025, which sets the competence they need to audit AI.

How do the two standards compare?

Both are certifiable management system standards with the same clause structure, so leadership, risk, documentation, internal audit and management review work the same way. They differ in what risk means. 27001 protects information. 42001 also covers harms from how an AI system behaves, and it applies only to the AI parts of your organisation.

AspectISO/IEC 27001ISO/IEC 42001
Management systemInformation security (ISMS)Artificial intelligence (AIMS)
Risk focusConfidentiality, integrity and availability of informationRisks and impacts of AI systems on the organisation, individuals and society
Typical scopeThe whole organisation or a product line and its supporting functionsThe AI systems you develop, provide or use, and the teams around them
Signature requirementStatement of Applicability against Annex A controlsAI system impact assessment, plus a Statement of Applicability for its own Annex A
Who usually asks for itEnterprise procurement and security questionnairesBuyers of AI products, especially in regulated sectors and the EU
CertificationAccredited certification widely availableAccredited certification available; fewer certification bodies so far
Relation to the EU AI ActSupports security and logging dutiesSupports governance, risk and documentation duties; doesn’t by itself prove compliance

Both follow the harmonised structure ISO uses for management system standards: context, leadership, planning, support, operation, performance evaluation and improvement. ISO/IEC 20000-1 for IT service management, which we’re certified to, uses the same skeleton. That shared skeleton is why running several of these standards together costs far less than running them separately.

Which one does your AI product need first?

For most AI product companies, ISO 27001 comes first. Security questionnaires block deals today, and 42001 assumes many controls 27001 already gives you, such as access control, supplier management and incident response. Add 42001 when buyers ask about AI governance, or when your AI makes decisions that affect people.

There are exceptions. If your organisation already holds 27001, the question is only when to extend to 42001. If you sell into the EU and your product may be a high-risk system under the AI Act, starting the 42001 work early is reasonable, because the impact assessment and lifecycle documentation take time to build. Our post on EU AI Act roles and obligations covers how to work out whether that applies.

US buyers often ask for SOC 2 rather than 27001. That’s an attestation report, not an ISO certification, but most of the control work carries across.

How can you run ISO 42001 and ISO 27001 together?

Run one integrated management system with shared governance, risk methodology, document control, internal audit and management review, then add the AI-specific pieces on top. A combined audit by one certification body is often possible. The main extra work for 42001 is the AI policy, impact assessments, and lifecycle and data controls.

What can be shared, and what can’t:

  • Shared outright: leadership commitment, roles, competence and awareness, document control, internal audit, management review, corrective action.
  • Shared with extensions: the risk register and method, supplier management (add model and data providers), incident management (add AI incidents such as harmful outputs), logging and monitoring.
  • AI only: the AI policy, AI system inventory, impact assessments, data quality and provenance records, model evaluation and human oversight arrangements.

Keep one risk register with an extra category for AI harms rather than two registers that drift apart. Ask your certification body early whether it holds accreditation for both standards, because not every body that audits 27001 is accredited for 42001.

What does a readiness plan look like?

A readiness plan starts with scope and a gap assessment, then builds the shared management system, then adds AI-specific controls, and finishes with internal audit and management review before the certification audit. The order is the same for one standard or both. Timelines depend on your size and how much already exists.

  1. Set scope. Decide which products, teams and locations each standard covers. Narrow scopes are easier to certify, but buyers will read the certificate’s scope, so don’t make it meaninglessly small.
  2. Inventory AI systems. List every model and AI feature you build or use, with owner, data sources and purpose. You need this for 42001 and for the AI Act anyway.
  3. Run a gap assessment. Compare what you do today against both standards’ clauses and Annex A controls.
  4. Build the shared core. Policies, risk method, document control, internal audit programme.
  5. Add the AI layer. AI policy, impact assessments for each AI system, data and evaluation records, oversight procedures.
  6. Operate it. Auditors want evidence the system has run, not just documents. Plan for a period of real operation before the audit.
  7. Internal audit and management review. Then the two-stage certification audit, followed by annual surveillance audits.

For the AI risk and governance side, the NIST AI Risk Management Framework is a useful, free companion. It’s voluntary guidance, not a certifiable standard, and its Govern, Map, Measure and Manage functions map reasonably well onto 42001 clauses.

When isn’t certification the right approach?

If no customer or regulator is asking, and you’re a small team with one AI feature, certification can be premature. The audits and surveillance cycle are a standing cost. Adopting the standards’ practices without certifying, then certifying when a deal needs it, is often the better order.

Certification also isn’t a substitute for law. Neither standard makes you compliant with the EU AI Act, the GDPR or sector rules on its own. Under Article 40 of the AI Act, only harmonised standards referenced in the Official Journal give a presumption of conformity, so check the Commission’s AI Act pages for the current position. This post is not legal advice.

As for what we don’t do: we’re not a certification body and can’t certify you. Keeping the people who build your management system separate from the people who audit it is the point of the scheme. We help with scoping, gap assessments, writing and operating the controls, and the engineering evidence behind them through our AI governance and security and cybersecurity and GRC work. Engagements start with a 2–6 week scoping phase.

Related reading: enterprise AI security practices and GRC software in practice.

Frequently asked questions

Can we get ISO 42001 without ISO 27001?

Yes. ISO/IEC 42001 doesn’t require 27001 certification. In practice you’ll still need many of the same security controls, because protecting training data, models and logs is part of managing AI risk. Teams without 27001 often end up building a lot of it anyway.

Does using a third-party model like an LLM API put us in scope for 42001?

It can. ISO/IEC 42001 covers organisations that use AI systems as well as those that develop them. If an AI feature built on a third-party model is part of your product, it belongs in your AI system inventory, and the model provider becomes a supplier you manage.

How often are the certificates audited?

Both follow the usual ISO certification cycle: a two-stage initial audit, surveillance audits each year, and a recertification audit before the certificate expires, typically every three years. If you hold both, ask about combined audits to cut the time spent.

Is ISO/IEC 42001 going to change soon?

The current edition is ISO/IEC 42001:2023. ISO reviews standards periodically, and related standards keep appearing, such as ISO/IEC 42006 for certification bodies. Check the standard’s page on iso.org for its current status before you start a programme.

Scroll to Top