Back to ISO 42001

ISO 42001 vs ISO 27001: Differences, Overlap, and Which First

ISO 42001 vs ISO 27001: Differences, Overlap, and Which First Photo: Unsplash

ISO/IEC 27001 has been the reference standard for information security management for two decades. ISO/IEC 42001, published in December 2023, is the first certifiable standard for managing artificial intelligence. If you build or use AI in your product, you will likely be asked about both. This guide explains what each standard covers, how they differ, how much of the work overlaps, and in what order to pursue them.

Key takeaways

  • ISO 27001 protects information. ISO 42001 governs AI systems. One is about confidentiality, integrity, and availability of data. The other is about how AI is developed, provided, and used responsibly.
  • They share the same management system structure. Both follow the ISO harmonized structure (clauses 4 to 10), so an existing ISMS gives you most of the skeleton for an AI management system (AIMS).
  • ISO 42001 adds work that has no ISO 27001 equivalent, mainly AI system impact assessments and controls over the AI life cycle, data, and responsible use.
  • Both are certifiable by accredited certification bodies on a three-year cycle with annual surveillance audits, and they can be audited together.
  • Most companies do ISO 27001 first, then extend it to ISO 42001 when customers or regulators start asking about AI governance.

ISO 42001 vs ISO 27001 at a glance

ISO/IEC 27001:2022 ISO/IEC 42001:2023
Management system Information security management system (ISMS) AI management system (AIMS)
What it protects or governs Information and the systems that process it AI systems across their life cycle, and their effects on people
Core risk focus Risks to confidentiality, integrity, and availability AI risks, plus impacts on individuals, groups, and society
Clause structure Harmonized structure, clauses 4 to 10 Harmonized structure, clauses 4 to 10
Annex A 93 controls in four themes: organizational, people, physical, technological 38 controls across nine control objectives specific to AI
Unique requirement Information security risk assessment and treatment AI system impact assessment (clause 6.1.4)
Statement of Applicability Required Required
Who it is for Any organization handling information Organizations that develop, provide, or use AI systems
Certification Accredited certification body, three-year cycle Accredited certification body, three-year cycle

What ISO 27001 covers

ISO 27001 specifies how to establish, run, and improve an information security management system. You define the scope, assess information security risks, choose controls to treat them, and prove through internal audits and management review that the system works.

Annex A lists 93 reference controls in the 2022 edition, covering areas such as access control, cryptography, supplier security, incident management, secure development, logging, and business continuity. You select the ones that apply and justify each decision in a Statement of Applicability.

What ISO 42001 covers

ISO 42001 specifies how to establish, run, and improve an AI management system. It applies whether you develop AI models, provide AI-powered products, or use AI systems from others.

Clauses 4 to 10 mirror ISO 27001, with AI-specific additions:

  • Context (clause 4): you identify the AI systems in scope and your role for each, such as developer, provider, or user.
  • Planning (clause 6): AI risk assessment and treatment, plus the AI system impact assessment in clause 6.1.4, which evaluates the potential consequences of AI systems for individuals, groups, and society.
  • Operation (clause 8): running those assessments and treatments as part of normal work.

Annex A contains 38 controls across nine objectives: policies related to AI, internal organization, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. Annex B gives implementation guidance, and Annex C lists AI-related objectives and risk sources to consider.

Where the two standards overlap

Because both use the harmonized structure, a large share of the management system is reusable:

Element Reusable from ISO 27001?
Scope, context, and interested parties Yes, extended to cover AI systems and your AI role
Leadership, policy, roles, and responsibilities Yes, with an AI policy and AI-specific roles added
Risk assessment method Mostly, extended with AI risk sources
Document control, competence, and awareness Yes
Internal audit and management review Yes, run as one integrated program
Nonconformity and corrective action Yes
Asset inventory Yes, extended to data, tooling, compute, and people behind each AI system
Supplier management Yes, extended to AI suppliers and model providers
Logging, incident management, secure development Yes, extended to AI inputs, outputs, and AI-specific failures

In practice, an organization with a working ISMS often finds that much of the management system work for ISO 42001 is already done. The new effort concentrates in the AI-specific pieces.

What is new in ISO 42001

These requirements have no real counterpart in ISO 27001, and they are where most of the new work sits:

  • AI system impact assessments. For each AI system in scope, assess the potential effects on people and society, such as fairness, safety, privacy, and transparency, and act on the results.
  • AI life cycle controls. Define objectives and requirements for AI systems, and document design, development, verification, validation, deployment, operation, and monitoring.
  • Data for AI systems. Manage the quality, provenance, and preparation of data used to train, test, and operate AI.
  • Information for interested parties. Tell users and affected people what they need to know about the AI system, including how to report problems.
  • Responsible use. Set and follow objectives and processes for using AI systems responsibly, including human oversight where needed.

Which should you pursue first?

  • You have neither, and customers ask about security: start with ISO 27001. It is more widely requested, and it builds the management system you will reuse.
  • You already hold ISO 27001 and ship AI features: extend to ISO 42001. It is usually the faster path to a credible AI governance story, and a combined audit keeps the cost down.
  • AI is your core product and buyers ask specifically about AI governance: you can pursue both together as an integrated management system with one internal audit program and one management review.
  • You sell into the EU: ISO 42001 does not equal EU AI Act compliance, but its risk management, documentation, data governance, and transparency controls give you a strong base for it. See our EU AI Act framework page.

How SecureSlate helps

SecureSlate runs ISO 27001 and ISO 42001 as one integrated program, for one fixed price:

  • A dedicated compliance lead scopes your AI systems, runs the AI impact assessment, and prepares the Statement of Applicability.
  • ISO 27001 evidence reuse. The platform maps controls across both standards, so evidence collected once counts for both. See multi-framework compliance.
  • Continuous evidence collection from the tools you already use, with an audit partner for certification or a certification body of your choice.

FAQ

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 is a standard for managing information security risks to data. ISO 42001 is a standard for managing AI systems responsibly, including their impact on people and society. They share the same management system structure, but ISO 42001 adds AI impact assessments and AI-specific controls.

Do I need ISO 27001 before ISO 42001?

No. ISO 42001 can be certified on its own. Having ISO 27001 first makes it much faster, because the management system structure, internal audit, document control, and many supporting controls are reusable.

Can ISO 27001 and ISO 42001 be audited together?

Yes. Many certification bodies offer integrated audits for organizations running both management systems, which reduces audit days and duplicate evidence.

How many controls are in ISO 42001?

ISO 42001 Annex A contains 38 controls across nine control objectives, compared with 93 controls in ISO 27001:2022 Annex A. As with ISO 27001, you justify which controls apply in a Statement of Applicability.

Does ISO 42001 certification mean I comply with the EU AI Act?

No. ISO 42001 is a voluntary management system standard, while the EU AI Act is a regulation with its own obligations based on the risk category of each AI system. ISO 42001 helps you build many of the processes the Act expects, but you still need to assess the Act's specific requirements.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory, or professional advice. Requirements vary by organization and jurisdiction. Consult qualified advisors for your specific obligations.


Related guides

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Keep reading

Oct 1, 2026 · ISO 27001

ISMS-P Certification: A Guide for SaaS and HealthTech Vendors Entering South Korea

Jul 7, 2026 · TemplatesISO 27001

ISO 27001 Statement of Applicability Template: Free SoA Excel Download

Jul 5, 2026 · ISO 27001

ISO 27001 Consultant vs Compliance Automation Platform: Which Is Right for You?

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?