Skip to main content
ISO 42001

ISO 27001 vs ISO 42001: What Each Standard Actually Governs

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

11 min read

Contents

    A Head of Security at a UK SaaS company put the confusion precisely last month: "We have ISO 27001. Our board has asked whether ISO 42001 is just the AI version of the same thing, and whether we can bolt it on. I do not know how to answer that, because half of what I read says yes and half says no."

    Both halves are right, which is why the question is hard. The management system architecture is close to identical. The control set is not. Understanding which part is which determines whether an ISO 42001 programme takes three months or nine.

    This is a practitioner read on what each standard governs, where the overlap is genuine, where ISO 42001 requires work that has no ISO 27001 equivalent, and how to sequence the two.

    The question behind the question

    Nobody asks this question in the abstract. It arrives attached to a commercial or regulatory pressure: an enterprise buyer has added AI governance questions to a security questionnaire, an investor has raised it in diligence, or a board has read something about the EU AI Act and wants to know the organisation's position.

    The useful reframing is to ask what the organisation is being asked to prove. ISO 27001 proves you manage information security. ISO 42001 proves you govern AI systems. If the question coming at you is about data protection, access control, and breach response, ISO 27001 is the answer. If it is about how a model was trained, who is accountable for its outputs, and what happens when it behaves unexpectedly, ISO 27001 does not address it and no amount of ISMS documentation will.

    What each standard is for

    ISO 27001 specifies an information security management system. Its object is information: how it is classified, protected, accessed, retained, and recovered. The 2022 revision carries 93 controls in Annex A across four themes: organisational, people, physical, and technological. It has been in the market since 2005 and the implementation practice around it is mature.

    ISO 42001 specifies an artificial intelligence management system. It was published in December 2023. Its object is AI systems: how they are inventoried, risk-assessed, developed, deployed, monitored, and retired, and who is accountable at each stage. Annex A carries 38 controls organised across control objectives covering AI policy, internal organisation, resources, impact assessment, lifecycle, data, information for interested parties, use of AI systems, and third-party relationships.

    The distinction that matters in practice: information security asks whether the data is protected. AI governance asks whether the system using the data should be doing what it is doing, whether anyone can explain why it produced a given output, and who is answerable when it is wrong.

    The shared management system spine

    Both standards are built on the harmonised structure that ISO applies across its management system standards. Clauses 4 through 10 are the same shape in both:

    Clause 4 covers context of the organisation and the scope of the management system. Clause 5 covers leadership, policy, and organisational roles. Clause 6 covers planning, risk, and objectives. Clause 7 covers resources, competence, awareness, communication, and documented information. Clause 8 covers operational planning and control. Clause 9 covers monitoring, internal audit, and management review. Clause 10 covers nonconformity and continual improvement.

    An organisation that already operates ISO 27001 has this spine running. The governance committee exists. The policy approval process exists. The internal audit programme, the management review cadence, the nonconformity process, the documented information controls, all of it operates. None of that needs rebuilding for ISO 42001. It needs extending in scope.

    This is the source of the honest half of the "you can bolt it on" answer. The management system architecture genuinely does reuse.

    Where ISO 42001 goes somewhere ISO 27001 does not

    Five areas have no meaningful ISO 27001 equivalent, and they are where the implementation effort concentrates.

    AI system inventory and impact assessment. ISO 42001 expects the organisation to know what AI systems it operates, what they do, who they affect, and what the consequences of failure are. Information asset inventories do not capture this. An asset register records that a system exists and what data it holds. An AI system inventory records what the system decides, on what basis, and with what oversight.

    AI risk with an AI risk taxonomy. ISO 27001 risk assessment is oriented to confidentiality, integrity, and availability. AI risk includes model performance degradation, training data quality and lineage, bias and discriminatory outcome, explainability failure, automation bias in human reviewers, and inappropriate reliance. These do not map onto CIA, and a risk register that tries to force them into that shape will not survive audit scrutiny.

    AI system lifecycle controls. ISO 42001 expects governance across the full lifecycle: design objectives, data acquisition and preparation, model development and validation, deployment approval, post-deployment monitoring, and retirement. This integrates the management system with the engineering process at a depth that ISO 27001 secure development controls do not reach.

    Human oversight and transparency. The standard expects documented decisions about where humans are in the loop, what information they receive, what authority they have to override, and what the organisation tells affected parties about AI involvement. There is no ISO 27001 analogue.

    Third-party AI. Supplier controls in ISO 27001 address security posture. AI supplier governance addresses model provenance, training data claims, update and versioning practices, and what happens when a foundation model provider changes behaviour without notice.

    How much of ISO 27001 actually reuses

    In practice, for an organisation with a mature ISMS, roughly 40 to 55 percent of the ISO 42001 control surface has a meaningful ISO 27001 antecedent. That proportion is an approximation drawn from delivery experience rather than a measured figure. The reuse concentrates in the management system spine, in security controls that extend to AI systems, in supplier assessment workflow, in awareness and competence, and in the audit and review architecture.

    The remainder is new work requiring practitioner judgement rather than adaptation. That proportion is why an ISO 42001 implementation for an ISO 27001-certified organisation is materially faster than a standalone build, and also why it is not the trivial overlay some organisations expect.

    The honest framing for a board is this: ISO 27001 gets you the scaffolding and about half the controls. The other half is new, and it is the half that determines whether the certificate means anything.

    Which to implement first

    For most organisations, ISO 27001 first.

    The reasons are commercial rather than technical. ISO 27001 is a recognised procurement requirement across UK and EU enterprise buying today. ISO 42001 is not yet, though it is moving in that direction. Certifying ISO 27001 first therefore unlocks revenue sooner, and it builds the management system spine that makes the ISO 42001 programme cheaper.

    The exception is the organisation where AI is the product rather than a feature. If the entire commercial proposition is an AI system, and the questions arriving from buyers and investors are specifically about model governance rather than data security, ISO 42001 first can be defensible. It is a harder build without the ISMS spine, and the timeline reflects that.

    The third case is regulatory. An organisation placing high-risk AI systems on the EU market has obligations under the EU AI Act that no amount of ISO 27001 addresses. Where that is the driver, ISO 42001 sequencing follows the regulatory timetable rather than commercial preference.

    Running both as one management system

    Where both are required, the efficient structure is a single integrated management system with two certification scopes rather than two parallel systems.

    One policy framework with AI-specific policies layered in. One risk methodology with an AI risk taxonomy extending it. One internal audit programme covering both scopes. One management review agenda. One set of documented information controls.

    The alternative, two disconnected programmes, produces duplicate policy sets in different formats, two risk registers with different methodologies, and an integration debt that surfaces at surveillance audit when the two systems have drifted apart. It also costs substantially more.

    The practitioner test for whether an integrated system is working: can you trace a single AI system from the inventory, through the risk register, to the controls that treat its risks, to the evidence those controls operate, and to the management review where residual risk was accepted. If that trace breaks at any point, the integration is nominal rather than real.

    If you are weighing ISO 27001 and ISO 42001 and want to establish which sequence fits your commercial and regulatory position, a readiness assessment establishes where you stand against either standard before you commit to a programme. Book a scoping call.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    ISO 42001

    7 min read

    What ISO 42001 Costs in the UK

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    Four different costs with four different owners, and only two of them are published by anyone. How to separate them, and the two variables that actually move your total.

    • ISO 42001
    • Pricing
    • Certification
    • AI Governance
    ISO 42001

    8 min read

    Can the Consultancy That Built Your AIMS Also Audit It?

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.

    • ISO 42001
    • Internal Audit
    • Certification
    • AI Governance
    AI Governance

    12 min read

    ISO 42001 and the EU AI Act: What the Standard Covers and What It Does Not

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    Where ISO 42001 supports EU AI Act readiness, which obligations the standard does not reach, and how to sequence a compliance programme against the enforcement timetable.

    • AI Governance
    • ISO 42001
    • EU AI Act
    ISO 42001

    9 min read

    Why a GRC Platform Is Not an AI Management System

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    What compliance platforms do well for ISO 42001, what they cannot do, and where the practitioner work actually sits.

    • ISO 42001
    • AI Governance
    • GRC
    AI Governance

    9 min read

    ISO 42001 vs NIST AI RMF: Which AI Governance Framework Your Buyers Actually Want

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    A certifiable international standard and a voluntary US framework. What each covers, which buyers recognise which, and when holding both makes sense.

    • AI Governance
    • ISO 42001
    • NIST AI RMF
    AI Governance

    10 min read

    ISO 42001 for UK Financial Services: FCA Expectations, Consumer Duty, and Automated Decisioning

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    How FCA-regulated firms are being asked about AI governance, where Consumer Duty and SM&CR create accountability exposure, and what ISO 42001 evidences. From £2,500.

    • ISO 42001
    • AI Governance
    • Financial Services

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.