Most people asking this question fall into one of two camps. Either they already hold ISO 27001 and just shipped an AI feature, or they run an AI-native company and an enterprise buyer has asked for “your AI governance certification.” The answer is the same for both camps: ISO 27001 secures your information and ISO 42001 governs your AI. Neither certificate covers the other. If AI is part of what you sell or how you make decisions, you’ll need both. If it’s just a productivity tool humming away in the background, ISO 27001 on its own is still fine.
Below: what each standard governs, where they overlap, what your existing ISMS doesn’t say about AI, how to decide, and how to run both as one management system rather than two.
The Short Answer: When You Need Both (and When You Don’t)
You need both when AI is part of your product or part of a decision that affects people, and a customer, regulator, or board could reasonably ask how you govern it. That covers most SaaS companies with a generative feature, every AI-native vendor, and any firm using AI to screen candidates, score credit, or make health or safety calls.
ISO 27001 alone is enough when your AI use is internal and low-stakes. Coding assistants, drafting tools, a chatbot answering FAQs from public docs. Your ISMS already covers the data those tools see, and nobody is asking you for an AI management system.
ISO 42001 on its own is a rare choice, and usually a bad one. The standard assumes there’s a working security baseline underneath it. An AI governance certificate sitting on top of an unaudited security program raises more questions than it answers, so ISO 27001 comes first or at the same time.
What ISO 27001 Covers vs What ISO 42001 Covers
ISO 27001: Information Security Management System (ISMS)
ISO/IEC 27001:2022 sets out the requirements for an Information Security Management System. The thing being protected is information. The risk being managed is losing its confidentiality, integrity, or availability. Annex A lists 93 controls across organizational, people, physical, and technological themes, and you explain which ones apply in a Statement of Applicability. The certificate tells customers you protect the data they systematically hand you.
ISO 42001: AI Management System (AIMS)
ISO/IEC 42001:2023 sets out the requirements for an Artificial Intelligence Management System. It’s the first certifiable standard for how an organization develops, provides, or uses AI. The thing being governed is the AI system across its whole lifecycle, and the risks go well past security: harm to people, bias, opacity, and a lack of human oversight. Annex A lists 38 controls under nine objectives, covering AI policy, impact assessment, lifecycle management, data governance, and third-party relationships. The certificate tells customers you can explain what your AI does, who’s accountable for it, and how you stop it from doing damage.
Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.
Schedule Your Free Assessment Today
ISO 42001 vs ISO 27001: The Key Differences
| ISO 27001:2022 | ISO 42001:2023 | |
|---|---|---|
| What it governs | Information assets and the systems that process them | AI systems across their lifecycle, whether built, bought, or used |
| Core risk question | Can this data be stolen, altered, or made unavailable? | Can this AI system harm people, mislead them, or operate without accountability? |
| Annex A controls | 93 security controls in 4 themes | 38 AI controls across 9 objectives |
| Key assessment | Information security risk assessment | AI risk assessment plus AI system impact assessment |
| Typical requester | Every enterprise security review | AI-focused questionnaires, regulated buyers, boards, EU AI Act mapping |
| Maturity | Established since 2005, revised 2022 | First edition, December 2023; auditors accredited under ISO/IEC 42006 |
Scope: Information Assets vs AI Systems
ISO 27001 draws its boundary around information and the infrastructure that handles it. ISO 42001 draws its boundary around AI systems and their use cases: a recommendation engine, a customer-facing agent, a hiring model, a third-party LLM embedded in your product. The same company can hold both certificates with different scopes. On a first certification cycle the AI scope is usually the narrower one.
Risks Managed: Security Risk vs AI Impact and Ethical Risk
An ISMS asks what happens if an attacker gets in. An AIMS also asks what happens when the system works exactly as designed and still produces a biased shortlist, a made-up policy answer, or a decision nobody can explain to the person it affected. Clause 6.1.4 of ISO 42001 requires an AI system impact assessment that looks at consequences for individuals and society. ISO 27001 has nothing like it.
Controls: Annex A Security Controls vs Annex A AI Controls
Roughly a third of ISO 42001’s Annex A maps onto something in ISO 27001. Supplier controls (A.10), data classification and handling (A.7), and roles and responsibilities (A.3) reuse work you’ve already done. The impact assessment group (A.5), most of the lifecycle group (A.6), and the transparency obligations to interested parties (A.8) have no ISO 27001 equivalent, and that’s where most of the new effort goes.
Who Asks for Each Certificate
Procurement teams ask for ISO 27001 or SOC 2 by default. ISO 42001 comes up when a buyer’s vendor questionnaire has grown an AI section: does a human review high-stakes outputs, do you track which third-party models touch customer data, have you run an impact assessment? A 42001 certificate answers most of that before the security call even starts. Boards and regulators in the EU and the Gulf are the other main source of demand.
Worth Knowing: Both standards use ISO’s Harmonized Structure
Both standards use ISO’s Harmonized Structure, so clauses 4 through 10 (context, leadership, planning, support, operation, performance evaluation, improvement) share the same numbering and mostly the same wording. An auditor moving between them sees the same management-system skeleton with a different set of risks and controls hung on it.
Where ISO 42001 and ISO 27001 Overlap
The Shared Harmonized Structure (Clauses 4 to 10)
The management-system machinery carries over almost untouched. Document control, competence records, the internal audit program, management review, corrective action, and the way you plan for risks and opportunities all serve both standards. A company with a working ISMS usually walks into an ISO 42001 gap analysis already meeting most clause-level requirements on paper. The job is extending them to AI, not rebuilding them.
Reusable Policies, Risk Processes and Evidence
Your information security policy becomes the parent of an AI policy. Your risk methodology picks up AI-specific risk sources and an impact assessment step. Supplier due diligence gains questions about model providers and training data. Access control, logging, change management, and incident response evidence all carry over wherever AI systems run on the same infrastructure, which for most SaaS companies means everywhere.
Does ISO 27001 Already Cover Your AI Systems?
Partly. The part it misses is the part buyers ask about.
What Your Existing Statement of Applicability Doesn’t Address
Your ISO 27001 SoA answers whether the servers running your model are patched, whether access to training data is restricted, and whether the vendor hosting your LLM has been assessed. It doesn’t answer whether the model’s outputs are monitored for drift or bias, whether affected users are told an AI made the decision, whether a human can override it, or whether anyone assessed the impact on the people it affects before it went live. Those are the questions ISO 42001 exists to make you write down.
Why the Gap Is Bigger Than It Looks on Paper
On a clause-mapping spreadsheet, ISO 42001 looks like a 30 percent delta on top of ISO 27001. In practice, that 30 percent is the hard part. Building an AI inventory, running impact assessments on each system, defining human oversight for high-stakes outputs, and documenting training-data provenance are new organizational habits rather than new documents, and they pull in product and data science teams who’ve never been anywhere near an audit. The reuse is real, but it front-loads the easy work and leaves the unfamiliar work for last.
Insider Note: The nonconformity we see most often in first-time ISO 42001 audits at companies that already hold ISO 27001 is an AI inventory that only lists the models the company built. Auditors expect every AI system in scope, including the third-party LLM behind a support chatbot and the SaaS tools with AI features that touch customer data. ISO 27001 teams are used to inventorying things they own. ISO 42001 asks them to inventory things they merely use.
Do You Need ISO 42001 If You Already Have ISO 27001?
You Need Both If…
AI is in your product or your decisions. You sell an AI-native product, embed a generative feature customers rely on, or use AI to make or shape decisions about people. You’re seeing AI sections in security questionnaires, deals are slowing down on AI governance questions, or you have EU customers who’ll need to trace their AI Act obligations through your supply chain. ISO 27001 keeps you in the procurement process. ISO 42001 gets you through it.
ISO 27001 Alone Is Enough If…
AI is a background tool with no external exposure. Your team uses coding assistants and drafting tools, nothing customer-facing runs on a model, and no decision about a person is automated. Add an acceptable-use policy for AI tools and a supplier assessment for the vendors behind them to your ISMS, then revisit the question the moment AI touches your product.
ISO 42001 Alone Is Enough If…
Almost never. Certification bodies will certify ISO 42001 standalone, and technically you can build an AIMS without an ISMS. But the AI controls lean on security controls only an ISMS provides, and no enterprise buyer accepts an AI governance certificate from a vendor who can’t show a security one. Starting from zero? Do ISO 27001 first, or both together.
Which Should You Certify First?
ISO 27001 first if you hold neither and revenue depends on enterprise deals. It opens more procurement doors, and it builds the management system ISO 42001 extends. Both together if you’re AI-native and buyers are already asking AI governance questions, because a combined implementation costs less than two sequential ones and the shared clauses only get built once. ISO 42001 next if you already hold ISO 27001. Companies with a mature ISMS routinely cut the 42001 timeline by 30 to 50 percent, since they’re extending a working system instead of building one. Our breakdown of how long ISO 42001 certification takes walks through the phases.
Pro Tip: Settle the ISO 42001
Settle the ISO 42001 scope before you settle the timeline. Certify the one or two AI systems buyers actually ask about, get the certificate, and widen scope at the first surveillance audit. The companies whose projects run past nine months are almost always the ones that tried to bring every AI use case into scope on the first pass.
How to Run ISO 42001 and ISO 27001 as One Integrated Management System
Mapping Controls Between the Two Standards
Start from your ISO 27001 SoA and build a single combined control set. Each ISO 42001 Annex A control gets one of three labels: fully covered by an existing ISO 27001 control, partly covered and needing an AI-specific extension, or new. Supplier, data handling, and roles controls land in the first two buckets. Impact assessment, lifecycle, and transparency controls land in the third. Keep one risk register with an AI risk-source category rather than two registers that disagree with each other by month three.
Combined Audits and Certification Cycles
One certification body can audit both standards in a single integrated audit, as long as it’s accredited for ISO 42001 under ISO/IEC 42006. The shared clauses get assessed once, and the two Annex A control sets are assessed separately. If you already hold ISO 27001, most bodies will bolt ISO 42001 on at your next surveillance or recertification audit, which puts both certificates on one three-year cycle. Check with your body before you plan around it, though. Plenty of ISO 27001 auditors haven’t added ISO 42001 accreditation yet.
Cost and Effort Savings of Integrating vs Certifying Separately
Integration saves money in three places: the management-system documentation gets written once, the internal audit and management review run once, and external audit days drop because the shared clauses are assessed together. With automation-supported fixed-fee delivery, Axipro delivers ISO 42001 readiness for around [$4,000 for companies under 50 employees and $5,500 above], with the GRC platform and accredited audit adding roughly [$4,000 to $7,000]. Our guide to ISO 42001 consulting cost explains why those numbers sit so far below the consulting quotes you may have seen. Certifying the two standards separately, with different consultants and auditors, typically costs 30 to 40 percent more and leaves you with two management systems that drift apart within a year.
Beyond ISO 42001: AIUC-1 for AI Agents
ISO 42001 governs the organization. It doesn’t test a specific AI agent for jailbreaks, data leakage, or unsafe tool use. That job belongs to AIUC-1, the first auditable standard written specifically for AI agents. It has 51 requirements across data and privacy, security, safety, reliability, accountability, and society. Auditors review operational controls once a year and re-run technical tests at least quarterly, and the standard is crosswalked to ISO 42001, NIST AI RMF, and the EU AI Act so you’re not doing the same work twice.
For most companies the stack now has three layers: ISO 27001 for the security baseline, ISO 42001 for the AI management system, and AIUC-1 for any customer-facing or tool-calling agent that enterprise buyers want independently tested. Axipro covers all three. Our AIUC-1 certification guide explains what the audit tests and who should go for it, and we’ve taken AI companies through combined ISO 27001, ISO 42001, and GDPR programs to certification in under three months.
Common Mistakes When Deciding Between ISO 42001 and ISO 27001
The most expensive misunderstanding is treating ISO 42001 as an upgrade that replaces ISO 27001. It’s an addition, and buyers will keep asking for the security certificate. Second is assuming ISO 42001 equals EU AI Act compliance. A certification body auditing under ISO/IEC 42006 doesn’t assess your obligations under the Act, and the certificate isn’t a conformity assessment. What it does give you is the management system the Act’s risk management, documentation, and human oversight articles assume you already have. After those two: scoping every AI use case into the first certification, running the AI risk assessment and the impact assessment in one spreadsheet, and letting the product team find out about the audit at Stage 2.
Important: ISO 42001 certification lasts three years with annual surveillance audits, the same as ISO 27001. If you’re adding it to an existing ISO 27001 cycle, ask whether the body will line up the expiry dates. Two certificates on offset cycles means two rounds of surveillance audits every year, which doubles the ongoing cost of holding both without anyone quite noticing.
Next Steps: Building One Program That Covers Both
ISO 27001 and ISO 42001 answer different questions, and if AI is in your product or your decisions, buyers will ask both. The efficient path is one integrated management system: reuse the ISMS clauses, extend the risk methodology to AI, add the impact assessments and lifecycle controls that have no security equivalent, and certify both with one body on one cycle. Axipro’s ISO 42001 certification services run that integrated program end to end, from gap analysis through guaranteed certification on the Achievement Plan, and our ISO 27001 certification services lay the foundation for companies starting from scratch. If you ship agents, AIUC-1 slots in as the third layer. Done well, it’s one program with three certificates at the end, not three separate projects.
Frequently Asked Questions
Can you get ISO 42001 without ISO 27001?
Yes. ISO 42001 stands on its own and certification bodies will certify it independently. Hardly anyone does, because the AI controls depend on security controls an ISMS provides and enterprise buyers expect the security certificate first. If you hold neither, plan on ISO 27001 first or both together.
Can ISO 27001 replace ISO 42001?
No. ISO 27001 governs information security. It doesn’t require an AI inventory, an AI system impact assessment, human oversight controls, or transparency toward people affected by AI decisions. You can extend an ISMS with AI policies, but you can’t certify it as an AI management system.
Do ISO 42001 and ISO 27001 share the same audit?
They can. A certification body accredited for both can run one integrated audit that covers the shared management-system clauses once and each Annex A control set separately. Ask your current ISO 27001 auditor whether they hold ISO/IEC 42006 accreditation before assuming they can add ISO 42001.
How much extra work is ISO 42001 if you already have ISO 27001?
Less than starting fresh, but more than a mapping exercise. Expect to reuse most of the clause 4 to 10 documentation and about a third of Annex A, and to build new AI inventories, impact assessments, lifecycle controls, and human oversight procedures. Companies with a mature ISMS typically reach ISO 42001 certification in three to six months instead of six to twelve.
Does having both standards make you compliant with the EU AI Act?
No. Neither certificate is a conformity assessment under the Act. Together they give you the management system, risk process, documentation, and oversight mechanisms the Act’s high-risk obligations assume exist, which shortens the mapping exercise a lot. But you still have to show compliance against the Act’s articles separately.