/

  / ISO 9001:2026 Changes: What’s New and How to Transition

ISO 9001:2026 Changes: What’s New and How to Transition

ISO published ISO 9001:2026 on September 16, 2026, and the 2015 edition is now formally withdrawn. If you hold a certificate, the good news is that the structure and the process approach are the same, and the list of new requirements is short. Top management now has to promote a quality culture and ethical behavior. Risks and opportunities get handled separately, change management carries more weight, and the 2024 climate change amendment sits inside the core text.

That’s most of it. Below, we go through each change clause by clause, cover what stayed where it was, set out the transition timeline, and list the work a certified company has to do before the deadline.

Key Takeaways

  • ISO 9001:2026 is the sixth edition of the standard and replaces ISO 9001:2015. Most of the new text is guidance, and only a small part of it adds requirements.
  • The changes that carry audit weight are in Clause 5.1 (quality culture and ethical behavior), Clause 6.1 (risks and opportunities addressed separately), and Clause 6.3 (planning of changes).
  • ISO 9001:2015 certificates stay valid during the transition period, which is expected to run for three years, until around September 2029. Your certification body confirms the exact date.
  • Certification bodies need their own accreditation to the new edition before they can issue 2026 certificates, so nobody has to panic this quarter.
  • A healthy 2015 system needs a gap analysis, some document updates, and better leadership evidence. You won’t have to rebuild it.

ISO 9001:2026 Is Now Published: Where the Revision Stands

On September 16, 2026, ISO announced the publication of ISO 9001:2026. ISO describes the edition as a set of targeted updates that make the standard clearer and easier to use, built on the framework more than one million organizations already work with. The official ISO 9001:2026 standard page is live. ISO’s page for ISO 9001:2015 now marks that edition as withdrawn and tells certified organizations to speak to their certification body about transition arrangements.

It took longer to get here than planned. ISO’s quality committee first voted to leave the 2015 edition alone, then changed its mind in August 2023 after wider consultation. The Draft International Standard followed in August 2025, the final draft went to ballot in spring 2026, and publication hit the September target.

Two companion documents came out earlier in the year. ISO 9000:2026, the fundamentals and vocabulary standard, was published in May 2026, and ISO 19011:2026, the auditing guideline, was updated around the same time. If your internal audit procedure cites either one by year, add it to the update list.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

Why ISO 9001:2015 Was Revised

Eleven years is a long time for a management standard. Since 2015, supply chains have become more fragile, remote, and hybrid work has changed how processes run, and customers ask harder questions about ethics and data integrity than they used to. ISO reviews its standards on a regular cycle, and in 2023 the consensus was that a revision would be worth the effort.

According to ISO/TC 176/SC 2, the subcommittee responsible for ISO 9001, 81 experts from 46 countries and liaison bodies took part. The result is still conservative, and that was a choice. A standard with a million-plus users can’t afford a rewrite every decade, so the committee went for clarification.

ISO 9001:2026 vs ISO 9001:2015: Summary of Changes

AreaISO 9001:2015ISO 9001:2026
StructureAnnex SL high-level structure, Clauses 4 to 10Same clause layout, updated to the latest Harmonized Structure
Clause 3, termsPoints entirely to ISO 9000Includes a limited set of core terms; ISO 9000:2026 remains the normative reference
Climate changeAdded by Amendment 1 in 2024Built into Clauses 4.1 and 4.2
Leadership (5.1)Commitment to the QMS and customer focusAdds promotion of quality culture and ethical behavior
Risks and opportunities (6.1)Addressed togetherAddressed separately, with distinct actions for each
Planning of changes (6.3)Brief requirementReinforced to protect intended results
Annex AShort clarification of structure and termsExpanded guidance on the intent of requirements, informative only
Annex BListed other ISO/TC 176 standardsRemoved; references moved to Annex A and the committee website

Key Changes in ISO 9001:2026, Clause by Clause

Clause 3: Core Terms Now Sit Inside the Standard

The 2015 edition sent readers to ISO 9000 for every definition. The 2026 edition brings a limited number of core management system terms into Clause 3 itself, and ISO 9000:2026 remains the normative reference for the full vocabulary. There’s nothing to set up here. Just check that your quality manual and procedures don’t cite definitions by their old source or year.

Clause 4: The Climate Change Amendment Is Now Core Text

In February 2024, ISO amended every major management system standard. Organizations had to determine whether climate change is a relevant issue (4.1) and whether interested parties have related requirements (4.2). That amendment took effect immediately, with no transition period, and ISO 9001:2026 folds the same text into the body of the standard.

If you handled the amendment properly in 2024, you have nothing new to do. If you wrote “not applicable” on a sticky note, go back to it, because auditors will now read this as a standing requirement. Not relevant is a perfectly acceptable conclusion for many businesses, as long as there’s a reason written down behind it.

Clause 5.1: Quality Culture and Ethical Behavior Become Leadership Duties

This is the change everyone is talking about, and it’s the hardest one to evidence. Top management now has to show leadership by promoting a quality culture and ethical behavior. The same themes turn up in the requirements for awareness (7.3) and the environment for the operation of processes (7.1.4).

You don’t need a culture program for this, and you don’t strictly need a new code of conduct, although one helps. What the auditor wants is for top management to show what they do day to day. Management review minutes where quality problems get discussed without blame are good evidence. So is a working route for staff to raise concerns. Auditors will interview leaders on this, and a scripted answer is usually obvious within two questions.

Important: A signed ethics policy on the wall is not evidence of promotion. Auditors test this clause through interviews and behavior, so brief top management before the transition audit the same way you’d brief them on customer focus.

Clause 6.1: Risks and Opportunities Are Addressed Separately

The 2015 edition treated risks and opportunities as one phrase, and most companies responded with a risk register that had an empty “opportunities” tab. The 2026 edition draws a clearer line between the two and expects you to consider the actions for each one separately.

Risk-based thinking itself hasn’t changed. The practical difference is that you can no longer treat an opportunity as the mirror image of a risk. A new market or a process automation deserves its own evaluation and its own planned actions. For most registers, that’s a restructuring job you can finish in a few hours.

Clause 6.3: Management of Change Gets Reinforced

Planning of changes was the thinnest clause in the 2015 edition, and companies treated it that way. The new edition strengthens it. You now have to plan changes to the quality management system in a way that protects what the system is meant to achieve.

In our experience, this is where 2015-era systems are weakest. Companies migrate ticketing tools, restructure teams, swap a main supplier, or move a process offshore, and the QMS hears about it at the next internal audit. If you run a software or services business, expect this clause to produce more transition findings than the ethics requirement. A lightweight change record that covers purpose, consequences, resources, and responsibilities is usually enough to close it.

Annex A Expands and Annex B Disappears

Annex A is much longer now and explains the structure, terminology, and intent behind the requirements. It’s informative, which means it adds no requirements and an auditor can’t raise a nonconformity against it. It’s still the best place to find out what the committee meant by “quality culture” before your auditor tells you.

Annex B, which listed other standards from the ISO 9000 family, is gone. Those references now live in Annex A and on the ISO/TC 176 website. SGS and other certification bodies also point to smaller clarifications around organizational knowledge and continual improvement, so read Clauses 7.1.6 and 10 in your own copy of the standard before you close your gap analysis.

Pro Tip: Read the Standard, Not Just the Summary

Buy the standard and compare Clauses 4 to 10 line by line yourself. Summaries, including this one, tell you where to look. Only the published text tells you what your auditor will hold you to.

What Is Not Changing in ISO 9001:2026

The Harmonized Structure and the Process Approach Stay Put

Clauses 4 to 10 keep their order and numbering. The process approach, the PDCA cycle, risk-based thinking, customer focus, documented information, internal audit, and management review all work the way they did, and the seven quality management principles still sit underneath. Your process maps, your procedures, and nearly all of your records carry across untouched.

The standard adopts the latest version of ISO’s Harmonized Structure, which keeps it in step with ISO 14001:2026, ISO 45001, and ISO/IEC 27001. If you run an integrated management system, that’s the most useful part of the revision.

Predicted Changes That Did Not Make the Final Standard

A lot of pre-publication commentary promised more than the committee delivered. Articles written during the draft stages forecast dedicated requirements for artificial intelligence, digital transformation, Industry 4.0, sustainability reporting, and a rewritten stakeholder engagement clause. The published edition has no standalone clause on any of them.

Technology and resilience do appear, but only as context and guidance, so there’s nothing new there for an auditor to test. Some quality professionals are disappointed, and that’s a fair reaction. For a certified company it means a smaller transition bill. It also means you can ignore any vendor who tells you ISO 9001:2026 requires an AI governance framework. ISO/IEC 42001 covers that, and it’s a separate certification.

Worth Knowing: Check the Date: Draft vs. Final Standard

Much of what still ranks on search engines for this topic was written against the 2025 draft or earlier committee drafts. If an article talks about “expected” or “anticipated” changes, check its date before you act on it.

ISO 9001:2026 Transition Timeline

Transition Period and Deadline for ISO 9001:2015 Certificates

Your ISO 9001:2015 certificate didn’t expire on publication day. Certificates stay valid through a transition period governed by the International Accreditation Forum (IAF), whose work is moving under the Global Accreditation Cooperation created with ILAC. Recent major revisions of management system standards have used a three-year window. That includes the 2015 edition, whose transition closed in September 2018.

Going by that precedent, most certification bodies are working to a deadline around September 2029. Treat that as a planning date and get the binding one in writing from your certification body. The deadline applies to the certification decision, so the audit itself has to happen months earlier to leave room for closing nonconformities.

When Certification Bodies Can Start Auditing to ISO 9001:2026

Certification bodies can’t issue accredited 2026 certificates on day one. They first have to train their auditors and get their own accreditation extended by a national accreditation body such as UKAS or ANAB. After the 2015 revision, that took most certification bodies several months, and it’ll likely be similar this time.

So your next surveillance audit will probably still run against the 2015 edition. For most companies, the realistic slot is a surveillance or recertification visit in 2027 or 2028. Try not to leave it to 2029. Auditor calendars filled up badly in the final months of the last transition, and the late movers ended up with awkward audit dates and rushed corrective actions.

How to Prepare Your QMS for the ISO 9001:2026 Changes

Run a Gap Analysis Against the New Requirements

Start with a clause-by-clause comparison focused on 4.1, 4.2, 5.1, 6.1, 6.3, 7.1.4, and 7.3. If your system is in good shape, this takes a few days. Outside help with an ISO 9001 gap analysis and certification support engagement makes sense when the quality manager is also the operations manager, which in smaller companies is often the case.

Update Documented Information

Expect to touch the risk and opportunity register, the change management procedure, the context and interested parties analysis, awareness and induction material, and any document that cites “ISO 9001:2015” by name. Don’t rewrite the manual for the sake of it. If a document already meets the new text, record that in the gap analysis and move on.

Brief Top Management and Retrain Internal Auditors

Leadership needs a one-hour briefing on what quality culture and ethical behavior mean in audit terms and what the auditor will ask them. Internal auditors need transition training and an updated checklist, ideally one that references ISO 19011:2026. This step always takes longer than planned, because it depends on executive calendars.

Cover the Changes in Internal Audit and Management Review

Run at least one full internal audit cycle against the 2026 requirements before the transition audit. Put the transition on the management review agenda too, and record the outputs. Certification bodies look for both, and turning up to a transition audit without them is the easiest way to pick up a major finding you could have avoided.

Schedule the Transition Audit With Your Certification Body

Ask your certification body three things now: when they expect to be accredited, whether they’ll combine the transition with a scheduled surveillance visit, and how much audit time they’ll add. Extra audit time is the main direct cost of transitioning. You’ll also pay for a copy of the standard, training, and any outside support you bring in. For a healthy system, the internal effort usually comes to four to eight weeks of part-time work.

Not Yet Certified? What the Changes Mean for New Implementations

Don’t wait. Until your chosen certification body is accredited for the 2026 edition, the 2015 edition is what they can certify, and a certificate issued under it stays valid through the transition period. Tenders don’t pause for standards committees, and buyers asking for ISO 9001 certification in Saudi Arabia or anywhere else in the GCC want a certificate now.

The sensible approach is to build the system against the 2026 text from the start and certify to whichever edition your certification body can offer on audit day. In practice, the new edition covers everything the old one did, so a system built this way passes either audit. If you’re still scoping the work, our breakdown of ISO 9001 certification requirements covers the ground this article skips.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

How the Changes Affect Integrated Management Systems and Sector Standards

Companies that run ISO 9001 alongside ISO/IEC 27001 or ISO 14001 have the easiest transition. Because the standards share the Harmonized Structure, you can update context, leadership, risk planning, change planning, internal audit, and management review once and apply the result across all of them. ISO 14001:2026 also came out this year with its own reinforced change clause, so handle both transitions in one pass. Axipro builds unified programs across multiple compliance frameworks for this reason, because integrated systems waste most of their money on duplicated audits and duplicated documents.

Sector standards built on ISO 9001 move on their own clocks. IATF 16949 for automotive, AS9100 for aerospace, and ISO 13485 for medical devices each need their own revision or alignment decision from their governing bodies. If you hold one of these, your sector scheme owner’s guidance outranks anything in this article.

Insider Note: For integrated systems, ask your certification body to put the ISO 9001 and ISO 14001 transitions into the same audit visit. That way you only sit through one leadership interview and one management review. If you do them twelve months apart, you double the disruption and get nothing extra for it.

Conclusion

ISO 9001:2026 is a modest revision with three changes that matter in an audit. Leadership has to promote quality culture and ethical behavior, risks and opportunities are handled separately, and you have to plan changes to the system properly. Climate change is now core text, Annex A is more useful, and the structure you know is intact. The transition window is expected to run to around September 2029, so there’s time to do this calmly, and a gap analysis in the next few months will show you how much work you really have. Axipro has taken 200+ clients through certification with a 100% audit success rate, and the ones who start early have the easiest audits.

Frequently Asked Questions

What are the main changes in ISO 9001:2026?

Top management must promote a quality culture and ethical behavior (5.1), risks and opportunities are addressed separately (6.1), and planning of changes is reinforced (6.3). The 2024 climate change amendment is now part of Clauses 4.1 and 4.2, Clause 3 includes core terms, Annex A is longer, and Annex B is gone. The clause structure and the process approach haven’t changed.

Yes. ISO has withdrawn the 2015 edition as a standard, but existing accredited certificates stay valid during the transition period. That period is expected to last three years, to around September 2029. Confirm the binding deadline with your certification body.

For a well-maintained system, plan for a few days of gap analysis and roughly four to eight weeks of part-time work on documents, training, internal audit, and management review. The audit itself is usually combined with a surveillance or recertification visit. A system that’s been neglected since the last recertification will take longer, mostly because of the backlog.

The direct costs are a copy of the standard, the extra audit time your certification body charges, and training for internal auditors. Outside support for the gap analysis and remediation is optional and depends on how much capacity you have in-house. Ask your certification body for the added audit time in writing, because it varies with company size and with whether the transition is combined with a scheduled visit.

No. Certification bodies have to be accredited to the new edition before they can issue 2026 certificates, and that takes time. Build your system against the 2026 text, certify to the edition your certification body can offer, and transition later if you need to. Waiting only delays the tenders and contracts the certificate unlocks.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

ISO published ISO 9001:2026 on September 16, 2026, and the 2015 edition is now formally withdrawn. If you hold a certificate, the good news is that the structure and the process approach are the same, and the list of new requirements is short. Top management now has to promote a quality culture and ethical behavior. Risks and opportunities get handled separately, change management carries more weight, and the 2024 climate change amendment sits inside the core text. That’s most of it. Below, we go through each change clause by clause, cover what stayed where it was, set out the transition timeline, and list the work a certified company has to do before the deadline. Key Takeaways ISO 9001:2026 is the sixth edition of the standard and replaces ISO 9001:2015. Most of the new text is guidance, and only a small part of it adds requirements. The changes that carry audit weight are in Clause 5.1 (quality culture and ethical behavior), Clause 6.1 (risks and opportunities addressed separately), and Clause 6.3 (planning of changes). ISO 9001:2015 certificates stay valid during the transition period, which is expected to run for three years, until around September 2029. Your certification body confirms the exact date. Certification bodies need their own accreditation to the new edition before they can issue 2026 certificates, so nobody has to panic this quarter. A healthy 2015 system needs a gap analysis, some document updates, and better leadership evidence. You won’t have to rebuild it. ISO 9001:2026 Is Now Published: Where the Revision Stands On September 16, 2026, ISO announced the publication of ISO 9001:2026. ISO describes the edition as a set of targeted updates that make the standard clearer and easier to use, built on the framework more than one million organizations already work with. The official ISO 9001:2026 standard page is live. ISO’s page for ISO 9001:2015 now marks that edition as withdrawn and tells certified organizations to speak to their certification body about transition arrangements. It took longer to get here than planned. ISO’s quality committee first voted to leave the 2015 edition alone, then changed its mind in August 2023 after wider consultation. The Draft International Standard followed in August 2025, the final draft went to ballot in spring 2026, and publication hit the September target. Two companion documents came out earlier in the year. ISO 9000:2026, the fundamentals and vocabulary standard, was published in May 2026, and ISO 19011:2026, the auditing guideline, was updated around the same time. If your internal audit procedure cites either one by year, add it to the update list. Why ISO 9001:2015 Was Revised Eleven years is a long time for a management standard. Since 2015, supply chains have become more fragile, remote, and hybrid work has changed how processes run, and customers ask harder questions about ethics and data integrity than they used to. ISO reviews its standards on a regular cycle, and in 2023 the consensus was that a revision would be worth the effort. According to ISO/TC 176/SC 2, the subcommittee responsible for ISO 9001, 81 experts from 46 countries and liaison bodies took part. The result is still conservative, and that was a choice. A standard with a million-plus users can’t afford a rewrite every decade, so the committee went for clarification. ISO 9001:2026 vs ISO 9001:2015: Summary of Changes Area ISO 9001:2015 ISO 9001:2026 Structure Annex SL high-level structure, Clauses 4 to 10 Same clause layout, updated to the latest Harmonized Structure Clause 3, terms Points entirely to ISO 9000 Includes a limited set of core terms; ISO 9000:2026 remains the normative reference Climate change Added by Amendment 1 in 2024 Built into Clauses 4.1 and 4.2 Leadership (5.1) Commitment to the QMS and customer focus Adds promotion of quality culture and ethical behavior Risks and opportunities (6.1) Addressed together Addressed separately, with distinct actions for each Planning of changes (6.3) Brief requirement Reinforced to protect intended results Annex A Short clarification of structure and terms Expanded guidance on the intent of requirements, informative only Annex B Listed other ISO/TC 176 standards Removed; references moved to Annex A and the committee website Key Changes in ISO 9001:2026, Clause by Clause Clause 3: Core Terms Now Sit Inside the Standard The 2015 edition sent readers to ISO 9000 for every definition. The 2026 edition brings a limited number of core management system terms into Clause 3 itself, and ISO 9000:2026 remains the normative reference for the full vocabulary. There’s nothing to set up here. Just check that your quality manual and procedures don’t cite definitions by their old source or year. Clause 4: The Climate Change Amendment Is Now Core Text In February 2024, ISO amended every major management system standard. Organizations had to determine whether climate change is a relevant issue (4.1) and whether interested parties have related requirements (4.2). That amendment took effect immediately, with no transition period, and ISO 9001:2026 folds the same text into the body of the standard. If you handled the amendment properly in 2024, you have nothing new to do. If you wrote “not applicable” on a sticky note, go back to it, because auditors will now read this as a standing requirement. Not relevant is a perfectly acceptable conclusion for many businesses, as long as there’s a reason written down behind it. Clause 5.1: Quality Culture and Ethical Behavior Become Leadership Duties This is the change everyone is talking about, and it’s the hardest one to evidence. Top management now has to show leadership by promoting a quality culture and ethical behavior. The same themes turn up in the requirements for awareness (7.3) and the environment for the operation of processes (7.1.4). You don’t need a culture program for this, and you don’t strictly need a new code of conduct, although one helps. What the auditor wants is for top management to show what they do day to day. Management review minutes where quality problems get discussed without blame are good evidence. So is a working route

An AI agent reads a customer record, decides a refund is warranted, and calls the payments API. The trail it leaves looks nothing like a human doing the same job. The log says a user logged in, a service account made three API calls, and the transaction cleared. It doesn’t say why the agent decided on a refund, what it read first, which model version did the reasoning, or who gave the agent permission to act in the first place. That missing “why” is the whole audit problem. This article covers what ISO/IEC 42001:2023 and the SOC 2 Trust Services Criteria expect from AI agent audit logs, where the two overlap, the fields a log needs to satisfy both, how long to keep records, what you shouldn’t record, and how to package it all for an auditor. It’s written for the CTO, platform lead, or founder who owns compliance for a product that now ships with autonomous agents and needs a certification and a Type II report without running two separate logging programs. The Compliance Gap: Traditional Application Logs vs. AI Agent Audit Logs Why Standard Logs Fall Short for Autonomous Agents Application logs were built for deterministic software. Same input, same state, same output, so recording the input, the state change, and the result is enough to reconstruct what happened. A SOC 2 auditor sampling access logs can trace a database write back to a login, a role, and a change ticket without much effort. Agents break that chain in a few places. They usually run under a shared service account or a borrowed OAuth token, so the log pins the action to a machine identity with no link to the human who set the task. The action itself was picked at runtime by a model rather than fixed in code, so there’s no source line to point at. The same prompt can produce a different tool call tomorrow, so a single sampled log entry proves almost nothing about how the system behaves in general. The Shift from Deterministic State Logging to Intent and Reasoning Capture Traditional logs answer “what changed.” Agent audit logs also have to answer “what was the agent trying to do, what did it consider, and what held it back.” That means capturing the task as delegated, the context the model was handed, the reasoning or planning steps it produced, the tools it picked and the arguments it passed, and every point where a guardrail stepped in. The unit of audit moves from the event to the decision, and each decision needs enough surrounding context that a reviewer can judge whether it was reasonable. Unique Audit Challenges of Non-Deterministic AI Behavior Non-determinism is the part auditors struggle with most. In a normal control test, the auditor re-performs the control and expects the same result. Re-run the same input through an agent and you may get a different path. The practical answer is to stop trying to prove that any single output was correct and instead prove that every output was recorded, attributed, bounded by policy, and reviewable. Logs show that the management system works. They don’t show the model is infallible, and nobody expects them to. ISO 42001 accepts this framing outright. SOC 2 auditors are still catching up, and you’ll spend some time educating them. Insider Note: Auditors don’t expect you to explain the model’s weights. They expect you to show that when the agent did something unexpected, you could find it, see what it read, see what it did, and see who was accountable. Frame every logging decision around that reconstruction test. What ISO 42001 Requires for AI Agent Audit Logs ISO/IEC 42001:2023 is the certifiable standard for an AI Management System (AIMS). It follows the same Plan-Do-Check-Act structure as ISO 27001 and comes with 38 Annex A controls. The phrase “audit log” barely appears in it, but logging obligations run through the main clauses and at least three Annex A areas. Our ISO 42001 certification services map these to your existing controls where possible. Clause 8: Operational Logging and Documentation Requirements Clause 8 asks you to plan, run, and control the processes needed to meet your AI requirements, and to keep documented information showing those processes ran as planned. For an agent in production, the process is the runtime behavior, so documented evidence means logs of the agent operating, not a procedure document on its own. Clause 8.4 adds an AI system impact assessment whose results you have to retain. When an agent’s scope or toolset changes, the record of that change and the updated assessment are both Clause 8 evidence. Clause 9: Performance Evaluation and Evidence of Monitoring Clause 9.1 asks you to decide what to monitor and measure, how, and when, and to keep evidence of the results. An auditor will want the monitoring you defined for each agent (error rates, guardrail block rates, tool-call anomalies, how often humans override) and the records showing you reviewed it. Clause 9.2 internal audit and 9.3 management review both feed off those records. Without operational logs, there’s nothing to measure, and Clause 9 falls over. Annex A.6: AI System Lifecycle Logging Obligations Annex A.6 is where logging gets explicit. A.6.2.8, AI system recording of event logs, requires you to decide at which phases of the AI system lifecycle event logging is switched on, and the Annex B guidance ties this to traceability and anomaly detection. A.6.2.6, AI system operation and monitoring, requires ongoing monitoring in operation, including AI-specific threats like data poisoning and model theft. Read together, they mean logging can’t start at go-live. Design decisions, validation runs, deployment configs, and production behavior all need a record. Annex A.9: Logging Requirements for AI System Operation Annex A.9 covers responsible use: processes for responsible use (A.9.2), objectives for it (A.9.3), and intended use (A.9.4). The logging consequence is that you need to show the agent stayed inside its intended use. That takes logs of the tasks it was given, the actions it took,

Most people asking this question fall into one of two camps. Either they already hold ISO 27001 and just shipped an AI feature, or they run an AI-native company and an enterprise buyer has asked for “your AI governance certification.” The answer is the same for both camps: ISO 27001 secures your information and ISO 42001 governs your AI. Neither certificate covers the other. If AI is part of what you sell or how you make decisions, you’ll need both. If it’s just a productivity tool humming away in the background, ISO 27001 on its own is still fine. Below: what each standard governs, where they overlap, what your existing ISMS doesn’t say about AI, how to decide, and how to run both as one management system rather than two. The Short Answer: When You Need Both (and When You Don’t) You need both when AI is part of your product or part of a decision that affects people, and a customer, regulator, or board could reasonably ask how you govern it. That covers most SaaS companies with a generative feature, every AI-native vendor, and any firm using AI to screen candidates, score credit, or make health or safety calls. ISO 27001 alone is enough when your AI use is internal and low-stakes. Coding assistants, drafting tools, a chatbot answering FAQs from public docs. Your ISMS already covers the data those tools see, and nobody is asking you for an AI management system. ISO 42001 on its own is a rare choice, and usually a bad one. The standard assumes there’s a working security baseline underneath it. An AI governance certificate sitting on top of an unaudited security program raises more questions than it answers, so ISO 27001 comes first or at the same time. What ISO 27001 Covers vs What ISO 42001 Covers ISO 27001: Information Security Management System (ISMS) ISO/IEC 27001:2022 sets out the requirements for an Information Security Management System. The thing being protected is information. The risk being managed is losing its confidentiality, integrity, or availability. Annex A lists 93 controls across organizational, people, physical, and technological themes, and you explain which ones apply in a Statement of Applicability. The certificate tells customers you protect the data they systematically hand you. ISO 42001: AI Management System (AIMS) ISO/IEC 42001:2023 sets out the requirements for an Artificial Intelligence Management System. It’s the first certifiable standard for how an organization develops, provides, or uses AI. The thing being governed is the AI system across its whole lifecycle, and the risks go well past security: harm to people, bias, opacity, and a lack of human oversight. Annex A lists 38 controls under nine objectives, covering AI policy, impact assessment, lifecycle management, data governance, and third-party relationships. The certificate tells customers you can explain what your AI does, who’s accountable for it, and how you stop it from doing damage. ISO 42001 vs ISO 27001: The Key Differences   ISO 27001:2022 ISO 42001:2023 What it governs Information assets and the systems that process them AI systems across their lifecycle, whether built, bought, or used Core risk question Can this data be stolen, altered, or made unavailable? Can this AI system harm people, mislead them, or operate without accountability? Annex A controls 93 security controls in 4 themes 38 AI controls across 9 objectives Key assessment Information security risk assessment AI risk assessment plus AI system impact assessment Typical requester Every enterprise security review AI-focused questionnaires, regulated buyers, boards, EU AI Act mapping Maturity Established since 2005, revised 2022 First edition, December 2023; auditors accredited under ISO/IEC 42006 Scope: Information Assets vs AI Systems ISO 27001 draws its boundary around information and the infrastructure that handles it. ISO 42001 draws its boundary around AI systems and their use cases: a recommendation engine, a customer-facing agent, a hiring model, a third-party LLM embedded in your product. The same company can hold both certificates with different scopes. On a first certification cycle the AI scope is usually the narrower one. Risks Managed: Security Risk vs AI Impact and Ethical Risk An ISMS asks what happens if an attacker gets in. An AIMS also asks what happens when the system works exactly as designed and still produces a biased shortlist, a made-up policy answer, or a decision nobody can explain to the person it affected. Clause 6.1.4 of ISO 42001 requires an AI system impact assessment that looks at consequences for individuals and society. ISO 27001 has nothing like it. Controls: Annex A Security Controls vs Annex A AI Controls Roughly a third of ISO 42001’s Annex A maps onto something in ISO 27001. Supplier controls (A.10), data classification and handling (A.7), and roles and responsibilities (A.3) reuse work you’ve already done. The impact assessment group (A.5), most of the lifecycle group (A.6), and the transparency obligations to interested parties (A.8) have no ISO 27001 equivalent, and that’s where most of the new effort goes. Who Asks for Each Certificate Procurement teams ask for ISO 27001 or SOC 2 by default. ISO 42001 comes up when a buyer’s vendor questionnaire has grown an AI section: does a human review high-stakes outputs, do you track which third-party models touch customer data, have you run an impact assessment? A 42001 certificate answers most of that before the security call even starts. Boards and regulators in the EU and the Gulf are the other main source of demand. Worth Knowing: Both standards use ISO’s Harmonized Structure Both standards use ISO’s Harmonized Structure, so clauses 4 through 10 (context, leadership, planning, support, operation, performance evaluation, improvement) share the same numbering and mostly the same wording. An auditor moving between them sees the same management-system skeleton with a different set of risks and controls hung on it. Where ISO 42001 and ISO 27001 Overlap The Shared Harmonized Structure (Clauses 4 to 10) The management-system machinery carries over almost untouched. Document control, competence records, the internal audit program, management review, corrective action, and the way you plan for risks