---
title: "ISO 42001 vs ISO 27001: Do You Need Both? Honest Answer"
description: "ISO 42001 vs ISO 27001: Compare scope, overlap, certification, and when you need both. Learn how to integrate them and where AIUC-1 fits."
canonical: "https://axipro.co/iso-42001-vs-iso-27001/"
language: "en-US"
modified: "2026-09-16T07:29:50+00:00"
generator: "WordPress 7.1"
---

[Home](https://axipro.co)

/ [ISO 42001](https://axipro.co/category/iso-42001/), [ISO-27001](https://axipro.co/category/iso-27001-2/)

/ ISO 42001 vs ISO 27001: Do You Need Both? Honest Answer

# ISO 42001 vs ISO 27001: Do You Need Both? Honest Answer

![Picture of Pedro Dias](https://axipro.co/wp-content/uploads/2026/05/pedro-passport-picture-scaled.jpg)

- Pedro Dias
- September 16, 2026

Copy Link

Most people asking this question fall into one of two camps. Either they already hold ISO 27001 and just shipped an AI feature, or they run an AI-native company and an enterprise buyer has asked for “your AI governance certification.” The answer is the same for both camps: **ISO 27001 secures your information and ISO 42001 governs your AI. Neither certificate covers the other.** If AI is part of what you sell or how you make decisions, you’ll need both. If it’s just a productivity tool humming away in the background, ISO 27001 on its own is still fine.

Below: what each standard governs, where they overlap, what your existing ISMS doesn’t say about AI, how to decide, and how to run both as one management system rather than two.

## **The Short Answer: When You Need Both (and When You Don’t)**

You need both when AI is part of your product or part of a decision that affects people, and a customer, regulator, or board could reasonably ask how you govern it. That covers most SaaS companies with a generative feature, every AI-native vendor, and any firm using AI to screen candidates, score credit, or make health or safety calls.

ISO 27001 alone is enough when your AI use is internal and low-stakes. Coding assistants, drafting tools, a chatbot answering FAQs from public docs. Your ISMS already covers the data those tools see, and nobody is asking you for an AI management system.

ISO 42001 on its own is a rare choice, and usually a bad one. The standard assumes there’s a working security baseline underneath it. An AI governance certificate sitting on top of an unaudited security program raises more questions than it answers, so ISO 27001 comes first or at the same time.

## **What ISO 27001 Covers vs What ISO 42001 Covers**

### ISO 27001: Information Security Management System (ISMS)

[ISO/IEC 27001:2022](https://www.iso.org/standard/27001) sets out the requirements for an Information Security Management System. The thing being protected is information. The risk being managed is losing its confidentiality, integrity, or availability. Annex A lists 93 controls across organizational, people, physical, and technological themes, and you explain which ones apply in a Statement of Applicability. The certificate tells customers you protect the data they systematically hand you.

### ISO 42001: AI Management System (AIMS)

[ISO/IEC 42001:2023](https://www.iso.org/standard/42001) sets out the requirements for an Artificial Intelligence Management System. It’s the first certifiable standard for how an organization develops, provides, or uses AI. The thing being governed is the AI system across its whole lifecycle, and the risks go well past security: harm to people, bias, opacity, and a lack of human oversight. Annex A lists 38 controls under nine objectives, covering AI policy, impact assessment, lifecycle management, data governance, and third-party relationships. The certificate tells customers you can explain what your AI does, who’s accountable for it, and how you stop it from doing damage.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

[Schedule a consultation](https://axipro.co/free-assessment/)

## **ISO 42001 vs ISO 27001: The Key Differences**

|  | ISO 27001:2022 | ISO 42001:2023 |
| --- | --- | --- |
| **What it governs** | Information assets and the systems that process them | AI systems across their lifecycle, whether built, bought, or used |
| **Core risk question** | Can this data be stolen, altered, or made unavailable? | Can this AI system harm people, mislead them, or operate without accountability? |
| **Annex A controls** | 93 security controls in 4 themes | 38 AI controls across 9 objectives |
| **Key assessment** | Information security risk assessment | AI risk assessment plus AI system impact assessment |
| **Typical requester** | Every enterprise security review | AI-focused questionnaires, regulated buyers, boards, EU AI Act mapping |
| **Maturity** | Established since 2005, revised 2022 | First edition, December 2023; auditors accredited under ISO/IEC 42006 |

### Scope: Information Assets vs AI Systems

ISO 27001 draws its boundary around information and the infrastructure that handles it. ISO 42001 draws its boundary around AI systems and their use cases: a recommendation engine, a customer-facing agent, a hiring model, a third-party LLM embedded in your product. The same company can hold both certificates with different scopes. On a first certification cycle the AI scope is usually the narrower one.

### Risks Managed: Security Risk vs AI Impact and Ethical Risk

An ISMS asks what happens if an attacker gets in. An AIMS also asks what happens when the system works exactly as designed and still produces a biased shortlist, a made-up policy answer, or a decision nobody can explain to the person it affected. Clause 6.1.4 of ISO 42001 requires an **AI system impact assessment** that looks at consequences for individuals and society. ISO 27001 has nothing like it.

### Controls: Annex A Security Controls vs Annex A AI Controls

Roughly a third of ISO 42001’s Annex A maps onto something in ISO 27001. Supplier controls (A.10), data classification and handling (A.7), and roles and responsibilities (A.3) reuse work you’ve already done. The impact assessment group (A.5), most of the lifecycle group (A.6), and the transparency obligations to interested parties (A.8) have no ISO 27001 equivalent, and that’s where most of the new effort goes.

### Who Asks for Each Certificate

Procurement teams ask for ISO 27001 or [SOC 2](https://axipro.co/soc-2/) by default. ISO 42001 comes up when a buyer’s vendor questionnaire has grown an AI section: does a human review high-stakes outputs, do you track which third-party models touch customer data, have you run an impact assessment? A 42001 certificate answers most of that before the security call even starts. Boards and regulators in the EU and the Gulf are the other main source of demand.

### Worth Knowing: Both standards use ISO’s Harmonized Structure

Both standards use ISO’s Harmonized Structure, so clauses 4 through 10 (context, leadership, planning, support, operation, performance evaluation, improvement) share the same numbering and mostly the same wording. An auditor moving between them sees the same management-system skeleton with a different set of risks and controls hung on it.

## **Where ISO 42001 and ISO 27001 Overlap**

### The Shared Harmonized Structure (Clauses 4 to 10)

The management-system machinery carries over almost untouched. Document control, competence records, the internal audit program, management review, corrective action, and the way you plan for risks and opportunities all serve both standards. A company with a working ISMS usually walks into an [ISO 42001 gap analysis](https://axipro.co/iso-42001-gap-analysis-checklist/) already meeting most clause-level requirements on paper. The job is extending them to AI, not rebuilding them.

### Reusable Policies, Risk Processes and Evidence

Your information security policy becomes the parent of an AI policy. Your risk methodology picks up AI-specific risk sources and an impact assessment step. Supplier due diligence gains questions about model providers and training data. Access control, logging, change management, and incident response evidence all carry over wherever AI systems run on the same infrastructure, which for most SaaS companies means everywhere.

## **Does ISO 27001 Already Cover Your AI Systems?**

Partly. The part it misses is the part buyers ask about.

### What Your Existing Statement of Applicability Doesn’t Address

Your ISO 27001 SoA answers whether the servers running your model are patched, whether access to training data is restricted, and whether the vendor hosting your LLM has been assessed. It doesn’t answer whether the model’s outputs are monitored for drift or bias, whether affected users are told an AI made the decision, whether a human can override it, or whether anyone assessed the impact on the people it affects before it went live. Those are the questions ISO 42001 exists to make you write down.

### Why the Gap Is Bigger Than It Looks on Paper

On a clause-mapping spreadsheet, ISO 42001 looks like a 30 percent delta on top of ISO 27001. In practice, that 30 percent is the hard part. Building an AI inventory, running impact assessments on each system, defining human oversight for high-stakes outputs, and documenting training-data provenance are new organizational habits rather than new documents, and they pull in product and data science teams who’ve never been anywhere near an audit. The reuse is real, but it front-loads the easy work and leaves the unfamiliar work for last.

**Insider Note:** The nonconformity we see most often in first-time ISO 42001 audits at companies that already hold ISO 27001 is an AI inventory that only lists the models the company built. Auditors expect every AI system in scope, including the third-party LLM behind a support chatbot and the SaaS tools with AI features that touch customer data. ISO 27001 teams are used to inventorying things they own. ISO 42001 asks them to inventory things they merely use.

## **Do You Need ISO 42001 If You Already Have ISO 27001?**

### You Need Both If…

AI is in your product or your decisions. You sell an AI-native product, embed a generative feature customers rely on, or use AI to make or shape decisions about people. You’re seeing AI sections in security questionnaires, deals are slowing down on AI governance questions, or you have EU customers who’ll need to trace their AI Act obligations through your supply chain. ISO 27001 keeps you in the procurement process. ISO 42001 gets you through it.

### ISO 27001 Alone Is Enough If…

AI is a background tool with no external exposure. Your team uses coding assistants and drafting tools, nothing customer-facing runs on a model, and no decision about a person is automated. Add an [acceptable-use policy for AI tools](https://axipro.co/shadow-ai-policy-template/) and a supplier assessment for the vendors behind them to your ISMS, then revisit the question the moment AI touches your product.

### ISO 42001 Alone Is Enough If…

Almost never. Certification bodies will certify ISO 42001 standalone, and technically you can build an AIMS without an ISMS. But the AI controls lean on security controls only an ISMS provides, and no enterprise buyer accepts an AI governance certificate from a vendor who can’t show a security one. Starting from zero? Do ISO 27001 first, or both together.

## **Which Should You Certify First?**

ISO 27001 first if you hold neither and revenue depends on enterprise deals. It opens more procurement doors, and it builds the management system ISO 42001 extends. Both together if you’re AI-native and buyers are already asking AI governance questions, because a combined implementation costs less than two sequential ones and the shared clauses only get built once. ISO 42001 next if you already hold ISO 27001. Companies with a mature ISMS routinely cut the 42001 timeline by 30 to 50 percent, since they’re extending a working system instead of building one. Our breakdown of [how long ISO 42001 certification takes](https://axipro.co/iso-42001-certification-timeline/) walks through the phases.

### Pro Tip: Settle the ISO 42001

Settle the ISO 42001 scope before you settle the timeline. Certify the one or two AI systems buyers actually ask about, get the certificate, and widen scope at the first surveillance audit. The companies whose projects run past nine months are almost always the ones that tried to bring every AI use case into scope on the first pass.

## **How to Run ISO 42001 and ISO 27001 as One Integrated Management System**

### Mapping Controls Between the Two Standards

Start from your ISO 27001 SoA and build [a single combined control set](https://axipro.co/soc-2-to-iso-27001-mapping/). Each ISO 42001 Annex A control gets one of three labels: fully covered by an existing ISO 27001 control, partly covered and needing an AI-specific extension, or new. Supplier, data handling, and roles controls land in the first two buckets. Impact assessment, lifecycle, and transparency controls land in the third. Keep one risk register with an AI risk-source category rather than two registers that disagree with each other by month three.

### Combined Audits and Certification Cycles

One certification body can audit both standards in a single integrated audit, as long as it’s accredited for ISO 42001 under ISO/IEC 42006. The shared clauses get assessed once, and the two Annex A control sets are assessed separately. If you already hold ISO 27001, most bodies will bolt ISO 42001 on at your next surveillance or recertification audit, which puts both certificates on one three-year cycle. Check with your body before you plan around it, though. Plenty of ISO 27001 auditors haven’t added ISO 42001 accreditation yet.

### Cost and Effort Savings of Integrating vs Certifying Separately

Integration saves money in three places: the management-system documentation gets written once, the internal audit and management review run once, and external audit days drop because the shared clauses are assessed together. With automation-supported fixed-fee delivery, Axipro delivers ISO 42001 readiness for around [$4,000 for companies under 50 employees and $5,500 above], with the GRC platform and accredited audit adding roughly [$4,000 to $7,000]. Our guide to [ISO 42001 consulting cost](https://axipro.co/iso-42001-consulting-cost/) explains why those numbers sit so far below the consulting quotes you may have seen. Certifying the two standards separately, with different consultants and auditors, typically costs 30 to 40 percent more and leaves you with two management systems that drift apart within a year.

## **Beyond ISO 42001: AIUC-1 for AI Agents**

ISO 42001 governs the organization. It doesn’t test a specific AI agent for jailbreaks, data leakage, or unsafe tool use. That job belongs to **AIUC-1**, the [first auditable standard written specifically for AI agents](https://www.aiuc-1.com/aiuc-1-certification). It has 51 requirements across data and privacy, security, safety, reliability, accountability, and society. Auditors review operational controls once a year and re-run technical tests at least quarterly, and the standard is crosswalked to ISO 42001, [NIST AI RMF](https://axipro.co/nist-ai-rmf-1-0/), and the EU AI Act so you’re not doing the same work twice.

For most companies the stack now has three layers: ISO 27001 for the security baseline, ISO 42001 for the AI management system, and AIUC-1 for any customer-facing or tool-calling agent that enterprise buyers want [independently tested](https://axipro.co/secure-ai-agent-vendor-certifications/). Axipro covers all three. Our [AIUC-1 certification guide](https://axipro.co/aiuc-1-certification/) explains what the audit tests and who should go for it, and we’ve taken AI companies through combined ISO 27001, ISO 42001, and GDPR programs to [certification in under three months](https://axipro.co/qa-company-iso27001-iso42001-gdpr-compliance/).

## **Common Mistakes When Deciding Between ISO 42001 and ISO 27001**

The most expensive misunderstanding is treating ISO 42001 as an upgrade that replaces ISO 27001. It’s an addition, and buyers will keep asking for the security certificate. Second is assuming ISO 42001 equals [EU AI Act compliance](https://axipro.co/eu-ai-act-compliance-and-certification/). A certification body auditing under ISO/IEC 42006 doesn’t assess your obligations under the [Act](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai), and the certificate isn’t a conformity assessment. What it does give you is the management system the Act’s risk management, documentation, and human oversight articles assume you already have. After those two: scoping every AI use case into the first certification, running the AI risk assessment and the impact assessment in one spreadsheet, and letting the product team find out about the audit at Stage 2.

**Important:** [ISO 42001 certification](https://axipro.co/iso-42001/) lasts three years with annual surveillance audits, the same as ISO 27001. If you’re adding it to an existing ISO 27001 cycle, ask whether the body will line up the expiry dates. Two certificates on offset cycles means two rounds of surveillance audits every year, which doubles the ongoing cost of holding both without anyone quite noticing.

## **Next Steps: Building One Program That Covers Both**

ISO 27001 and ISO 42001 answer different questions, and if AI is in your product or your decisions, buyers will ask both. The efficient path is one integrated management system: reuse the ISMS clauses, extend the risk methodology to AI, add the impact assessments and lifecycle controls that have no security equivalent, and certify both with one body on one cycle. Axipro’s [ISO 42001 certification services](https://axipro.co/iso-42001-certification/) run that integrated program end to end, from [gap analysis](https://axipro.co/services/gap-analysis/) through guaranteed certification on the Achievement Plan, and our [ISO 27001 certification services](https://axipro.co/iso-27001-certification/) lay the foundation for companies starting from scratch. If you ship agents, AIUC-1 slots in as the third layer. Done well, it’s one program with three certificates at the end, not three separate projects.

## Frequently Asked Questions

Can you get ISO 42001 without ISO 27001?

Yes. ISO 42001 stands on its own and certification bodies will certify it independently. Hardly anyone does, because the AI controls depend on security controls an ISMS provides and enterprise buyers expect the security certificate first. If you hold neither, plan on ISO 27001 first or both together.

Can ISO 27001 replace ISO 42001?

No. ISO 27001 governs information security. It doesn’t require an AI inventory, an AI system impact assessment, human oversight controls, or transparency toward people affected by AI decisions. You can extend an ISMS with AI policies, but you can’t certify it as an AI management system.

Do ISO 42001 and ISO 27001 share the same audit?

They can. A certification body accredited for both can run one integrated audit that covers the shared management-system clauses once and each Annex A control set separately. Ask your current ISO 27001 auditor whether they hold ISO/IEC 42006 accreditation before assuming they can add ISO 42001.

How much extra work is ISO 42001 if you already have ISO 27001?

Less than starting fresh, but more than a mapping exercise. Expect to reuse most of the clause 4 to 10 documentation and about a third of Annex A, and to build new AI inventories, impact assessments, lifecycle controls, and human oversight procedures. Companies with a mature ISMS typically reach ISO 42001 certification in three to six months instead of six to twelve.

Does having both standards make you compliant with the EU AI Act?

No. Neither certificate is a conformity assessment under the Act. Together they give you the management system, risk process, documentation, and oversight mechanisms the Act’s high-risk obligations assume exist, which shortens the mapping exercise a lot. But you still have to show compliance against the Act’s articles separately.

Axipro Author

![Picture of Pedro Dias](https://axipro.co/wp-content/uploads/2026/05/pedro-passport-picture-scaled.jpg)

### Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

- September 16, 2026
- [ISO 42001](https://axipro.co/category/iso-42001/), [ISO-27001](https://axipro.co/category/iso-27001-2/)

Copy Link

## Blog Highlights

## Explore More Articles

[Read More Blogs](https://axipro.co/blog/)

- [ISO 42001](https://axipro.co/category/iso-42001/), [ISO-27001](https://axipro.co/category/iso-27001-2/)

- September 16, 2026

#### [ISO 42001 vs ISO 27001: Do You Need Both? Honest Answer](https://axipro.co/iso-42001-vs-iso-27001/)

Most people asking this question fall into one of two camps. Either they already hold ISO 27001 and just shipped an AI feature, or they run an AI-native company and an enterprise buyer has asked for “your AI governance certification.” The answer is the same for both camps: ISO 27001 secures your information and ISO 42001 governs your AI. Neither certificate covers the other. If AI is part of what you sell or how you make decisions, you’ll need both. If it’s just a productivity tool humming away in the background, ISO 27001 on its own is still fine. Below: what each standard governs, where they overlap, what your existing ISMS doesn’t say about AI, how to decide, and how to run both as one management system rather than two. The Short Answer: When You Need Both (and When You Don’t) You need both when AI is part of your product or part of a decision that affects people, and a customer, regulator, or board could reasonably ask how you govern it. That covers most SaaS companies with a generative feature, every AI-native vendor, and any firm using AI to screen candidates, score credit, or make health or safety calls. ISO 27001 alone is enough when your AI use is internal and low-stakes. Coding assistants, drafting tools, a chatbot answering FAQs from public docs. Your ISMS already covers the data those tools see, and nobody is asking you for an AI management system. ISO 42001 on its own is a rare choice, and usually a bad one. The standard assumes there’s a working security baseline underneath it. An AI governance certificate sitting on top of an unaudited security program raises more questions than it answers, so ISO 27001 comes first or at the same time. What ISO 27001 Covers vs What ISO 42001 Covers ISO 27001: Information Security Management System (ISMS) ISO/IEC 27001:2022 sets out the requirements for an Information Security Management System. The thing being protected is information. The risk being managed is losing its confidentiality, integrity, or availability. Annex A lists 93 controls across organizational, people, physical, and technological themes, and you explain which ones apply in a Statement of Applicability. The certificate tells customers you protect the data they systematically hand you. ISO 42001: AI Management System (AIMS) ISO/IEC 42001:2023 sets out the requirements for an Artificial Intelligence Management System. It’s the first certifiable standard for how an organization develops, provides, or uses AI. The thing being governed is the AI system across its whole lifecycle, and the risks go well past security: harm to people, bias, opacity, and a lack of human oversight. Annex A lists 38 controls under nine objectives, covering AI policy, impact assessment, lifecycle management, data governance, and third-party relationships. The certificate tells customers you can explain what your AI does, who’s accountable for it, and how you stop it from doing damage. ISO 42001 vs ISO 27001: The Key Differences ISO 27001:2022 ISO 42001:2023 What it governs Information assets and the systems that process them AI systems across their lifecycle, whether built, bought, or used Core risk question Can this data be stolen, altered, or made unavailable? Can this AI system harm people, mislead them, or operate without accountability? Annex A controls 93 security controls in 4 themes 38 AI controls across 9 objectives Key assessment Information security risk assessment AI risk assessment plus AI system impact assessment Typical requester Every enterprise security review AI-focused questionnaires, regulated buyers, boards, EU AI Act mapping Maturity Established since 2005, revised 2022 First edition, December 2023; auditors accredited under ISO/IEC 42006 Scope: Information Assets vs AI Systems ISO 27001 draws its boundary around information and the infrastructure that handles it. ISO 42001 draws its boundary around AI systems and their use cases: a recommendation engine, a customer-facing agent, a hiring model, a third-party LLM embedded in your product. The same company can hold both certificates with different scopes. On a first certification cycle the AI scope is usually the narrower one. Risks Managed: Security Risk vs AI Impact and Ethical Risk An ISMS asks what happens if an attacker gets in. An AIMS also asks what happens when the system works exactly as designed and still produces a biased shortlist, a made-up policy answer, or a decision nobody can explain to the person it affected. Clause 6.1.4 of ISO 42001 requires an AI system impact assessment that looks at consequences for individuals and society. ISO 27001 has nothing like it. Controls: Annex A Security Controls vs Annex A AI Controls Roughly a third of ISO 42001’s Annex A maps onto something in ISO 27001. Supplier controls (A.10), data classification and handling (A.7), and roles and responsibilities (A.3) reuse work you’ve already done. The impact assessment group (A.5), most of the lifecycle group (A.6), and the transparency obligations to interested parties (A.8) have no ISO 27001 equivalent, and that’s where most of the new effort goes. Who Asks for Each Certificate Procurement teams ask for ISO 27001 or SOC 2 by default. ISO 42001 comes up when a buyer’s vendor questionnaire has grown an AI section: does a human review high-stakes outputs, do you track which third-party models touch customer data, have you run an impact assessment? A 42001 certificate answers most of that before the security call even starts. Boards and regulators in the EU and the Gulf are the other main source of demand. Worth Knowing: Both standards use ISO’s Harmonized Structure Both standards use ISO’s Harmonized Structure, so clauses 4 through 10 (context, leadership, planning, support, operation, performance evaluation, improvement) share the same numbering and mostly the same wording. An auditor moving between them sees the same management-system skeleton with a different set of risks and controls hung on it. Where ISO 42001 and ISO 27001 Overlap The Shared Harmonized Structure (Clauses 4 to 10) The management-system machinery carries over almost untouched. Document control, competence records, the internal audit program, management review, corrective action, and the way you plan for risks

[Read more](https://axipro.co/iso-42001-vs-iso-27001/)

- [GDPR](https://axipro.co/category/gdpr/)

- September 15, 2026

#### [KVKK vs GDPR: Key Compliance Gaps for Turkish Exporters](https://axipro.co/kvkk-vs-gdpr-turkish-exporters/)

The EU buys more from Türkiye than anyone else. According to the European Commission’s trade profile for Türkiye, about 41% of Turkish goods exports went to the EU in 2024, and the share keeps climbing. Nearly every company behind those shipments holds some EU personal data: a buyer’s name in the CRM, a webshop account, a logistics contact, a support ticket. That data puts the exporter inside the GDPR, and a KVKK compliance file won’t answer the questions an EU customer’s procurement team is going to ask. KVKK and GDPR look alike, and the 2024 amendments brought them closer. They’re still two laws with two regulators, two sets of paperwork and very different fine ceilings. This article walks through the eight places where a KVKK-compliant Turkish exporter falls short of GDPR, covers both directions of data flow, and ends with a roadmap that reflects how long this stuff actually takes. Why KVKK Compliance Doesn’t Make a Turkish Exporter GDPR-Ready Law No. 6698 was written to line Türkiye up with the EU’s 1995 Data Protection Directive. It came into force in April 2016, a few weeks before the EU adopted the GDPR. That timing explains most of what follows. KVKK inherited the Directive’s structure and then developed on its own track under the Personal Data Protection Board, while the GDPR added accountability tools, extraterritorial reach and turnover-based fines that the Directive never had. So a Turkish company can be fully KVKK compliant, registered in VERBİS, privacy notices in place, and still have no records of processing, no DPIA method, no EU representative, and no answer for an EU customer asking which Article 46 mechanism covers the data they’re about to send to Istanbul. When GDPR Applies to a Turkish Company Article 3(2) of the GDPR catches companies with no EU establishment in two situations: offering goods or services to people in the EU, and monitoring their behavior. The European Data Protection Board’s guidelines on territorial scope treat euro pricing, shipping to EU addresses, EU-language storefronts and EU-targeted marketing as “offering.” Analytics, retargeting pixels and personalization count as “monitoring.” There’s a third route that’s easy to miss. A Turkish software house or contract manufacturer that processes EU personal data for an EU customer is a processor under Article 28. The customer will want a data processing agreement, security commitments and help meeting its own GDPR obligations, even if the Turkish company never markets to the EU at all. Important: Selling only B2B to EU companies doesn’t get you out of this. Business contacts are data subjects. The names, emails and phone numbers of a German buyer’s purchasing staff are personal data under both laws, and the exporter is the controller of them. KVKK vs GDPR at a Glance Obligation KVKK (Law No. 6698, as amended 2024) GDPR (Regulation (EU) 2016/679) Default legal basis Explicit consent, with listed exceptions including legitimate interest Six equal lawful bases; consent is one of them Registry Mandatory VERBİS registration for most controllers No public registry; internal Article 30 records Impact assessment No statutory DPIA Mandatory DPIA for high-risk processing DPO Not required Required in defined cases (Article 37) Representative abroad Foreign controllers appoint a Türkiye representative Non-EU controllers appoint an EU representative (Article 27) Data portability Not granted Granted (Article 20) Breach notice Board within 72 hours Supervisory authority within 72 hours Transfers Adequacy, Turkish standard contracts, BCRs; 5-business-day filing Adequacy, EU SCCs, BCRs; transfer impact assessment Maximum fine ₺17,092,242 in 2026 €20 million or 4% of global turnover Gap 1: Lawful Bases and Consent KVKK’s Article 5 puts explicit consent at the top and lists everything else as an exception. Turkish privacy notices reflect that, and most of them lean on consent for almost everything. The GDPR treats consent as one option among six, and in practice it’s the weakest one for core business processing. Regulators expect contract performance for order fulfillment, legal obligation for tax records, and legitimate interest for fraud prevention and B2B marketing. Consent also has a cost that exporters don’t always price in. Under Article 7 it has to be as easy to withdraw as it was to give, and once it’s withdrawn the processing has to stop. An exporter that collects EU customer data “with consent” and then keeps invoicing records for ten years has written a contradiction into its own notice. Law No. 7499 closed one part of this gap in 2024. Health and sexual-life data lost their special carve-out and the list of grounds for processing sensitive data got longer, so KVKK Article 6 now tracks GDPR Article 9 fairly closely. An exporter’s KVKK approach to sensitive data can be reused for GDPR with light editing. Cookies are another point of convergence. The Board’s cookie guidance already asks for opt-in consent for anything beyond strictly necessary cookies, a reject button as visible as the accept one, and no pre-ticked boxes. A banner built to that standard will pass with most EU supervisory authorities too. Gap 2: Accountability Documentation KVKK asks controllers to register in VERBİS, the public Data Controllers’ Registry, and to keep a processing inventory behind that registration. The GDPR has no registry. What it has instead is Article 30: an internal record of processing activities that a supervisory authority can demand at any time, covering purposes, data categories, recipients, transfers, retention periods, and security measures. The VERBİS inventory gets you roughly 70% of the way to an Article 30 record. What’s usually missing is the lawful basis for each purpose (VERBİS doesn’t push for it at the same level of detail), the transfer mechanism per recipient, and the Article 28 processor list. The bigger gap is the Data Protection Impact Assessment. KVKK has nothing like it. GDPR Article 35 makes a DPIA mandatory before high-risk processing starts, and an EU customer may ask to see one before signing. Building the method takes a few weeks. Retrofitting DPIAs onto processing that’s already live takes longer, and it tends to turn up things nobody wanted to find. Insider

[Read more](https://axipro.co/kvkk-vs-gdpr-turkish-exporters/)

- [ISO 42001](https://axipro.co/category/iso-42001/)

- September 11, 2026

#### [The ISO 42001 Gap Analysis Checklist Consultants Actually Use](https://axipro.co/iso-42001-gap-analysis-checklist/)

A consultant-grade ISO 42001 gap analysis checklist has 38 Annex A controls, roughly 80 clause-level “shall” statements, and one question attached to every line: where is the evidence, and would a certification body accept it? That last question is what separates the checklists consultants use from the free self-assessment spreadsheets that rank for the same search. This article lays out the checklist itself: what a consultant checks before the engagement starts, the clause-by-clause and control-by-control checkpoints, how evidence gets sampled, how gaps get scored, what the deliverables look like, and what fails most often. Use it to run your own assessment, or to check whether the consultant you’re about to hire is doing the job properly. What Makes a Consultant-Grade ISO 42001 Gap Analysis Checklist Different​ Depth of Evidence Review vs. Self-Assessment Tools A self-assessment tool asks whether you have an AI policy. A consultant asks to see it, checks the approval date and version, reads clause 5.2 against it, and then asks three people in engineering whether they’ve read it. The checklist item is the same. The evidence standard is not. Consultants score every item on three levels: documented, implemented, and effective. A policy that exists but nobody follows scores as “ad hoc,” not “defined.” A control that runs but produces no record scores as unverifiable, which for audit purposes is the same as absent. Self-assessment tools collapse those three levels into a single yes/no, which is why companies that score 85% on a free tool routinely receive major nonconformities at Stage 2. Alignment with Certification Body Expectations Certification bodies auditing against ISO/IEC 42001:2023 now work under ISO/IEC 42006:2025, which sets competence, audit-time, and impartiality requirements for AIMS auditors and builds on ISO/IEC 17021-1. A consultant-grade checklist is written with 42006 in mind: it organizes findings by clause and control identifier, because that’s how the auditor works, and it records evidence locations, because that’s what the auditor will sample. The practical difference shows up in the report. A gap register that says “AI governance needs improvement” is useless in front of an auditor. One that says “A.5.2 not conformant: no documented impact assessment process; two of four in-scope systems have no assessment on file” maps directly to the audit plan. Risk-Weighted Scoring Methodology Self-assessments count gaps. Consultants weight them. A missing AI policy under clause 5.2 and an incomplete competence matrix under 7.2 are both gaps, but the first will block certification and the second will earn you a minor finding. A consultant-grade checklist carries two scores per line: a maturity rating (how far the control is from working) and a certification criticality (what happens at audit if it stays this way). Effort estimates live in the remediation plan, never in the gap score, because mixing them produces a roadmap that fixes easy things first rather than important ones. Insider Note: The fastest tell that a checklist is consultant-grade rather than a marketing download is whether it has a column for evidence location. Auditors don’t accept “yes” as evidence. If the checklist has nowhere to record where the proof lives, it wasn’t built by someone who has sat through a Stage 2. Pre-Engagement Preparation Consultants Complete Before the Gap Analysis Client AI Inventory and Use Case Cataloging Nothing in the checklist works without a complete AI inventory, and it’s the input clients get wrong most often. The inventory records every AI system in use: purpose, the role you play (developer, provider, deployer, or user), data consumed, outputs produced, whether a human sits between the output and the decision, and which third-party model or API it depends on. Consultants push hard on shadow AI here: SaaS tools that added AI features, agents running under employee credentials, and internal scripts calling model APIs. Every one of those is in scope until you document why it isn’t. Defining AIMS Scope Boundaries Clause 4.3 requires a scope statement naming which AI systems, business units, locations, and lifecycle stages the AIMS covers. Consultants draft this from the inventory, not before it. Scope discipline matters commercially too: certification bodies price audits by audit days, and audit days scale with scope. A narrow, well-justified first scope (the customer-facing AI product, say, rather than every internal tool) is usually the right call for a first certification. Stakeholder Interview Planning The checklist needs answers from people who don’t write policies. A typical interview plan covers the executive sponsor (clause 5), the AI or product lead (clauses 6 and 8), data engineering (A.7), procurement or vendor management (A.10), legal or privacy (A.5, A.8), and at least one front-line user of the AI system (A.9). Consultants interview the doers separately from the document owners, because the distance from what the procedure says to what actually happens is the finding. Document Request List (DRL) Consultants Send Clients The DRL goes out one to two weeks before fieldwork. A standard ISO 42001 DRL asks for the AI inventory; existing AI, security, and data policies; org chart with AI governance roles; any AI risk assessments or impact assessments; model documentation (model cards, system cards, or whatever exists); training-data provenance and data quality records; supplier contracts for third-party models; incident and change logs; training records; any ISO 27001 ISMS documentation; and the last internal audit and management review minutes if they exist. Missing items become findings rather than delays. Pro Tip: Return an Honest DRL Return the DRL with a column that says “does not exist” wherever that’s true. Consultants would rather know on day one than discover it in a workshop. An honest DRL shortens fieldwork by days and makes the maturity scores more accurate, which makes the remediation plan cheaper. Clause-by-Clause Checklist Consultants Use (ISO 42001 Clauses 4 to 10) ISO 42001 follows the Harmonized Structure shared with ISO 27001 and ISO 9001, so clauses 4 to 10 will look familiar to anyone who has run an ISMS. What’s different is the content each clause demands. Clause 4 – Context of the Organization Checkpoints Consultants check for a documented analysis of

[Read more](https://axipro.co/iso-42001-gap-analysis-checklist/)

WhatsApp us
