Quick Answer: If you hold ISO 27001 you have a real head start. Both share the same management system structure, so clauses 4 through 10 largely carry across. Comparing ISO 42001 vs ISO 27001, the new work is AI-specific. System inventory, impact assessment, data provenance, model lifecycle controls.
You have the ISO 27001 certificate. It took months and it worked.
Now a customer is asking about AI governance. The answer they want is a second certificate. The reasonable question is how much of the first one counts.
More than you would guess on the management system. Less than you would hope on the controls.
We talk about all you need to know. But first:
Key Takeaways
- ISO 27001 protects information. ISO 42001 governs how AI systems make and act on decisions.
- Both follow the same management system structure. Scope, leadership, planning and audit processes map across.
- ISO/IEC 27001:2022 has 93 controls in 4 themes. ISO/IEC 42001:2023 has 38 controls across 9 control objectives.
- The AI system impact assessment has no ISO 27001 equivalent. It needs product and legal input.
- BEMO builds the AI management system on top of your existing ISMS. Not a second program beside it.
What Each Standard Governs
The scopes sound adjacent. They are not the same thing at all.
ISO/IEC 27001:2022 governs information security, the ground your ISO 27001 practice already covers. Confidentiality, integrity and availability of information, whatever form it takes. Its 93 Annex A controls sit in four themes: organizational, people, physical and technological.
ISO/IEC 42001:2023 governs AI systems. Not the data alone. How a system uses that data to shape a decision. And who that decision affects.
The gap between them is easiest to see in an example. Take a resume screening model trained on encrypted, access-controlled, correctly retained data. It can still produce discriminatory outcomes. ISO 27001 is satisfied. ISO 42001 is not.
That is the distinction to hold onto. Security asks whether the data was protected. AI governance asks whether the decision was defensible.
ISO 27001 AI compliance does not exist as a category. Auditors assessing your ISMS will not ask about model drift, provenance or explainability. Those sit outside the standard's scope.
That is why an AI governance question is not answered by your SOC 2 report. Your ISO 27001 certificate does not answer it either. They are asking about a different failure mode.
The Shared Management System Structure
Both standards use the Harmonized Structure that ISO applies across management system standards. Clause numbering is the same. So is the logic.
That means a working ISMS gives you real reusable assets, not just familiarity.
|
Clause |
ISO 27001 asset |
Reuse for ISO 42001 |
|---|---|---|
|
4. Context |
Interested parties, scope statement |
Extend to AI-affected parties, rewrite scope for AI systems |
|
5. Leadership |
Policy, roles, responsibilities |
Add AI policy, assign AI risk ownership |
|
6. Planning |
Risk methodology, objectives |
Reuse methodology, add AI impact assessment |
|
7. Support |
Competence, awareness, document control |
Reuse directly, add AI-specific training |
|
8. Operation |
Operational planning and control |
New AI lifecycle controls required |
|
9. Perf. eval. |
Internal audit, management review |
Reuse cadence and process, extend scope |
|
10. Improv. |
Nonconformity/corrective action |
Reuse directly |
Your risk assessment methodology transfers. The criteria change, but the process does not.
Your internal audit program transfers. Auditors, schedule, reporting format and corrective action workflow all work for a second scope.
Your management review cadence transfers. You are adding agenda items, not creating a governance body.
Your document control transfers. Version control, approval routing and retention already exist and already pass audit.
Both standards also use a Statement of Applicability. The concept carries across. You select from the Annex A control set and justify exclusions. Confirm the expected format with your certification body. Do not assume your ISO 27001 template drops straight in.
What ISO 42001 Adds
Five things are genuinely new. None of them is a rewrite of something you have.
AI system inventory. Your ISMS has an asset register. It lists systems, data stores and suppliers. It almost certainly does not identify which of them contain AI. That includes AI features vendors shipped into tools you licensed. Building this inventory is usually the first stall point.
AI system impact assessment. This has no ISO 27001 equivalent, and it is the largest single addition. Your risk assessment asks what could harm the organization. Impact assessment asks who the system affects and how, including people outside the company. ISO/IEC 42005:2025 gives dedicated guidance. The inputs come from product and legal, not security.
Data quality and provenance. Where training data came from, what it contains, whether it is representative. And whether you can show that. ISO 27001 cares how the data is stored. ISO 42001 cares what is in it.
Model lifecycle controls. Design, development, verification, deployment, monitoring and retirement, each with records. Change control exists in your ISMS. It tracks configuration changes, not model behavior changes.
Transparency and explainability. Information you give users and affected parties about how the system works. This produces customer-facing artifacts, which means marketing and legal review.
Supplier management extends rather than duplicates. You already assess vendors. Now you assess them for model provenance and training practices. Also whether they produce evidence when your auditor asks.
Certifying Both Together
An integrated approach is usually cheaper and always less disruptive.
One management system, two scopes. The scope statement names the ISMS boundary and the AIMS boundary. Leadership, document control, audit and review run once.
Integrated audits are possible where a certification body is accredited for both standards. Combining reduces auditor days and calendar disruption. The AI-specific audit time follows ISO/IEC 42006:2025 rules and does not disappear.
Surveillance cycles can be aligned. If you are mid-cycle on ISO 27001, ask about synchronizing. Both certificates can share an annual visit.
Timing matters here. Adding AI management system certification just before an ISO 27001 recertification is often cleanest. The documentation review happens anyway. Our note on how long ISO 27001 certification stays valid sets out that cycle.
Confirm with your body before assuming any of it. Accreditation for ISO 42001 is still spreading and not every ISO 27001 auditor holds it.
Why the Gap Is Bigger than It Looks on Paper
The clause mapping table above makes this look like a small delta. It is not.
The delta is evidence, and evidence is where certified organizations still fail.
- Monitoring is the clearest case. Your ISMS produces logs by design, because security tooling generates them automatically. Model behavior monitoring does not happen unless somebody builds it. An auditor wants six months of evaluation output. A policy saying you intend to will not pass.
- Impact assessment repetition is the second. It is not a document you file. Every material model change reopens it. Retrain the model, change the system prompt, swap the provider. The assessment now describes something that no longer exists.
- Provenance records are the third, and they are frequently retroactive. Nobody was recording where training data came from before it mattered. Reconstructing that after the fact ranges from tedious to impossible.
- Then the organizational problem. Your ISMS lives inside security, where you have authority. AI governance needs product, legal and engineering, none of whom report to you. Booking their time is the real constraint on the calendar.
ISO 42001 compliance is also continuous in a way that catches ISO 27001 teams out. The ISMS settles into a rhythm. An AIMS does not. The systems it governs change faster than the controls describing them.
The Shorter Path from Where You Are
Holding ISO 27001 puts you months ahead of a cold start. That advantage is real and worth using. Our certification roadmap shows where each carried-over element lands in the sequence, and the cost breakdown shows what the head start is worth in budget terms.
It also creates a trap. The clause mapping looks like a small extension, so the work gets scoped as one. Then the AI inventory turns out to be missing. Impact assessments need people outside your reporting line.
The organizations that move fastest treat this as one management system with a second scope, not a second project. That is how BEMO approaches it, with the wider compliance services sitting around it.
Book a gap assessment and get a mapped view of what your ISMS already covers.
Frequently Asked Questions
Can we get ISO 42001 without ISO 27001?
Yes. ISO 27001 is not a prerequisite. Holding it shortens the path materially, because the management system clauses, risk methodology and audit program carry across, but organizations can pursue ISO 42001 on its own.
Can one auditor certify both?
Sometimes. The certification body must hold accreditation for both standards. The individual auditor needs competence in each. ISO/IEC 42006:2025 sets AI-specific competence requirements. Ask your current body directly before assuming.
Does our existing Statement of Applicability cover AI?
No. Your ISO 27001 Statement of Applicability covers the 93 information security controls. ISO 42001 needs its own, covering the 38 Annex A controls. Each inclusion and exclusion needs separate justification.
Will adding ISO 42001 extend our current certification cycle?
Not necessarily. Many organizations align the two so surveillance audits happen together. The AI-specific audit time is additional, but the calendar disruption can be shared. Discuss sequencing with your certification body early.
Top 10 Posts
-
Office 365 MFA Setup: Step-by-Step Instructions
-
CMMC Phase 2 Suspended: What the Compliance Pause Changed
-
Google Workspace to Office 365 Migration: A Step-by-Step Guide
-
What is The CIA Triad?
-
How Much Does ISO/IEC 27001 Lead Auditor Certification Cost in 2025?
-
What is Microsoft Purview ? Your A to Z Guide to Getting Secure Fast
-
SharePoint vs. OneDrive (What's the Difference Again?)
-
How to Migrate from GoDaddy to Office 365
-
When Will CMMC 2.0 Be Required for DoD Contracts?
-
How to Set Up Office Message Encryption (OME)


Leave us a comment!