ISO 42001 vs ISO 27001
They are not competitors and they are not substitutes. One protects information. The other governs AI. They share a skeleton, which is why holding one makes the other substantially cheaper, and why some organisations mistakenly think one covers the other.
Side by side
| ISO/IEC 27001:2022 | ISO/IEC 42001:2023 | |
|---|---|---|
| Manages | Information security | Artificial intelligence |
| System | ISMS | AIMS |
| Protects | Confidentiality, integrity, availability | Responsible development, provision and use of AI, including impacts on individuals and society |
| Annex A controls | 93, in 4 themes | 38, in 9 objectives (A.2–A.10) |
| Core clauses | 4–10 (Annex SL) | 4–10 (Annex SL): structurally parallel |
| Distinctive requirement | Risk treatment against security risk | AI system impact assessment: impacts on people and groups, not just on the organisation |
| Certifiable | Yes, accredited | Yes, accredited |
| Prerequisite | None | None |
| EU AI Act relationship | Supports Art. 15 cybersecurity | Supports the governance layer; not a harmonised standard, no Art. 40 presumption |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The one conceptual difference that matters
ISO/IEC 27001 assesses risk to the organisation. ISO/IEC 42001 additionally requires assessment of the impact of AI systems on individuals, groups and society.
That is not a rhetorical flourish, it is a different input to the risk register. A model that quietly disadvantages a protected group may present no information security risk at all and a serious AI impact. Teams that treat 42001 as “27001 with AI words” consistently fail this part in Stage 2 audits, because the impact assessment evidence simply does not exist.
What an existing ISMS actually gives you
Reusable: scope definition, leadership and policy machinery, competence and awareness, documented information control, internal audit programme, management review, nonconformity and corrective action, supplier management framework. That is most of clauses 4 to 10.
New work: AI policy, AI roles and accountability, AI system inventory, AI impact assessment, AI life-cycle controls, data-for-AI controls, information for interested parties, responsible-use objectives, and the AI-specific supplier and customer controls in A.10.
Which first?
27001 first, if…
Your customers are asking security questions, you are selling into enterprise or public sector procurement, and AI is one feature rather than the product. 27001 is still the certificate most often named in vendor questionnaires.
42001 first, if…
Your customers are specifically asking how you govern AI, AI is the product, or you have Annex III exposure under the EU AI Act. 42001 answers the question actually being asked, and the answer is now increasingly asked separately.
Practical recommendation. If you are doing both within eighteen months, scope them as one integrated management system from the start. A shared audit programme, shared management review and a combined Statement of Applicability cost meaningfully less than two sequential projects, and certification bodies will run combined audits.
What neither of them does
Neither ISO/IEC 27001 nor ISO/IEC 42001 is a harmonised standard under the EU AI Act, and neither confers the Article 40 presumption of conformity. If a vendor tells you a certificate makes you AI Act compliant, that is the point to stop listening. What 42001 does and does not cover →
Build the AIMS layer
The gap between an ISMS and an AIMS is a defined, finite set of documents: AI policy, AI system inventory, impact assessment procedure, life-cycle controls and a Statement of Applicability covering all 38 Annex A controls with justified exclusions.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Questions
What is the difference between ISO 42001 and ISO 27001?
ISO/IEC 27001 specifies an information security management system, protecting confidentiality, integrity and availability of information. ISO/IEC 42001 specifies an AI management system, governing how an organisation develops, provides and uses AI systems responsibly. ISO/IEC 27001 Annex A carries 93 controls in four themes. ISO/IEC 42001 Annex A carries 38 controls across nine control objectives numbered A.2 to A.10. Both follow the ISO Annex SL harmonised structure, so clauses 4 to 10 are structurally parallel and an existing ISMS provides most of the management-system machinery.
Can you certify to ISO 42001 without ISO 27001?
Yes. ISO/IEC 42001 is a standalone standard with no prerequisite certification. In practice organisations that already hold ISO/IEC 27001 reach ISO/IEC 42001 faster because the clause 4 to 10 management system, internal audit programme, management review and corrective action processes are already running and can be extended in scope.
How many controls does ISO 42001 have?
38 controls, organised under nine control objectives numbered A.2 through A.10: AI policy, internal organisation, resources for AI systems, assessing impacts of AI systems, AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. Annex A is a reference set, not a mandatory checklist; applicability is determined through a Statement of Applicability driven by risk and impact assessment, and exclusions must be justified.
Should we do ISO 42001 or ISO 27001 first?
If you hold neither and your driver is enterprise procurement, ISO/IEC 27001 is usually asked for first and more often. If your driver is specifically AI governance questions in customer due diligence, or you are preparing for the EU AI Act, ISO/IEC 42001 addresses the actual question being asked. Many organisations run an integrated management system covering both, which shares the audit programme and management review.