Comply · ISO 42001

    We already have ISO 27001. What does 42001 actually add?

    Your ISMS carries more weight than most auditors admit. But AI systems bring risks an information security management system was never built to catch — and pretending otherwise gets flagged in the first surveillance audit.

    Last reviewed:

    Sound familiar?

    • Teams assume 27001 controls (access management, incident response, supplier review) simply transfer — most do, some don't.
    • 27001 has no concept of an AI impact assessment, a model, or a training dataset — 42001 requires all three.
    • Human oversight of automated decisions is not an information security concern, so your existing ISMS says nothing about it.
    • Third-party model risk (a vendor's foundation model, a fine-tune, an API you call) needs its own supplier due diligence, distinct from your current supplier security review.

    What we do

    Control mapping

    A clause-by-clause comparison of what your existing ISMS documentation already satisfies and what is genuinely new.

    AI-specific gaps

    Impact assessment process, data and model lifecycle management, and human oversight mechanisms — the parts with no 27001 equivalent.

    Third-party model risk

    A due diligence process for vendor models and APIs that plugs into your existing supplier management, not a parallel one.

    Integrated management system

    One set of policies and one internal audit programme covering both standards, so you are not running two ISMS-shaped bureaucracies.

    Questions we get

    Can we just extend our existing ISMS scope statement?

    Usually yes — most certification bodies accept an integrated management system covering both standards, provided the AI-specific controls are demonstrably in place, not just referenced.

    Does our existing internal audit team need new training?

    They need to understand what an AI impact assessment and a model lifecycle record look like. The audit methodology itself does not change.

    Will our current risk register work for 42001?

    The structure usually works. The content needs new risk categories — fairness, robustness, and oversight failure are not information security risks in the traditional sense.

    What if we don't have ISO 27001 at all?

    Then this comparison isn't for you — start with our general gap analysis, which builds the AI management system from nothing rather than from an existing ISMS.

    Tell us what's running in production.

    We'll tell you what we'd check first — and what we wouldn't bother with.

    Book a call
    Related
    More in Comply