Compare · 03
As of September 2026
Comply · ISO 42001 · AI Governance · AI Security Assessment
Two systems,
or one?
AI management system (AIMS). Published December 2023. How you govern the AI you develop, provide or use.
Information security management system (ISMS). Current edition 2022, amended in 2024. How you protect information, AI or not.
01 · Side by side
Same skeleton,
different organs.
Both follow ISO’s harmonized structure for management systems, so clauses 4 to 10 line up. The difference is what they protect, and what their Annex A asks you to control.
| Dimension | ISO/IEC 42001 | ISO/IEC 27001 |
|---|---|---|
| Protects | People, groups and society from the effects of AI systems, and the organisation’s objectives | Confidentiality, integrity and availability of information |
| Scope | The AI systems you develop, provide or use, and your role for each | Information, and the processes, people and technology that handle it |
| Structure | Harmonized structure, clauses 4 to 10 | Harmonized structure, clauses 4 to 10 |
| Risk | AI risk assessment and treatment (6.1.2, 6.1.3) | Information security risk assessment and treatment (6.1.2, 6.1.3) |
| Only here | AI system impact assessment on individuals, groups and society (6.1.4, 8.4) | No equivalent. Security risk is about the organisation’s information. |
| Annex A | 38 controls under 9 control objectives, A.2 to A.10 | 93 controls in 4 themes: organisational, people, physical, technological |
| Statement of applicability | Required, against Annex A | Required, against Annex A |
| Guidance | Annex B, inside the standard, normative | ISO/IEC 27002, a separate standard |
| Certification | Accredited certification bodies; ISO/IEC 42006 (2025) sets extra requirements for them | Accredited certification bodies; ISO/IEC 27006-1 (2024) sets extra requirements for them |
| Who asks for it | Customers and tenders where AI is the product or the risk. Newer, still spreading. | Most B2B security questionnaires. Established for years. |
02 · When to pick which
Which one
first.
The order depends on who is asking, and on what AI is for you.
42001 first when
- 01AI is your product, or part of it
Customers will ask how you govern it, not only how you secure it.
- 02A tender asks for ISO/IEC 42001 by name
Then the order is decided for you.
- 03You already hold 27001
Most of the management system exists. The gap is the AI part.
- 04You are preparing for the EU AI Act
42001 helps you produce evidence the Act asks for. It is not proof of compliance.
27001 first when
- 01Customers send security questionnaires and want a certificate
27001 is the one most procurement teams already know.
- 02You use AI mostly as a tool, and your main worry is data leaking
Security controls first. Put the AI tools in the ISMS scope and risk register.
- 03You have no management system at all yet, and no AI in your products
Start with the broader base. 42001 later reuses most of the system.
And Both at once works too: one integrated management system with two scopes, one policy set, one risk process with two lenses, one audit programme.
03 · Decide
Four questions,
one order.
Answer all four for a recommended order, and the service that fits.
01Do you hold ISO/IEC 27001 today?
02What is AI for you?
03Who is asking for what?
04Is any of your systems high-risk under the EU AI Act?
04 · Together
One management system,
two certificates.
The harmonized structure is why the two stack. What you can merge, what stays separate, and where the controls meet.
- 4Context
Issues, interested parties, scope, the system itself
The intended purpose of your AI systems, and your role for each
- 5Leadership
Commitment, policy, roles and authorities
An AI policy
- 6Planning
Risks and opportunities, objectives, planning of changes
AI risk criteria and the AI system impact assessment (6.1.4)
- 7Support
Resources, competence, awareness, communication, documented information
- 8Operation
Operational control, running the risk assessment and treatment
Running the impact assessments (8.4)
- 9Performance evaluation
Monitoring, internal audit, management review
- 10Improvement
Nonconformity, corrective action, continual improvement
Annex A, to scale
ISO/IEC 27001:202293 controls · 4 themes
- 5Organisational 37
- 6People 8
- 7Physical 14
- 8Technological 34
ISO/IEC 42001:202338 controls · 9 objectives
- A.2Policies related to AI 3
- A.3Internal organisation 2
- A.4Resources for AI systems 5
- A.5Assessing impacts 4
- A.6AI system life cycle 9
- A.7Data for AI systems 5
- A.8Information for interested parties 4
- A.9Use of AI systems 3
- A.10Third parties and customers 3
- One policy frameworkISO/IEC 42001AI policy (5.2), aligned with other policiesISO/IEC 27001Information security policy (5.2)merge
- One risk process, two lensesISO/IEC 42001AI risks, plus impact on people (6.1.2 to 6.1.4)ISO/IEC 27001Information security risks (6.1.2, 6.1.3)merge
- One audit programme, one reviewISO/IEC 42001Internal audit and management review (9.2, 9.3)ISO/IEC 27001Internal audit and management review (9.2, 9.3)merge
- Statements of applicabilityISO/IEC 42001Against the 38 AI controlsISO/IEC 27001Against the 93 security controlsseparate
- SuppliersISO/IEC 42001Third-party and customer relationships (A.10)ISO/IEC 27001Supplier relationships and cloud services (5.19 to 5.23)partial
- DataISO/IEC 42001Data for AI systems: quality, provenance, preparation (A.7)ISO/IEC 27001Classification, privacy and protection of PII, data leakage prevention (5.12, 5.34, 8.12)partial
- LogsISO/IEC 42001AI system recording of event logs (A.6.2.8)ISO/IEC 27001Logging (8.15)partial
Merge: one process or document serves both. Partial: related controls, different questions. Separate: required per standard. Clause and control numbers from the 2023 and 2022 editions.
05 · Questions
Asked by
every auditor.
Doesn’t ISO 27001 already cover AI?
Partly. It secures the information AI systems use and produce. It doesn’t ask about impact on people, bias, transparency or the AI life cycle. That is the gap 42001 fills.
Can we get both certificates in one audit?
Combined audits of an integrated management system are possible if the certification body is accredited for both standards. Ask for it explicitly, and expect two certificates.
How much of our ISMS can we reuse?
The clause structure is the same, so policies, document control, competence, internal audit and management review carry over. The AI-specific work is the risk criteria, the impact assessment and the controls on the AI life cycle and data.
Is ISO 42001 proof of EU AI Act compliance?
No. It helps you produce evidence, but the Act is checked per system, against the law. More on the EU AI Act vs. ISO 42001 page.
Which version of 27001 is current?
ISO/IEC 27001:2022, with Amendment 1 from 2024 on climate action. Certificates to the 2013 version had to transition by 31 October 2025 under the accreditation rules (IAF MD 26).
What is the harmonized structure?
The shared clause layout, titles, core text and terms ISO uses for all management system standards, set out in Annex SL of the ISO/IEC Directives. Formerly called the high-level structure. It is why 9001, 27001 and 42001 fit on top of each other.
ISO/IEC
One system,
two audits.
Start with a gap analysis against both. It shows how much of your ISMS already counts.