ISO 27001 vs ISO 42001: Information Security vs AI Governance

TL;DR — ISO 27001 governs information security (ISMS); ISO 42001 governs responsible AI (AIMS). They share the Plan-Do-Check-Act framework and overlap in security controls, but address different domains. ISO 27001 protects confidentiality, integrity, and availability. ISO 42001 addresses AI-specific risks: bias, transparency, accountability, data quality, lifecycle management, and human oversight. If you provide or use AI systems, you need both. A mature ISO 27001 program covers ~40% of ISO 42001's requirements. ISO 42001's Annex A has 39 controls across 9 sections. A mature ISO 42001 program covers ~78% of EU AI Act operational requirements. Implement both together for efficiency — shared clauses, shared audit evidence, shared PDCA cycle.

Two Standards, Two Domains

Property ISO 27001 ISO 42001
Full name ISO/IEC 27001:2022 ISO/IEC 42001:2023
Domain Information Security Artificial Intelligence
Management system ISMS (Information Security Management System) AIMS (AI Management System)
Focus Confidentiality, integrity, availability Responsible AI: bias, transparency, accountability
Published 2022 (latest revision) December 2023
Certification Widely adopted, expected by enterprise buyers Emerging, increasingly required in EU procurement
Annex A controls 93 controls in 4 themes 39 controls in 9 sections
Framework Plan-Do-Check-Act Plan-Do-Check-Act
Voluntary? Voluntary, but de facto required Voluntary, but becoming de facto required

ISO 27001: Information Security Management System (ISMS)

ISO 27001 certifies that an organization has a systematic approach to managing information security risks. It requires:
- Risk assessment and treatment
- Security policies and procedures
- Access control, encryption, incident management
- Supplier relationship security
- Business continuity
- Continuous improvement

The standard is technology-neutral — it doesn't mandate specific tools or products. It requires that the organization identify its risks and implement appropriate controls.

ISO 42001: AI Management System (AIMS)

ISO 42001 is the world's first AI management system standard. It certifies that an organization has a systematic approach to governing AI systems throughout their lifecycle. It requires:
- AI policy and objectives
- AI-specific risk assessment (bias, safety, misuse, data quality)
- AI system impact assessments (AIIA)
- Data governance and quality controls
- Transparency and information provision
- Human oversight mechanisms
- AI lifecycle management (design, development, deployment, monitoring, decommission)
- Third-party AI system assessment
- Performance evaluation and continual improvement

Where They Overlap

The two standards share the same management system architecture (PDCA) and have significant control overlap:

Shared Area ISO 27001 ISO 42001
Management system framework Clauses 4-10 Clauses 4-10 (identical structure)
Risk assessment Clause 6.1.2 Clause 6.1 (AI-specific)
Policies Clause 5.2 (ISMS policy) Clause 5.2 (AI policy)
Internal audit Clause 9.2 Clause 9.2
Management review Clause 9.3 Clause 9.3
Continual improvement Clause 10 Clause 10
Competence and training Clause 7.2 Clause 7.2 (AI-specific competence)
Supplier relationships Annex A.5.15-22 Annex A.10 (third-party AI)
Incident management Annex A.5.24-26 Annex A.8 (AI incidents)

Key insight: Clauses 4-10 are structurally identical between the two standards. Both follow the ISO high-level structure (HLS). This means your management system framework — context, leadership, planning, support, operation, performance evaluation, improvement — can be shared.

Where They Differ

ISO 27001 Unique Requirements

  • Information security risk assessment (assets, threats, vulnerabilities)
  • Access control (logical and physical)
  • Cryptography and key management
  • Network security
  • Secure development
  • Supplier security assessments
  • Business continuity and disaster recovery
  • Physical and environmental security

ISO 42001 Unique Requirements

  • AI system impact assessment (AIIA): Assess impacts of AI systems on individuals, groups, and society before deployment
  • AI lifecycle management: Controls across design, data collection, training, testing, deployment, operation, monitoring, and decommissioning
  • Bias and fairness monitoring: Ongoing monitoring for discriminatory outputs
  • Transparency and explainability: Document how AI systems make decisions, provide information to users and affected parties
  • Human oversight: Ensure humans can override AI decisions, especially in high-risk contexts
  • Data quality and provenance: Document data sources, quality measures, and data lineage for AI training
  • AI-specific incident management: Handle AI failures, bias incidents, and model drift
  • Third-party AI assessment: Evaluate AI systems procured from vendors
  • Model evaluation and testing: Performance metrics, robustness testing, edge case handling

ISO 42001 Annex A Controls

Annex A contains 39 control objectives organized into 9 sections:

Section Title Key Controls
A.2 Policies related to AI AI policy, alignment with organizational strategy
A.3 Internal organization AI roles and responsibilities, AI governance committee
A.4 Resources for AI systems Resource planning, data resources, computing resources
A.5 Competence and awareness AI literacy training, role-specific competence
A.6 Communication Internal and external communication about AI
A.7 Operational planning AI risk treatment, operational controls, testing
A.8 AI system impact assessment AIIA, stakeholder impact, affected parties
A.9 Transparency and information Documentation, user information, explainability
A.10 Third-party and customer relationships Supplier assessment, contractual requirements, monitoring

Statement of Applicability (SoA)

The SoA maps every Annex A control to a yes/no/partially-applicable decision with justification. It is:
- The document your auditor will spend the most time on
- The document your buyers will most often request
- The evidence that you thought about each control rather than blanket-asserting compliance

EU AI Act Alignment

ISO 42001 is positioning to be the harmonized standard that demonstrates conformity with key EU AI Act requirements:

EU AI Act Article Requirement ISO 42001 Coverage
Article 9 Risk management system Clause 6.1, Annex A.7
Article 10 Data and data governance Annex A.4, A.7
Article 12 Record keeping and logging Clause 7.5, Annex A.9
Article 13 Transparency to users Annex A.9
Article 14 Human oversight Annex A.9
Article 15 Accuracy, robustness, cybersecurity Annex A.7, A.8
Article 17 Quality management system Clauses 4-10

CSA analysis estimate: A mature ISO 42001 program covers roughly 78% of the EU AI Act's operational requirements. The remaining 22% includes EU-specific requirements like CE marking, conformity assessment procedures, and EU database registration that are outside any ISO standard's scope.

Integration Strategy: Implementing Both Together

Step 1: Shared Management System (Clauses 4-10)

Since both standards share the same HLS structure, build one management system that covers both:

Integrated Management System (IMS)
    ├── Clause 4: Context of the organization
    │   ├── ISMS context (information security risks)
    │   └── AIMS context (AI risks and impacts)
    ├── Clause 5: Leadership
    │   ├── ISMS policy
    │   └── AI policy
    ├── Clause 6: Planning
    │   ├── Information security risk assessment
    │   └── AI risk assessment + AIIA
    ├── Clause 7: Support
    │   ├── Resources (shared)
    │   ├── Competence (security + AI literacy)
    │   ├── Awareness (security + AI ethics)
    │   └── Documented information (shared control)
    ├── Clause 8: Operation
    │   ├── Security operations
    │   └── AI lifecycle operations
    ├── Clause 9: Performance evaluation
    │   ├── Internal audit (combined)
    │   └── Management review (combined)
    └── Clause 10: Improvement
        ├── Nonconformity and corrective action
        └── Continual improvement

Step 2: Unified Risk Register

Maintain one risk register that includes both information security risks and AI-specific risks:

risk_register:
  - risk_id: "R-001"
    type: "information_security"
    description: "Unauthorized access to customer database"
    iso_standard: "ISO 27001"
    treatment: "Access control, encryption, monitoring"
    residual_risk: "low"

  - risk_id: "R-002"
    type: "ai_bias"
    description: "LLM produces discriminatory responses for certain demographics"
    iso_standard: "ISO 42001"
    treatment: "Bias testing, output filtering, human review"
    residual_risk: "medium"

  - risk_id: "R-003"
    type: "ai_data_quality"
    description: "Training data contains outdated information causing hallucinations"
    iso_standard: "ISO 42001"
    treatment: "Data provenance tracking, RAG grounding, freshness checks"
    residual_risk: "low"

  - risk_id: "R-004"
    type: "information_security"
    description: "API keys exposed in source code"
    iso_standard: "ISO 27001"
    treatment: "Secret scanning, vault, CI/CD checks"
    residual_risk: "low"

Step 3: Combined Audit Program

Internal audits can cover both standards in a single audit cycle:

audit_program:
  - audit_id: "IA-2026-Q3"
    scope: "Integrated ISMS + AIMS audit"
    standards: ["ISO 27001", "ISO 42001"]
    areas:
      - "Access control (ISO 27001 A.5.15)"
      - "AI system impact assessment (ISO 42001 A.8)"
      - "Incident management (ISO 27001 A.5.24 + ISO 42001 A.8)"
      - "Supplier assessment (ISO 27001 A.5.19 + ISO 42001 A.10)"
      - "Transparency documentation (ISO 42001 A.9)"
    auditors: 2
    duration_days: 5

Step 4: Unified Statement of Applicability

Create a combined SoA that maps controls from both standards:

Control Standard Applicable Justification Implementation
A.5.1 Information security policies ISO 27001 Yes Required for ISMS Security policy document
A.2.1 AI policy ISO 42001 Yes Required for AIMS AI governance policy
A.5.15 Access control ISO 27001 Yes Protects information assets RBAC, MFA, least privilege
A.7.1 AI risk treatment ISO 42001 Yes Manages AI-specific risks AIIA, bias testing, monitoring
A.5.19 Supplier security ISO 27001 Yes Third-party risk Vendor security assessment
A.10.1 Third-party AI assessment ISO 42001 Yes AI vendor risk AI supplier evaluation

Certification Process

Stage 1: Documentation Review

The auditor reviews your management system documentation:
- AI policy and ISMS policy
- Risk register (security + AI)
- Statement of Applicability (both standards)
- AIIA documents
- Internal audit reports
- Management review minutes

Duration: 1-2 days

Stage 2: On-Site Audit

The auditor interviews staff, reviews evidence, samples artifacts, and verifies the management system operates in practice:
- Do employees actually follow the AI policy?
- Are AIIAs completed before AI system deployment?
- Is bias monitoring actually running?
- Are third-party AI systems assessed before procurement?
- Are AI incidents logged and treated?

Duration: 3-10 days depending on scope

Common findings:
- Empty CAPA (Corrective and Preventive Action) log
- Vacuous AIIA (checked boxes without real analysis)
- Missing training records
- No evidence of bias monitoring in practice

Certification and Surveillance

  • Certification valid for 3 years
  • Annual surveillance audits
  • Re-certification audit at year 3

Common Mistakes

Treating ISO 42001 as "ISO 27001 for AI"

ISO 42001 is not a security standard with AI controls bolted on. It addresses fundamentally different concerns: bias, fairness, transparency, accountability, and societal impact. Implementing it as a security extension misses the point.

Blanket-Asserting All Controls

Marking every Annex A control as "applicable" and "implemented" without real analysis. Auditors check for evidence — an empty AIIA or a vacuous risk assessment is a major nonconformity.

No AI-Specific Risk Assessment

Using the ISO 27001 information security risk assessment for ISO 42001. AI risks (bias, hallucination, model drift, data poisoning) are different from security risks (unauthorized access, data breach).

No Evidence of Operation

Having policies and procedures on paper but no evidence they're followed. The Stage 2 audit checks for operational evidence — completed AIIAs, bias monitoring logs, training records, incident reports.

Not Assessing Third-Party AI

Deploying an AI system from a vendor without assessing it. ISO 42001 Annex A.10 requires assessment of third-party AI systems before deployment and ongoing monitoring after.

Implementation Checklist

  • [ ] Establish an AI policy (ISO 42001 Clause 5.2)
  • [ ] Define AI roles and responsibilities (Annex A.3)
  • [ ] Conduct AI-specific risk assessment (Clause 6.1)
  • [ ] Perform AI system impact assessments (AIIA) for each AI system (Annex A.8)
  • [ ] Document data sources, quality measures, and provenance (Annex A.4)
  • [ ] Implement bias and fairness monitoring (Annex A.7)
  • [ ] Establish transparency documentation (Annex A.9)
  • [ ] Implement human oversight mechanisms (Annex A.9)
  • [ ] Define AI lifecycle controls (Annex A.7)
  • [ ] Assess third-party AI systems before deployment (Annex A.10)
  • [ ] Include AI-specific clauses in vendor contracts (Annex A.10.2)
  • [ ] Monitor third-party AI systems after deployment (Annex A.10.3)
  • [ ] Create a unified risk register (security + AI risks)
  • [ ] Build a combined Statement of Applicability (both standards)
  • [ ] Implement AI literacy training (Annex A.5)
  • [ ] Define AI incident management procedures (Annex A.8)
  • [ ] Conduct combined internal audits (ISMS + AIMS)
  • [ ] Hold combined management reviews
  • [ ] Maintain CAPA log with evidence of corrective actions
  • [ ] Map controls to EU AI Act articles for compliance alignment
  • [ ] Document the integration approach for auditors
  • [ ] Prepare evidence packs for Stage 2 audit
  • [ ] Test bias monitoring with real AI systems
  • [ ] Verify AIIAs are completed before deployment
  • [ ] Review and update SoA annually

Conclusion

ISO 27001 and ISO 42001 are complementary, not competing. ISO 27001 protects your information assets. ISO 42001 governs your AI systems. If you provide or use AI systems, you need both — and implementing them together is more efficient than implementing them separately.

The shared Plan-Do-Check-Act framework, identical clause structure (4-10), and overlapping controls mean you can build one integrated management system that satisfies both standards. A unified risk register, combined audit program, and integrated Statement of Applicability reduce duplication while ensuring comprehensive coverage.

ISO 42001 is positioning to be the harmonized standard for EU AI Act conformity. A mature program covers 78% of the Act's operational requirements. It's increasingly referenced in EU public procurement and enterprise vendor qualification. For organizations selling AI capabilities to public sector buyers or large enterprises, ISO 42001 is becoming a de facto requirement.

The investment in dual certification — typically 6-12 months for organizations with existing ISO 27001 — pays off in enterprise deals, regulatory alignment, and customer trust. The cost of not having it: lost deals, compliance gaps, and the scramble to implement under audit pressure.