ISO 27001 vs ISO 42001: Information Security vs AI Governance
TL;DR — ISO 27001 governs information security (ISMS); ISO 42001 governs responsible AI (AIMS). They share the Plan-Do-Check-Act framework and overlap in security controls, but address different domains. ISO 27001 protects confidentiality, integrity, and availability. ISO 42001 addresses AI-specific risks: bias, transparency, accountability, data quality, lifecycle management, and human oversight. If you provide or use AI systems, you need both. A mature ISO 27001 program covers ~40% of ISO 42001's requirements. ISO 42001's Annex A has 39 controls across 9 sections. A mature ISO 42001 program covers ~78% of EU AI Act operational requirements. Implement both together for efficiency — shared clauses, shared audit evidence, shared PDCA cycle.
Two Standards, Two Domains
| Property | ISO 27001 | ISO 42001 |
|---|---|---|
| Full name | ISO/IEC 27001:2022 | ISO/IEC 42001:2023 |
| Domain | Information Security | Artificial Intelligence |
| Management system | ISMS (Information Security Management System) | AIMS (AI Management System) |
| Focus | Confidentiality, integrity, availability | Responsible AI: bias, transparency, accountability |
| Published | 2022 (latest revision) | December 2023 |
| Certification | Widely adopted, expected by enterprise buyers | Emerging, increasingly required in EU procurement |
| Annex A controls | 93 controls in 4 themes | 39 controls in 9 sections |
| Framework | Plan-Do-Check-Act | Plan-Do-Check-Act |
| Voluntary? | Voluntary, but de facto required | Voluntary, but becoming de facto required |
ISO 27001: Information Security Management System (ISMS)
ISO 27001 certifies that an organization has a systematic approach to managing information security risks. It requires:
- Risk assessment and treatment
- Security policies and procedures
- Access control, encryption, incident management
- Supplier relationship security
- Business continuity
- Continuous improvement
The standard is technology-neutral — it doesn't mandate specific tools or products. It requires that the organization identify its risks and implement appropriate controls.
ISO 42001: AI Management System (AIMS)
ISO 42001 is the world's first AI management system standard. It certifies that an organization has a systematic approach to governing AI systems throughout their lifecycle. It requires:
- AI policy and objectives
- AI-specific risk assessment (bias, safety, misuse, data quality)
- AI system impact assessments (AIIA)
- Data governance and quality controls
- Transparency and information provision
- Human oversight mechanisms
- AI lifecycle management (design, development, deployment, monitoring, decommission)
- Third-party AI system assessment
- Performance evaluation and continual improvement
Where They Overlap
The two standards share the same management system architecture (PDCA) and have significant control overlap:
| Shared Area | ISO 27001 | ISO 42001 |
|---|---|---|
| Management system framework | Clauses 4-10 | Clauses 4-10 (identical structure) |
| Risk assessment | Clause 6.1.2 | Clause 6.1 (AI-specific) |
| Policies | Clause 5.2 (ISMS policy) | Clause 5.2 (AI policy) |
| Internal audit | Clause 9.2 | Clause 9.2 |
| Management review | Clause 9.3 | Clause 9.3 |
| Continual improvement | Clause 10 | Clause 10 |
| Competence and training | Clause 7.2 | Clause 7.2 (AI-specific competence) |
| Supplier relationships | Annex A.5.15-22 | Annex A.10 (third-party AI) |
| Incident management | Annex A.5.24-26 | Annex A.8 (AI incidents) |
Key insight: Clauses 4-10 are structurally identical between the two standards. Both follow the ISO high-level structure (HLS). This means your management system framework — context, leadership, planning, support, operation, performance evaluation, improvement — can be shared.
Where They Differ
ISO 27001 Unique Requirements
- Information security risk assessment (assets, threats, vulnerabilities)
- Access control (logical and physical)
- Cryptography and key management
- Network security
- Secure development
- Supplier security assessments
- Business continuity and disaster recovery
- Physical and environmental security
ISO 42001 Unique Requirements
- AI system impact assessment (AIIA): Assess impacts of AI systems on individuals, groups, and society before deployment
- AI lifecycle management: Controls across design, data collection, training, testing, deployment, operation, monitoring, and decommissioning
- Bias and fairness monitoring: Ongoing monitoring for discriminatory outputs
- Transparency and explainability: Document how AI systems make decisions, provide information to users and affected parties
- Human oversight: Ensure humans can override AI decisions, especially in high-risk contexts
- Data quality and provenance: Document data sources, quality measures, and data lineage for AI training
- AI-specific incident management: Handle AI failures, bias incidents, and model drift
- Third-party AI assessment: Evaluate AI systems procured from vendors
- Model evaluation and testing: Performance metrics, robustness testing, edge case handling
ISO 42001 Annex A Controls
Annex A contains 39 control objectives organized into 9 sections:
| Section | Title | Key Controls |
|---|---|---|
| A.2 | Policies related to AI | AI policy, alignment with organizational strategy |
| A.3 | Internal organization | AI roles and responsibilities, AI governance committee |
| A.4 | Resources for AI systems | Resource planning, data resources, computing resources |
| A.5 | Competence and awareness | AI literacy training, role-specific competence |
| A.6 | Communication | Internal and external communication about AI |
| A.7 | Operational planning | AI risk treatment, operational controls, testing |
| A.8 | AI system impact assessment | AIIA, stakeholder impact, affected parties |
| A.9 | Transparency and information | Documentation, user information, explainability |
| A.10 | Third-party and customer relationships | Supplier assessment, contractual requirements, monitoring |
Statement of Applicability (SoA)
The SoA maps every Annex A control to a yes/no/partially-applicable decision with justification. It is:
- The document your auditor will spend the most time on
- The document your buyers will most often request
- The evidence that you thought about each control rather than blanket-asserting compliance
EU AI Act Alignment
ISO 42001 is positioning to be the harmonized standard that demonstrates conformity with key EU AI Act requirements:
| EU AI Act Article | Requirement | ISO 42001 Coverage |
|---|---|---|
| Article 9 | Risk management system | Clause 6.1, Annex A.7 |
| Article 10 | Data and data governance | Annex A.4, A.7 |
| Article 12 | Record keeping and logging | Clause 7.5, Annex A.9 |
| Article 13 | Transparency to users | Annex A.9 |
| Article 14 | Human oversight | Annex A.9 |
| Article 15 | Accuracy, robustness, cybersecurity | Annex A.7, A.8 |
| Article 17 | Quality management system | Clauses 4-10 |
CSA analysis estimate: A mature ISO 42001 program covers roughly 78% of the EU AI Act's operational requirements. The remaining 22% includes EU-specific requirements like CE marking, conformity assessment procedures, and EU database registration that are outside any ISO standard's scope.
Integration Strategy: Implementing Both Together
Step 1: Shared Management System (Clauses 4-10)
Since both standards share the same HLS structure, build one management system that covers both:
Integrated Management System (IMS)
├── Clause 4: Context of the organization
│ ├── ISMS context (information security risks)
│ └── AIMS context (AI risks and impacts)
├── Clause 5: Leadership
│ ├── ISMS policy
│ └── AI policy
├── Clause 6: Planning
│ ├── Information security risk assessment
│ └── AI risk assessment + AIIA
├── Clause 7: Support
│ ├── Resources (shared)
│ ├── Competence (security + AI literacy)
│ ├── Awareness (security + AI ethics)
│ └── Documented information (shared control)
├── Clause 8: Operation
│ ├── Security operations
│ └── AI lifecycle operations
├── Clause 9: Performance evaluation
│ ├── Internal audit (combined)
│ └── Management review (combined)
└── Clause 10: Improvement
├── Nonconformity and corrective action
└── Continual improvement
Step 2: Unified Risk Register
Maintain one risk register that includes both information security risks and AI-specific risks:
risk_register:
- risk_id: "R-001"
type: "information_security"
description: "Unauthorized access to customer database"
iso_standard: "ISO 27001"
treatment: "Access control, encryption, monitoring"
residual_risk: "low"
- risk_id: "R-002"
type: "ai_bias"
description: "LLM produces discriminatory responses for certain demographics"
iso_standard: "ISO 42001"
treatment: "Bias testing, output filtering, human review"
residual_risk: "medium"
- risk_id: "R-003"
type: "ai_data_quality"
description: "Training data contains outdated information causing hallucinations"
iso_standard: "ISO 42001"
treatment: "Data provenance tracking, RAG grounding, freshness checks"
residual_risk: "low"
- risk_id: "R-004"
type: "information_security"
description: "API keys exposed in source code"
iso_standard: "ISO 27001"
treatment: "Secret scanning, vault, CI/CD checks"
residual_risk: "low"
Step 3: Combined Audit Program
Internal audits can cover both standards in a single audit cycle:
audit_program:
- audit_id: "IA-2026-Q3"
scope: "Integrated ISMS + AIMS audit"
standards: ["ISO 27001", "ISO 42001"]
areas:
- "Access control (ISO 27001 A.5.15)"
- "AI system impact assessment (ISO 42001 A.8)"
- "Incident management (ISO 27001 A.5.24 + ISO 42001 A.8)"
- "Supplier assessment (ISO 27001 A.5.19 + ISO 42001 A.10)"
- "Transparency documentation (ISO 42001 A.9)"
auditors: 2
duration_days: 5
Step 4: Unified Statement of Applicability
Create a combined SoA that maps controls from both standards:
| Control | Standard | Applicable | Justification | Implementation |
|---|---|---|---|---|
| A.5.1 Information security policies | ISO 27001 | Yes | Required for ISMS | Security policy document |
| A.2.1 AI policy | ISO 42001 | Yes | Required for AIMS | AI governance policy |
| A.5.15 Access control | ISO 27001 | Yes | Protects information assets | RBAC, MFA, least privilege |
| A.7.1 AI risk treatment | ISO 42001 | Yes | Manages AI-specific risks | AIIA, bias testing, monitoring |
| A.5.19 Supplier security | ISO 27001 | Yes | Third-party risk | Vendor security assessment |
| A.10.1 Third-party AI assessment | ISO 42001 | Yes | AI vendor risk | AI supplier evaluation |
Certification Process
Stage 1: Documentation Review
The auditor reviews your management system documentation:
- AI policy and ISMS policy
- Risk register (security + AI)
- Statement of Applicability (both standards)
- AIIA documents
- Internal audit reports
- Management review minutes
Duration: 1-2 days
Stage 2: On-Site Audit
The auditor interviews staff, reviews evidence, samples artifacts, and verifies the management system operates in practice:
- Do employees actually follow the AI policy?
- Are AIIAs completed before AI system deployment?
- Is bias monitoring actually running?
- Are third-party AI systems assessed before procurement?
- Are AI incidents logged and treated?
Duration: 3-10 days depending on scope
Common findings:
- Empty CAPA (Corrective and Preventive Action) log
- Vacuous AIIA (checked boxes without real analysis)
- Missing training records
- No evidence of bias monitoring in practice
Certification and Surveillance
- Certification valid for 3 years
- Annual surveillance audits
- Re-certification audit at year 3
Common Mistakes
Treating ISO 42001 as "ISO 27001 for AI"
ISO 42001 is not a security standard with AI controls bolted on. It addresses fundamentally different concerns: bias, fairness, transparency, accountability, and societal impact. Implementing it as a security extension misses the point.
Blanket-Asserting All Controls
Marking every Annex A control as "applicable" and "implemented" without real analysis. Auditors check for evidence — an empty AIIA or a vacuous risk assessment is a major nonconformity.
No AI-Specific Risk Assessment
Using the ISO 27001 information security risk assessment for ISO 42001. AI risks (bias, hallucination, model drift, data poisoning) are different from security risks (unauthorized access, data breach).
No Evidence of Operation
Having policies and procedures on paper but no evidence they're followed. The Stage 2 audit checks for operational evidence — completed AIIAs, bias monitoring logs, training records, incident reports.
Not Assessing Third-Party AI
Deploying an AI system from a vendor without assessing it. ISO 42001 Annex A.10 requires assessment of third-party AI systems before deployment and ongoing monitoring after.
Implementation Checklist
- [ ] Establish an AI policy (ISO 42001 Clause 5.2)
- [ ] Define AI roles and responsibilities (Annex A.3)
- [ ] Conduct AI-specific risk assessment (Clause 6.1)
- [ ] Perform AI system impact assessments (AIIA) for each AI system (Annex A.8)
- [ ] Document data sources, quality measures, and provenance (Annex A.4)
- [ ] Implement bias and fairness monitoring (Annex A.7)
- [ ] Establish transparency documentation (Annex A.9)
- [ ] Implement human oversight mechanisms (Annex A.9)
- [ ] Define AI lifecycle controls (Annex A.7)
- [ ] Assess third-party AI systems before deployment (Annex A.10)
- [ ] Include AI-specific clauses in vendor contracts (Annex A.10.2)
- [ ] Monitor third-party AI systems after deployment (Annex A.10.3)
- [ ] Create a unified risk register (security + AI risks)
- [ ] Build a combined Statement of Applicability (both standards)
- [ ] Implement AI literacy training (Annex A.5)
- [ ] Define AI incident management procedures (Annex A.8)
- [ ] Conduct combined internal audits (ISMS + AIMS)
- [ ] Hold combined management reviews
- [ ] Maintain CAPA log with evidence of corrective actions
- [ ] Map controls to EU AI Act articles for compliance alignment
- [ ] Document the integration approach for auditors
- [ ] Prepare evidence packs for Stage 2 audit
- [ ] Test bias monitoring with real AI systems
- [ ] Verify AIIAs are completed before deployment
- [ ] Review and update SoA annually
Conclusion
ISO 27001 and ISO 42001 are complementary, not competing. ISO 27001 protects your information assets. ISO 42001 governs your AI systems. If you provide or use AI systems, you need both — and implementing them together is more efficient than implementing them separately.
The shared Plan-Do-Check-Act framework, identical clause structure (4-10), and overlapping controls mean you can build one integrated management system that satisfies both standards. A unified risk register, combined audit program, and integrated Statement of Applicability reduce duplication while ensuring comprehensive coverage.
ISO 42001 is positioning to be the harmonized standard for EU AI Act conformity. A mature program covers 78% of the Act's operational requirements. It's increasingly referenced in EU public procurement and enterprise vendor qualification. For organizations selling AI capabilities to public sector buyers or large enterprises, ISO 42001 is becoming a de facto requirement.
The investment in dual certification — typically 6-12 months for organizations with existing ISO 27001 — pays off in enterprise deals, regulatory alignment, and customer trust. The cost of not having it: lost deals, compliance gaps, and the scramble to implement under audit pressure.