Already certified for ISO 27001? This guide shows exactly what ISO 42001 adds, what you can reuse from your existing ISMS, and how to plan a combined certification programme.
This article provides educational guidance on ISO standards. ISO standard documents require purchase for full text access. This content is for practitioner orientation and does not constitute certification advice.The Short Version
ISO 27001 covers the confidentiality, integrity, and availability of information assets. ISO 42001 covers responsible development and deployment of AI systems — including fairness, transparency, human oversight, and AI supply chain risks. They share the same management system backbone (the ISO Annex SL / ISO harmonised structure), which means organisations with 27001 can integrate 42001 without starting from scratch.
If you already hold ISO 27001, roughly 40-50% of your existing management system directly supports ISO 42001 compliance. The remaining work is the AI-specific additions that 27001 does not address.
Side-by-Side at a Glance
| Dimension | ISO/IEC 27001:2022 | ISO/IEC 42001:2023 |
|---|---|---|
| Focus | Information security — confidentiality, integrity, availability of information assets | Responsible AI — governance, transparency, fairness, human oversight of AI systems |
| Published | 2022 (replacing 2013 version) | December 2023 (first version) |
| Certifiable? | Yes — widely recognised, thousands of accredited certification bodies | Yes — accredited certification bodies increasingly available (still limited as of 2025-2026) |
| Scope | All information assets, systems, and processes that handle information of value | All AI systems designed, developed, or deployed by the organisation |
| Primary audience | IT, security, compliance teams | AI/ML engineers, product teams, risk and compliance, C-suite |
| Key risk concern | Security incidents, breaches, unauthorised access, data loss | Algorithmic bias, model failure, misuse, lack of transparency, AI supply chain risk |
| Controls format | Annex A — 93 controls across 4 themes (organisational, people, physical, technological) | Annex A — 38 AI-specific controls across 10 categories |
| Existing regulators reference it? | Widely referenced in contracts, procurement, regulatory frameworks (GDPR, NIS2) | Increasingly referenced — EU AI Act guidance suggests it as an implementation pathway for high-risk AI systems |
What ISO 27001 Already Covers (Reusable for 42001)
Because both standards use the ISO Harmonised Structure (formerly Annex SL), clauses 4 through 10 have the same logical structure in both. Your existing 27001 processes provide a direct foundation:
| Clause | 27001 artefact you already have | What 42001 requires in addition |
|---|---|---|
| 4 (Context) | Stakeholder register, scope statement, internal/external issue analysis | Add AI-specific context: AI system inventory, AI-related stakeholder concerns, intended and unintended AI use cases |
| 5 (Leadership) | Information security policy, ISMS roles and responsibilities | Add AI policy covering responsible use principles, AI-specific roles (AI risk owner, responsible AI lead) |
| 6 (Planning) | Risk assessment methodology, risk treatment plan, ISMS objectives | Apply risk methodology to AI-specific risks (algorithmic bias, model failure, misuse). Add AI impact assessment process. |
| 7 (Support) | Competence requirements, awareness training, documented information controls | Add AI literacy training programme. Document AI-specific competence requirements for different roles. |
| 9 (Performance evaluation) | Internal audit programme, management review | Extend audit scope to include AI-specific controls. Add AI performance metrics to management review agenda. |
| 10 (Improvement) | Nonconformity and corrective action process, continual improvement | Same process — extend to cover AI-specific nonconformities (e.g., discovered bias, model failure, misuse incident). |
If your 27001 management review already covers risk landscape changes, you are 80% of the way to meeting clause 9.3 of 42001. The main addition is including AI-specific risk indicators (model performance, fairness metrics, AI incident log) on the management review agenda.What ISO 42001 Adds That 27001 Does Not Cover
Clause 8 (Operation) is where the two standards diverge most significantly. ISO 42001 requires:
Clause 8.4: AI System Impact Assessment
Before deploying an AI system, or when making significant changes, organisations must conduct an impact assessment covering potential harms to individuals and society. This is analogous to a DPIA (Data Protection Impact Assessment) under GDPR, but broader — it covers fairness, transparency, and societal impacts beyond data privacy.
The assessment must document: the intended use, known limitations, potential for misuse, impact on affected individuals, and mitigation measures. It must be reviewed and updated when the system changes significantly.
Clause 8.5: AI System Lifecycle Management
ISO 42001 requires documented processes covering the full AI system lifecycle from design through decommissioning. ISO 27001's system development lifecycle controls (A.8.25-A.8.32) cover security in development but do not address the AI-specific lifecycle phases. The 42001 lifecycle requirements include:
- Design objectives and requirements documentation (including fairness and transparency objectives).
- Data management requirements for training, validation, and test datasets.
- Model development and training controls, including model selection rationale.
- Testing and validation against stated design objectives.
- Deployment controls including monitoring setup.
- Operation and performance monitoring throughout the deployment life.
- Decommissioning and data retention/deletion processes.
The AI-Specific Annex A Controls
ISO 42001 Annex A contains 38 controls across 10 categories. Here are the categories that have no meaningful equivalent in ISO 27001:
| Annex A category | Key controls (selected) | 27001 equivalent? |
|---|---|---|
| A.5: Impact of AI systems on individuals or groups | AI impact assessment process, criteria for assessing societal impact, stakeholder consultation process | No — DPIA under GDPR is adjacent but narrower |
| A.6: AI system lifecycle | Design objectives documentation, data requirements specification, model development controls, AI testing and validation | Partial — 27001 covers security in SDLC but not AI-specific lifecycle phases |
| A.7: Data for AI systems | Training data governance, data quality criteria, labelling policies, dataset bias assessment | Partial — 27001 covers data classification and access control but not training data quality/bias |
| A.8: Transparency and information for AI users and affected parties | User documentation of AI limitations and intended use, explainability controls, communication of AI system changes | No — no equivalent transparency controls in 27001 |
| A.9: Use of AI systems by interested parties | User guidance, feedback mechanisms, controls on use beyond intended purpose | Partial — 27001 has user access controls but not AI-specific user guidance requirements |
| A.10: Third-party and customer AI relationships | AI supplier assessment, contractual AI governance requirements, customer communication of AI use | Partial — 27001 has supplier security controls; 42001 extends this to AI-specific risk in the supply chain |
Integration Strategy for Dual Certification
The most efficient path for organisations with existing ISO 27001 certification is an integrated management system approach. Both standards support this — ISO explicitly designed them to be combinable.
Recommended integration approach
- Extend your ISMS scope to explicitly include AI systems. Update the scope statement to cover AI system development, deployment, and operation.
- Conduct a gap analysis against ISO 42001 Annex A using your existing 27001 control set as the baseline. Map what you have against what is required.
- Add AI-specific policies to your existing policy suite: AI use policy, responsible AI principles, AI impact assessment procedure.
- Extend your risk assessment process to include AI-specific risk categories. Use the same methodology — just apply it to AI system risks as a new asset category.
- Build out the AI system lifecycle controls (Clause 8.5) as additions to your existing SDLC documentation.
- Train your internal auditors on AI-specific controls before your first combined audit.
Combined audit scope
When you go for ISO 42001 certification with an existing 27001 certificate, certification bodies can conduct a combined audit. The auditor will review your 27001 controls as supporting evidence where they overlap, and separately assess the AI-specific controls. This reduces the audit duration compared to treating them as entirely separate programmes.
Approach certification bodies that already hold ISO 27001 and AI-related audit accreditations. A combined audit with an auditor who understands both standards is more efficient than two separate engagements with different teams.Estimated Effort for ISO 42001 Given Existing ISO 27001
| Work area | Estimated effort (with 27001 in place) | Without 27001 |
|---|---|---|
| Management system backbone (clauses 4-10) | Low — extend existing documents and processes | High — build from scratch |
| AI impact assessment process | Medium — new process, no 27001 equivalent | Medium — same |
| AI system lifecycle documentation | Medium — new, builds on existing SDLC docs | High — no baseline |
| AI-specific Annex A controls (A.5-A.10) | Medium — significant new content in A.7 and A.8 | High — no baseline |
| AI system inventory | Medium — likely missing even with 27001 | High |
| AI literacy training | Low-medium — extend existing security awareness programme | Medium |
| Internal audit extension | Low — extend existing audit programme and checklists | Medium |
| Total indicative effort (FTEs months) | 3-6 months, 1-2 FTE | 9-18 months, 2-3 FTE |
What to Do First
- Build your AI system inventory. You cannot certify a scope you have not defined. Catalogue every AI system your organisation designs, develops, or deploys.
- Run the gap analysis against Annex A. Use your 27001 control set as the baseline. The gap will be largest in A.5 through A.10.
- Prioritise the impact assessment process (Clause 8.4). Certification auditors spend significant time on this. It is also the most valuable addition to your actual governance practice.
- Check certification body availability. ISO 42001 certification is newer and fewer accredited bodies offer it. Confirm your preferred certification body's timeline and pricing before committing to a target date.