The difference in one line

ISO 27001
Information Security

Protects the confidentiality, integrity, and availability of all information assets across the organization.

Applies to: databases, networks, systems, people, processes
ISO 42001
AI Governance

Establishes how to design, develop, deploy, and monitor artificial intelligence systems responsibly.

Applies to: AI models, decision algorithms, automated systems

What each standard covers

ISO 27001
ISO 42001
Primary object
Information Security Management System (ISMS)
AI Management System (AIMS)
Current version
ISO/IEC 27001:2022
ISO/IEC 42001:2023
What it manages
Security risk: confidentiality, integrity, availability
AI risk: bias, opacity, rights impact, model performance
Annex A controls
93 information security controls
38 AI governance controls
Algorithmic impact assessment
Not specific to AI
✓ Required — §8.2 + Annex A.5
Decision explainability
Not applicable
✓ Explicit requirement — Annex A.6.1.2
AI systems inventory
Information asset inventory (Control 5.9)
✓ Inventory with AI risk classification — Annex A.4
People's rights
Partial — related to privacy
✓ Impact on fundamental rights, fairness, non-discrimination
EU AI Act alignment
Low — provides technical support but does not cover AI obligations
✓ High — mappable to high-risk AI requirements (Art. 9–12)
Accredited certification
✓ Extensive — thousands of bodies worldwide
✓ Growing — SGS, Bureau Veritas, TÜV SÜD, LRQA

What they share (and why it is an advantage)

Both standards use the High Level Structure (HLS) — the same clause structure from 4 to 10. This means that if you already have ISO 27001, you can directly reuse:

  • Organizational context (§4) — stakeholders, management system scope
  • Leadership (§5) — management policy, roles and responsibilities
  • Planning (§6) — risk assessment methodology (adaptable to AI risks)
  • Support (§7) — document management, competence, communication
  • Management review (§9.3) — the same process applies to both standards
  • Internal audit (§9.2) — shareable audit program
  • Non-conformities and corrective actions (§10) — identical procedure in structure
Efficiency estimate: Organizations with ISO 27001 already implemented can reduce ISO 42001 implementation effort by 25–35%, by reusing existing management system documentation and processes.

When do you need ISO 42001 even if you already have ISO 27001?

ISO 27001 does not cover AI-specific risks. You need ISO 42001 if:

  • Your organization develops, deploys, or uses AI systems that make decisions affecting people
  • You operate in a sector with applicable AI regulation: EU AI Act, national AI strategies, sector-specific rules
  • Enterprise clients or government tenders require evidence of AI governance
  • You use AI in credit decisions, hiring, access to services, or risk scoring
  • You want to demonstrate EU AI Act alignment if you export to Europe or use European AI providers

When is ISO 27001 enough?

  • Your organization does not use AI systems in any of its critical processes
  • You use AI only for internal productivity (drafting, summarizing) without the output affecting third parties
  • Your sector has no specific AI regulation applicable to your size and activity
The reality is that increasingly organizations — even without in-house AI development — use third-party models (credit scoring, customer service chatbots, hiring tools). Using third-party AI also creates governance obligations under ISO 42001 and the EU AI Act.

The 3 most common scenarios

1
ISO 27001 only

Organization that does not use AI in its processes, or whose use is purely internal with no third-party impact. Can remain here until regulation or clients require otherwise.

Sufficient for now
2
ISO 42001 (without ISO 27001)

Startup or company using AI as a business differentiator that needs to demonstrate responsible governance, but does not yet require an information security certification.

Common AI path
3
ISO 42001 + ISO 27001

Technology company, fintech, healthcare, or public sector handling sensitive data and using AI in critical decisions. The integrated system is more efficient and covers both dimensions.

Best coverage

Frequently asked questions

Yes. ISO 42001 is an independent standard and does not require ISO 27001 as a prerequisite. However, if your organization already has ISO 27001 in place, you can reuse existing documentation — risk management policy, management review process, internal audit program — and reduce implementation effort by up to 30%.

It depends on your situation. If your business relies on data security trust (SaaS, fintech, healthcare), start with ISO 27001. If your product or service uses AI systems and you need to demonstrate responsible governance — especially for EU AI Act compliance — start with ISO 42001. If you need both, you can implement them in parallel using a single integrated management system.

Not specifically. ISO 27001 protects the confidentiality, integrity, and availability of information assets. It does not address algorithmic bias, AI decision explainability, algorithmic impact assessments, or the AI system lifecycle. That is precisely what ISO 42001 was designed for.

No. They are complementary standards with distinct scopes. ISO 27001 manages information security across all assets. ISO 42001 manages governance specific to artificial intelligence systems. A mature AI organization should have both.

Not proportionally. Both standards share the same High Level Structure (clauses 4–10). Documents such as the risk management policy, management review procedure, and internal audit plan can be shared. An integrated implementation is more efficient than two separate projects.

Do you need ISO 42001, ISO 27001, or both?

Our free 20-question diagnostic identifies which standards apply to your organization and the most efficient path forward.

Free diagnostic

You might also like: ISO 42001 implementation roadmap · ISO 42001 vs NIST AI RMF · ISO 42001 vs EU AI Act