Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
ISO 27001 vs ISO 42001

ISO 27001 vs ISO 42001: security management and AI management

ISO 27001 governs information security; ISO 42001 governs how you develop and use AI. Why companies that ship AI features end up needing both, and how much of the second comes from the first.

The short answer

ISO 27001 is the standard for an information security management system: protecting information through risk-based controls. ISO 42001 is the standard for an AI management system: governing the AI you build and buy, its intended use, its impacts, its data and the oversight around it. They share the same high-level structure and most management clauses, so a company holding ISO 27001 reuses most of that work for ISO 42001; what is new is the AI-specific part, the inventory of AI systems, the impact assessments and the controls on AI data and oversight.

Side by side

ISO 27001 and ISO 42001, row by row

ISO 27001ISO 42001
What it governsInformation securityResponsible development and use of AI systems
Published2022 edition (first 2005)December 2023
Controls93 Annex A controls in four themes38 Annex A controls in nine themes, plus the shared management clauses
Distinctive workRisk assessment, Statement of Applicability, security controlsAI system inventory, AI impact assessments, data for AI, transparency and oversight
Who asks for itBuyers worldwide as the security baselineBuyers and regulators of any vendor that ships AI features, increasingly alongside 27001
CertificationTwo-stage audit by an accredited body, three-year cycleThe same model, by bodies accredited for 42001
With ViglynIncluded in every plan, Stage 1 and 2 in the platformIncluded in every plan, the AI governance module runs the AI-specific part
Straight answers

The questions that decide it

Do we need ISO 42001 if we have ISO 27001?

If you ship AI features or run AI in your operations and your buyers ask how it is governed, yes: 27001 does not cover intended use, impact, bias, transparency or human oversight. If you only use off-the-shelf AI tools internally, 27001 plus a vendor assessment is usually enough today.

How much of ISO 42001 is already done by ISO 27001?

The management system clauses, context, leadership, planning, support, operation, performance evaluation and improvement, carry over with AI-specific additions. The security controls that protect AI data and systems carry over too. The AI inventory, impact assessments and AI-specific controls are new, and they are where the time goes.

Can we certify both in one audit?

Often, yes: certification bodies accredited for both can run an integrated audit of the two management systems, and the shared evidence makes that efficient. Viglyn keeps one evidence base for both and runs Stage 1 and Stage 2 inside the platform.

FAQ

More questions

Is ISO 42001 only for companies that train models?
No. It applies to any organization that develops, provides or uses AI systems, which includes embedding a third-party model in your product and buying AI tools for your operations. The inventory covers all three kinds.
What about NIST AI RMF?
The NIST AI Risk Management Framework is a voluntary framework of outcomes rather than a certifiable standard, and NIST publishes a crosswalk to ISO 42001. Companies selling into the US often align with the AI RMF and certify to ISO 42001 for everyone else; Viglyn maps one set of evidence to both.
How much does ISO 42001 cost with Viglyn?
It counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners. The certification body's fee is separate and paid by you directly; we take no commission.

Find out which one you are closer to

A practitioner maps your gaps for the framework you are going for, in the order to close them, and tells you the honest timeline. Free, no account, no card.