ISO 27001 vs ISO 42001: security management and AI management
ISO 27001 governs information security; ISO 42001 governs how you develop and use AI. Why companies that ship AI features end up needing both, and how much of the second comes from the first.
The short answer
ISO 27001 is the standard for an information security management system: protecting information through risk-based controls. ISO 42001 is the standard for an AI management system: governing the AI you build and buy, its intended use, its impacts, its data and the oversight around it. They share the same high-level structure and most management clauses, so a company holding ISO 27001 reuses most of that work for ISO 42001; what is new is the AI-specific part, the inventory of AI systems, the impact assessments and the controls on AI data and oversight.
ISO 27001 and ISO 42001, row by row
| ISO 27001 | ISO 42001 | |
|---|---|---|
| What it governs | Information security | Responsible development and use of AI systems |
| Published | 2022 edition (first 2005) | December 2023 |
| Controls | 93 Annex A controls in four themes | 38 Annex A controls in nine themes, plus the shared management clauses |
| Distinctive work | Risk assessment, Statement of Applicability, security controls | AI system inventory, AI impact assessments, data for AI, transparency and oversight |
| Who asks for it | Buyers worldwide as the security baseline | Buyers and regulators of any vendor that ships AI features, increasingly alongside 27001 |
| Certification | Two-stage audit by an accredited body, three-year cycle | The same model, by bodies accredited for 42001 |
| With Viglyn | Included in every plan, Stage 1 and 2 in the platform | Included in every plan, the AI governance module runs the AI-specific part |
The questions that decide it
Do we need ISO 42001 if we have ISO 27001?
If you ship AI features or run AI in your operations and your buyers ask how it is governed, yes: 27001 does not cover intended use, impact, bias, transparency or human oversight. If you only use off-the-shelf AI tools internally, 27001 plus a vendor assessment is usually enough today.
How much of ISO 42001 is already done by ISO 27001?
The management system clauses, context, leadership, planning, support, operation, performance evaluation and improvement, carry over with AI-specific additions. The security controls that protect AI data and systems carry over too. The AI inventory, impact assessments and AI-specific controls are new, and they are where the time goes.
Can we certify both in one audit?
Often, yes: certification bodies accredited for both can run an integrated audit of the two management systems, and the shared evidence makes that efficient. Viglyn keeps one evidence base for both and runs Stage 1 and Stage 2 inside the platform.
More questions
Is ISO 42001 only for companies that train models?
What about NIST AI RMF?
How much does ISO 42001 cost with Viglyn?
Standards buyers weigh against each other
Find out which one you are closer to
A practitioner maps your gaps for the framework you are going for, in the order to close them, and tells you the honest timeline. Free, no account, no card.
