ISO 27001 and ISO 42001 are complementary, not competing. ISO/IEC 27001 is the standard for an information security management system; ISO/IEC 42001 is the standard for an AI management system. Both use the same management system structure, so an organisation that already holds ISO 27001 adds ISO 42001 as a layer rather than starting again.
That is the whole answer, and the rest of this post is the working. If you already run an ISMS and your people are using AI, the practical question is not which standard to pick. It is how much of what you have already built counts towards the AI management system (opens in a new tab) you are now being asked about, and where the new work actually sits.
ISO 42001 vs ISO 27001 at a Glance
The two standards line up on structure and part company on subject matter.
| ISO/IEC 27001:2022 | ISO/IEC 42001:2023 | |
|---|---|---|
| What it governs | An information security management system (ISMS) | An artificial intelligence management system (AIMS) |
| Published | October 2022 (opens in a new tab), edition 3, with Amendment 1 in 2024 (opens in a new tab) | December 2023 (opens in a new tab), edition 1 |
| Who it is for | Organisations of any size and sector, per ISO (opens in a new tab) | Organisations of any size that develop, provide or use AI-based products or services, per ISO (opens in a new tab) |
| The asset being protected | Information, wherever it sits | The decisions and outputs of AI systems, and the people affected by them |
| Structure | ISO's harmonized structure (opens in a new tab) for management system standards | The same harmonized structure |
| Method | Plan-Do-Check-Act | Plan-Do-Check-Act (opens in a new tab) |
| Certifiable | Yes, by an independent certification body | Yes, by an independent certification body; ISO/IEC 42006:2025 sets the requirements for those bodies |
| Sold together | ISO offers the two as a single package (opens in a new tab) |
Whilst that table looks symmetrical, the two right-hand cells that matter most are the first and the fourth. Everything else about how the standards relate follows from what each is protecting.
What Each Standard Actually Covers
ISO 27001 protects information; ISO 42001 governs how AI is built, bought and used. Those are different jobs, and treating them as the same job is where most of the confusion starts.
ISO/IEC 27001:2022 (opens in a new tab) sets out the requirements an information security management system has to meet. It is the older and more established of the two, it is the certificate (opens in a new tab) most UK organisations reading this will already hold, and its subject is the confidentiality, integrity and availability of information. An AI model that leaks training data is an ISO 27001 problem. So is an AI tool that a member of staff has connected to a customer database without telling anyone.
ISO/IEC 42001:2023 (opens in a new tab) is younger by a year and narrower by design. In ISO's words it specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, for organisations developing, providing or using AI-based products or services. The subject is not the information. It is the AI system itself: what it is for, who is accountable for it, what it might do to the people on the receiving end, and whether anyone is checking. An AI model that quietly declines loan applications from one postcode is not a breach. Nobody's data went anywhere. It is an ISO 42001 problem, and ISO 27001 has nothing to say about it.
That last sentence is the one to keep. The two standards are adjacent, they share a chassis, and they do not overlap on substance as much as people assume.
Where AI Already Sits Inside Your ISO 27001 Scope
AI is already inside your ISMS scope whether or not anyone has written it down. The moment a member of staff pastes a customer email into a public chatbot, or a developer connects an assistant to a code repository, information is being processed by a system that the ISMS is supposed to know about. That is not a new category of risk. It is a supplier, an asset and a data flow, and ISO 27001 has a place for all three.
The difficulty is that most of it arrived without a change request. The tools were free, the sign-up took a minute, and the information security function found out afterwards, if at all. So the first practical job for an ISO 27001 holder is not ISO 42001 at all. It is establishing which AI tools are actually in use, what they can reach, and whether the existing controls on suppliers, access and data classification have been applied to them. That is an AI risk assessment (opens in a new tab), and it feeds the ISMS directly. How to find the tools nobody approved (opens in a new tab) is its own subject.
Once that is done, the ISMS covers the information side of AI. What it still does not cover is what the AI does. That is where the second standard starts.
Where ISO 42001 and ISO 27001 Overlap
The overlap is structural, and it is deliberate. ISO builds all of its management system standards on what it calls the harmonized structure (opens in a new tab): the standards are laid out in the same way regardless of domain, and where the same text can be used, it is. ISO's stated reason is that anyone familiar with one management system standard will immediately feel at ease with another, and that this is particularly useful for organisations that choose to operate a single, integrated management system meeting two or more standards at once.
In practice that means the clauses you know from ISO 27001 reappear in ISO 42001 under the same headings. Context of the organisation, leadership, planning, support, operation, performance evaluation and improvement.
Both standards also run on the Plan-Do-Check-Act (opens in a new tab) cycle, which ISO describes as the process of establishing, implementing, maintaining and continually improving the AI management system. If you have ever sat through an ISMS management review, an AIMS management review will feel familiar. Same room, same agenda, different risks on the register.
The commercial consequence is the one that matters to a finance director. The scope statement, the risk methodology, the document control, the internal audit programme, the management review, the corrective action process and the competence records you built for ISO 27001 are the same machinery ISO 42001 expects to find. 2-sec's own ISO 42001 readiness (opens in a new tab) work starts with a gap assessment for exactly this reason: to establish what can be reused and where AI-specific responsibilities and practices need to be added. It is usually more than people expect. It is never everything.
Where ISO 42001 and ISO 27001 Differ
The differences are in what is being managed, not how. Four criteria decide it, and they apply to both standards equally.
The Subject of the Risk Assessment
ISO 27001's risk assessment asks what could happen to information. ISO 42001's asks what the AI system could do, and to whom. That is a genuinely different exercise. The information security risk register you already keep will list threats to assets. It will not list the possibility that a recruitment model has learned to prefer one demographic, or that a customer-facing chatbot can be talked into offering a refund policy that does not exist. Those are AI risks, they belong on an AI risk register, and ISO's own summary (opens in a new tab) of what ISO 42001 defines includes risk management for AI systems as its own item, alongside data governance and system lifecycle controls.
The Impact on People Outside the Organisation
ISO 27001 is inward-facing; ISO 42001 is not. An ISMS protects the organisation's information and, by extension, the people whose data it holds. An AIMS has to consider the effect of the AI system on individuals and groups who may never have handed over any data at all. ISO's summary of ISO 42001 lists transparency and information provision as one of its requirement areas, which has no equivalent in an ISMS. Nobody expects your firewall to explain itself. People increasingly expect your AI to.
The Controls
Both standards carry a set of controls in an annex; the controls are different. ISO 27001's Annex A controls are information security controls, and if you hold the certificate you have already argued with an auditor about which ones apply. ISO 42001 carries its own annex of AI-specific controls covering the areas ISO lists: leadership and organisational context, AI policy and objectives, risk management for AI systems, data governance and lifecycle controls, transparency, performance evaluation and continual improvement.
Who Can Certify You
Any certification body can audit an ISMS; auditing an AIMS is newer and more tightly specified. ISO published ISO/IEC 42006:2025 (opens in a new tab) in July 2025, setting the requirements for bodies providing audit and certification of AI management systems, on top of the general requirements in ISO/IEC 17021-1. In the UK, the Department for Science, Innovation and Technology (opens in a new tab) noted in September 2025 that UKAS is piloting accreditation for organisations providing certification against ISO/IEC 42001. For the avoidance of doubt, 2-sec does not issue either certificate. An independent certification body makes that decision after its own assessment.
Do You Need Both ISO 42001 and ISO 27001?
Most organisations using AI in anger need both, and the order is 27001 first. The honest routing looks like this.
| Your position | What fits | Why |
|---|---|---|
| Hold ISO 27001; staff use AI tools; no AI products | ISO 27001, with AI folded into the ISMS scope and an AI policy (opens in a new tab) behind it. ISO 42001 readiness when customers or regulators start asking | The immediate risk is information leaving through AI tools, which is an ISMS matter. Governance of the tools comes next |
| Hold ISO 27001; developing or deploying AI in products or decisions that affect people | Both, run as one integrated system | The ISMS does not cover impact on people or accountability for AI decisions. That is the gap ISO 42001 exists to fill |
| No ISO 27001; being asked about ISO 42001 | ISO 27001 first, or both together from a single gap assessment | An AIMS without an ISMS underneath is a governance layer with no information security under it. Auditors notice |
| Supplying AI to organisations that hold ISO 42001 | Expect the question. ISO 42001 readiness, at minimum | ISO's summary of the standard includes supplier and lifecycle controls; your customers' auditors will look upstream ⚠ |
The cell to argue with is the first one. Plenty of firms in that position are being told they need ISO 42001 now. I think that is premature for most of them, and the money is better spent making sure the AI tools their staff have already adopted are inside the ISMS scope rather than outside it. Finding out which tools those are (opens in a new tab) is usually the more urgent job.
How to Run ISO 42001 and ISO 27001 as One System
One management system, two certificates, is the shape to aim for. ISO says as much in explaining why the harmonized structure exists, and the package (opens in a new tab) in which it sells the two standards together says the quiet part out loud.
What that looks like on a Tuesday: one policy framework with an AI policy sitting alongside the information security policy, not competing with it. One risk methodology, with an AI risk register that shares its scoring with the information security one so that the Board sees a single picture. One internal audit programme that covers both scopes on one calendar. One management review. One corrective action log. Two sets of controls, one set of people.
The mistake to avoid is building the AIMS as a separate project with a separate owner, usually because AI arrived in the business through a different door than security did. Six months later there are two risk registers that disagree, two policies that overlap, and an auditor asking which one is current. It is not a technical problem. It is an org chart problem, and it is cheaper to fix on day one, which is most of what AI governance (opens in a new tab) work turns out to be.
Why ISO 42001 Is Being Asked About Now in the UK
The UK's approach to AI runs on assurance and standards rather than a single AI law, and ISO 42001 is where that approach points. The Department for Science, Innovation and Technology (opens in a new tab) said it plainly in February 2024: without standards we have advice, not assurance. Its market study (opens in a new tab) of November 2024 counted an estimated 524 firms supplying AI assurance goods and services in the UK, generating an estimated £1.01 billion, and set out four government actions, one of which was AI Management Essentials, a free baseline of organisational good practice for organisations that develop or use AI. The roadmap (opens in a new tab) that followed in September 2025 named certification of assurance processes and accreditation as two of the three pathways it is exploring to raise quality, and recorded the UKAS pilot for ISO 42001 certification bodies.
None of that makes ISO 42001 compulsory. What it does is make the certificate the obvious thing for a customer, an insurer or a public sector buyer to ask for when they want evidence that your AI is governed, in the same way ISO 27001 became the thing they ask for about your information. If you hold the first, you already know how that conversation goes. What AI assurance means in the UK, and what the government's programme covers, is a subject on its own (opens in a new tab).
FAQs About ISO 42001 and ISO 27001
Does ISO 27001 Cover AI?
Only the information security side of it. ISO 27001 applies to information wherever it is processed, so an AI tool handling your data is inside scope. What ISO 27001 does not address is the behaviour, fairness or accountability of the AI system itself; that is ISO 42001's territory.
Can You Get ISO 42001 Without ISO 27001?
Yes. Neither standard is a prerequisite for the other, and ISO 42001 is written to stand alone. In practice an AI management system with no information security management system underneath it is an unusual thing to want, and most organisations that pursue ISO 42001 already hold, or are pursuing, ISO 27001.
Is ISO 42001 Certification Mandatory?
No. ISO's own explainer (opens in a new tab) states that certification for ISO/IEC 42001 is voluntary, chosen by organisations that want independent confirmation their AI management system meets the requirements. No UK law requires it.
Why the Order Matters More Than the Certificate
The reason to hold ISO 27001 before ISO 42001 is not a rule. It is that the first standard builds the machinery the second one runs on, and building the machinery twice is how organisations end up with two of everything and confidence in neither.
So the question isn't so much “ISO 42001 or ISO 27001.” It's more “what have we already built, and what does the AI we are using add to it?”. If you hold the first certificate and want a straight answer on how far it takes you towards the second, do get in touch (opens in a new tab). The gap assessment is short, and it tends to be less alarming than the sales emails suggest.

