ISO 42001 vs ISO 27001: Do You Need Both?

Shubham S.
October 2, 2026
•
20
mins

Your enterprise buyer's security questionnaire has two lines that weren't there last year. One asks for your ISO 27001 certificate. The next asks whether you're ISO 42001 certified, or working toward it.

The instinct is to ask which of the two you need. In the ISO 42001 vs ISO 27001 question, the sharper version is which one comes first, and how much of the second the first has already done for you.

ISO 27001 certifies how you protect information. ISO 42001 certifies how you govern AI systems. They share the same management-system skeleton (clauses 4 through 10) but carry different Annex A controls. Neither replaces the other, neither is a prerequisite for the other, and most companies that build AI on sensitive customer data end up holding both.

Quick answer Hold ISO 27001 if you handle customer data and sell to enterprises. Add ISO 42001 when AI is part of what you ship and buyers start asking how you govern it. You can build them as one management system, and certify them in one combined audit if your certification body is accredited for both.

One boundary before we go further. This guide compares two ISO standards. If you're weighing ISO 27001 against SOC 2, ComplyJet's ISO 27001 vs SOC 2 guide is the right read. If what you need is the AI governance policy document itself, start with ComplyJet's AI governance policy guide.

By the end, you'll know exactly where the two standards overlap, where they don't, and which path fits your company. Here's what I'll cover:

  • A side-by-side comparison of ISO 27001 and ISO 42001, with a verdict on each dimension
  • The Annex SL clauses both standards share, and what you reuse
  • How the Annex A control sets and risk assessments differ
  • Whether ISO 27001 is a prerequisite for ISO 42001
  • A decision guide for whether you need both, and in what order
  • How to run both with one audit programme, plus the mistakes that trip teams up

Both standards are frameworks ComplyJet supports. If you'd like to see how the two sit on one platform before reading further, this is the place to start.

ISO 27001 + ISO 42001
Building toward ISO 42001 on top of ISO 27001?
See how ComplyJet supports the AI management system standard, with risk and impact assessment templates, automated evidence collection, and a vetted auditor network.
See ISO 42001 support

ISO 42001 vs ISO 27001 at a Glance: Side-by-Side Comparison

Asking which standard is better misses the point. They answer different buyer questions, and the clearest way to see ISO 27001 vs ISO 42001 is one dimension at a time, with a verdict on each. That's also the fastest route to the difference between ISO 27001 and ISO 42001 in practice.

Dimension ISO 27001 ISO 42001 Verdict
Full name and year ISO/IEC 27001:2022 ISO/IEC 42001:2023 (published December 2023) 27001 is the mature baseline; 42001 is new and still being asked about for the first time
What it certifies An information security management system (ISMS) An AI management system (AIMS) Different systems, different questions
What it protects Confidentiality, integrity, and availability of information People, groups, and society affected by AI systems, plus the organization 42001 looks outward at impact; 27001 looks inward at assets
Annex A 93 controls in 4 themes 38 controls in 9 objectives (A.2 to A.10) More controls does not mean more work; both are selected by risk
Core clauses 4 to 10 4 to 10 Same skeleton, reusable
Impact assessment Not required Required (clauses 6.1.4 and 8.4) The biggest single gap 27001 leaves
Certification cycle Three-year cycle with annual surveillance audits Three-year cycle with annual surveillance audits No difference in rhythm
Who usually asks Enterprise buyers, procurement, security reviewers Buyers evaluating AI vendors, AI-focused procurement Most SaaS buyers ask for 27001 first
Side-by-side comparison card showing ISO 27001 as the information security management system standard with 93 Annex A controls, and ISO 42001 as the AI management system standard with 38 Annex A controls, both built on the same clauses 4 through 10.

The two sections below give each standard the same treatment, in the same order, so you can compare them without hunting.

ISO 27001: The Information Security Management System (ISMS)

What it certifies: an information security management system, the set of policies, risk processes, and controls that protect your information assets. The current version is ISO/IEC 27001:2022, and its Annex A holds 93 controls in four themes: organizational (37), people (8), physical (14), and technological (34). Organizations certified to the 2013 version had until October 31, 2025 to transition.

What the buyer is really asking: "How do you protect our data?" It's the question behind almost every enterprise security review, which is why the certificate shows up in procurement checklists.

Verdict: ISO 27001 is the general-purpose trust signal. If you sell to enterprises or outside the US, it's usually the first one you're asked for.

ISO 42001: The AI Management System (AIMS)

What it certifies: an AI management system, the ongoing system of policies, risk and impact assessments, and controls that governs how you build, deploy, or use AI. It was published as ISO/IEC 42001:2023, and its Annex A holds 38 controls across nine objectives, A.2 through A.10. ComplyJet's guide to what ISO 42001 is covers the full definition.

What the buyer is really asking: "How do you govern the AI in this product?" That covers bias, transparency, human oversight, and what happens when a model misbehaves.

Verdict: ISO 42001 is the AI-specific trust signal. It matters when AI is part of what you sell, or when a buyer's AI vendor review is a formal gate.

What ISO 42001 and ISO 27001 Share: Annex SL Clauses 4 Through 10

Both standards are built on the ISO harmonized structure for management system standards, first published as Annex SL in 2012 and now sitting in the ISO/IEC Directives as Annex L. It's the same skeleton ISO 9001, ISO 22301, and ISO 27701 follow. That's why an ISO 27001 audit and an ISO 42001 audit feel structurally familiar to anyone who has sat through one.

The practical consequence: seven auditable clauses in the same order, doing the same jobs. That is the overlap between ISO 42001 and ISO 27001 that matters most.

Clause What it does Reused as-is AI-specific addition in ISO 42001
4. Context Scope, interested parties, boundaries Method and documentation AI systems and AI-related stakeholders enter the scope
5. Leadership Management commitment, policy, roles Governance structure A separate AI policy alongside the security policy
6. Planning Risk, opportunities, objectives Risk register method and treatment cycle AI risk assessment plus a distinct AI system impact assessment (6.1.4)
7. Support Resources, competence, awareness, documents Training, document control AI-specific competence and awareness
8. Operation Running the controls Change and supplier processes AI system impact assessment carried out (8.4), lifecycle controls
9. Performance evaluation Monitoring, internal audit, management review The whole cadence AI performance metrics added to the review
10. Improvement Nonconformities, corrective action The whole process None beyond scope
Diagram of one shared management system layer, clauses 4 through 10, sitting on top of two separate Annex A control sets: ISO 27001 with 93 information security controls and ISO 42001 with 38 AI controls.

How much ISO 42001 ISO 27001 overlap you can actually count on depends on who's counting. Drata disclosed that its existing SOC 2, ISO 27001, and privacy work already covered roughly 35 to 40 percent of ISO 42001's requirements when it pursued its own certification. Elevate Consult puts control overlap at about 40 percent. Konfirmity claims 60 to 70 percent foundational overlap but doesn't cite a basis for it.

The spread is wide because each source counts something different: requirements, controls, or management-system effort. My read is that the shared clauses are where the real savings live, and the numbers matter less than knowing which work transfers.

The clauses are the part you only build once. Scope, risk method, internal audit, and management review are the same muscle for security and for AI. What's new is the layer on top: the impact assessment and the AI controls. — Upendra Varma, CTO at ComplyJet

ISO 42001 vs ISO 27001 Annex A: 93 Controls Against 38

Read ISO 42001 vs ISO 27001 Annex A side by side and the first thing you notice is that the two sets aren't variants of each other. They're different catalogues, built to answer different risk questions, and a rough one-to-one mapping only exists for a handful of topics.

Rob Black, comparing the two after reading the standard in a January 2024 LinkedIn post, wrote that "Annex A is totally different from ISO 27001." Walter Haydock replied in the same thread that "it will look very similar" to anyone familiar with ISO 27001, which holds for the clauses but, as the table shows, not for the controls.

Topic ISO 27001 Annex A ISO 42001 Annex A Where they touch
Policy A.5.1 Policies for information security A.2 Policies related to AI Same idea, separate documents
Roles A.5.2 Roles and responsibilities A.3 Internal organization Shared role model, AI accountability added
Suppliers A.5.19 to A.5.23 Supplier relationships A.10 Third-party and customer relationships Reuse the vendor process; add model-provider risk
Data A.5.12 Classification, A.8.10 Information deletion A.7 Data for AI systems 27001 protects data; 42001 also asks about quality and provenance
Development A.8.25 to A.8.31 Secure development A.6 AI system life cycle (9 controls) Overlap on process; 42001 adds design, testing, monitoring of AI behavior
Impact and transparency No direct equivalent A.5 Impact assessment, A.8 Information for interested parties Entirely new ground
Physical and device security A.7 Physical controls (14) No direct equivalent 27001 only

Both standards use the same selection logic. You assess risk, decide which controls apply, and record the decision in a Statement of Applicability (the document listing which controls you've implemented, which you haven't, and why). Neither asks you to implement every control by default, so the smaller number on the ISO 42001 side doesn't make it the easier standard. ComplyJet's ISO 42001 checklist walks through all 38, and the ISO 27002 checklist does the same for the ISO 27001 controls.

ISO 42001 vs ISO 27001 Risk Assessment: Security Risk vs Impact on People

This is where the two standards genuinely part ways. ISO 27001's risk lens is information: what could compromise its confidentiality, integrity, or availability. ISO 42001 keeps a risk assessment (clause 6.1.2) that looks at risk to the organization, then adds a second exercise that ISO 27001 has no counterpart for.

Clause 6.1.4 requires an AI system impact assessment methodology, and clause 8.4 requires you to carry it out. It looks at consequences for individuals, groups, and society across the AI system's lifecycle, including foreseeable misuse, not only what could go wrong for your company.

Watch out A clean ISO 27001 risk register does not contain an AI system impact assessment. If you're extending an existing ISMS to cover AI, this is the artifact auditors will look for first, and it can't be back-filled from your security risk assessment.

What ISO 27001 Alone Does Not Cover for AI

Does ISO 27001 cover AI? Only in the sense that AI systems are information systems. If they sit inside your ISMS scope, access control, logging, supplier management, and incident response already apply to them. What the standard never asks about is how the AI behaves:

  • Bias and fairness in model outputs and the decisions built on them
  • Transparency toward users and other interested parties about when and how AI is used
  • Human oversight of consequential automated decisions
  • AI system lifecycle controls for design, testing, deployment, and monitoring
  • Data quality and provenance for training and operating data

Those map to ISO 42001's A.5 through A.9 objectives. The controls that do carry across are the operational ones: access, logging, incident response, and vendor risk.

Not everyone accepts that a gap exists. In the comments on that same LinkedIn thread, one user, who said they hadn't read the standard yet, argued that "27001 is supposed to be technology agnostic." That is a fair case for treating AI as another system in scope. It doesn't answer the impact assessment, though, which asks about people affected by the system, not the system itself.

Verdict: ISO 27001 secures the system that runs your AI. ISO 42001 governs what the AI does. One doesn't answer the other's questions.

Is ISO 27001 a Prerequisite for ISO 42001, or Can You Start With Either?

On paper, ISO 27001 is not a prerequisite for ISO 42001. Konfirmity's comparison states there's no formal prerequisite, and TÜV UK, a certification body, doesn't establish one standard as a precondition for the other either. Its guidance is that "the answer depends on how AI is used within the organisation."

Practitioners said the same before the standard was even published. Danny Manimbo of Schellman noted in a November 2023 LinkedIn post, based on a draft, that neither 27001 nor the other ISO frameworks are "considered prerequisites to become ISO 42001 certified."

So the ISO 27001 prerequisite for ISO 42001 question has a formal answer (no) and a practical one (usually yes, in effect). Building the management-system core once and adding the AI layer second is cheaper than the reverse.

Here's what that looks like in money. ComplyJet's ISO 42001 certification cost guide covers a company that already held ISO 27001 and ISO 9001 and added ISO 42001 for roughly $35,000, against $70,000 to $90,000 for a similar company starting from zero (Elevate Consult, 2026). That gap is the value of the shared clauses.

Konfirmity estimates the ISO 42001 effort shrinks by a third to a half for an ISO 27001 holder. Treat that as a vendor estimate, not a benchmark, but the direction matches the cost example.

There are two cases where starting with ISO 42001 is legitimate. The first is an AI-native product where the buyer's first formal question is about AI governance. The second is a company that already holds another Annex SL certification, such as ISO 9001, and is building its management system from that base.

One ComplyJet customer describes the ISO 27001 foundation in plain terms.

"ComplyJet made SOC 2 and ISO 27001 readiness manageable with automation."
David Orr, COO, Romina Day Read more customer stories

That quote is about ISO 27001. The same management-system foundation is what an ISO 42001 program extends, which is the whole argument for building the base first.

Do You Need Both ISO 42001 and ISO 27001? A Decision Guide

Do you need both ISO 42001 and ISO 27001? The better question is when the second one earns its cost. For most companies the answer follows from two facts: whether you handle sensitive customer data, and whether AI is part of what you ship. Peju Adedeji, an IT audit and GRC professional whose LinkedIn headline also lists AI governance, framed it in an October 2025 post as "Both matter, but they serve different purposes."

Your situation Recommended path Why
No certification yet, AI is a minor feature, buyers ask for security proof ISO 27001 first, ISO 42001 later 27001 unlocks the most deals; the AI layer costs less once the base exists
Hold ISO 27001, just shipped an AI feature, buyers ask AI governance questions Add ISO 42001 by extending your ISMS You reuse clauses 4 to 10 and only build the AI layer
AI-native product, enterprise buyers ask about both Build both as one program One scope, one audit programme, two Annex A sets
Hold SOC 2 but not ISO 27001, AI questions are starting Map SOC 2 to ISO 27001 first, then add ISO 42001 See the mapping guide below
Only use third-party AI tools internally, no AI in your product ISO 27001 plus an AI use policy; ISO 42001 can wait Little AI you build or deploy means little for an AIMS to govern
Decision path showing three questions: do you handle sensitive customer data, is AI part of what you ship, and do buyers ask for AI governance evidence, leading to ISO 27001 only, ISO 27001 then ISO 42001, or both as one program.

If you hold SOC 2 but not ISO 27001, ComplyJet's SOC 2 to ISO 27001 mapping guide shows what carries over, and does SOC 2 cover AI explains what a SOC 2 report says about AI.

Choose ISO 27001 only if you handle customer data but AI isn't in your product. Choose ISO 27001 first, then ISO 42001, if you hold neither and are building AI features. Choose both together if AI is your product and buyers are asking for both. Otherwise, open your last three security questionnaires and count what they ask for.

Try this yourself Pull your last three enterprise security questionnaires. Count the questions that name ISO 27001 or information security, then the ones that ask about AI governance, model risk, or bias. The ratio tells you which certificate you're being asked for and which one you're only being asked about.

Running ISO 42001 vs ISO 27001 Together: Integrated Audit and One Management System

Once you've decided on both, the goal is to run them as one system, not two. The shared clauses make this straightforward, and it's the point where the savings actually show up.

A combined, or integrated audit, is one engagement in which a single accredited certification body assesses both standards. Konfirmity and Elevate Consult both describe it as possible when the same body is accredited for both.

That accreditation is the catch. ISO/IEC 42006:2025 sets requirements for bodies that audit and certify AI management systems, on top of the general ISO/IEC 17021-1 requirements. Your ISO 27001 auditor may not yet hold that scope, so confirm it before assuming one engagement will cover both.

To run both as one system:

  1. Write one scope statement that names your information systems and your AI systems together, with the AI systems clearly identified.
  2. Keep one risk method. Extend your existing risk register with AI risk and add the impact assessment as its own artifact.
  3. Run one internal audit programme with two sets of Annex A controls in the plan.
  4. Hold one management review with security and AI as separate agenda items.
  5. Maintain one Statement of Applicability per standard. The controls differ, so the documents do too.
  6. Ask your certification body about combined audit scheduling before you book Stage 1.
Pro tip Schedule your ISO 42001 Stage 1 audit within a few weeks of an ISO 27001 surveillance audit. The evidence, the people, and the management review minutes are already assembled, and the gap between Stage 1 and Stage 2 shouldn't run past six months.

Mistakes That Trip Teams Up Comparing ISO 42001 vs ISO 27001

  • Treating an ISO 27001 certificate as the answer to an AI questionnaire. The certificate says nothing about bias, transparency, or human oversight, and buyers who ask about AI know that.
  • Reading ISO 27001 vs ISO 42001 control counts (93 versus 38) as "27001 is bigger." Both are risk-selected catalogues. A small, well-scoped ISO 42001 program can carry more real work than a broad ISO 27001 one.
  • Scoping ISO 42001 across the whole company. Scope it to the AI systems you build, deploy, or supply, then grow it.
  • Running two internal audit programmes. The shared clauses exist so that one audit cycle covers both.
  • Skipping the impact assessment because the security risk assessment "already covers it." It doesn't. Clause 6.1.4 is a separate exercise.
  • Assuming one certificate's scope covers the other's. An ISO 27001 scope that excludes your AI systems doesn't turn on ISO 42001 coverage, and the reverse is equally true.

Where ComplyJet Fits When You Need Both

ComplyJet supports both frameworks directly. For ISO 27001, that means policy templates and control mapping for all 93 Annex A controls, an automatically generated Statement of Applicability, and access to vetted auditors. For ISO 42001, it means AI risk and impact assessment templates, AI supply chain documentation, and a Stage 1 and Stage 2 audit workspace.

Both run on the same 350+ integrations, and pricing is flat and per-company, not per-seat. We guide you through the process end to end, so adding the AI layer to an existing ISO 27001 program isn't a fresh project. See ComplyJet's ISO 27001 support and ISO 42001 support for the specifics of each.

ComplyJet
Work out your ISO 27001 and ISO 42001 path with our team
Bring your questionnaires and your current certifications. We'll show you what carries over and what you'd build new, at flat per-company pricing.
Book a demo

FAQs

ISO 42001 vs ISO 27001: What Is the Difference?

The difference between ISO 27001 and ISO 42001 comes down to what each certifies. ISO 27001 certifies an information security management system that protects your information assets. ISO 42001 certifies an AI management system that governs how you build or use AI. They share clauses 4 through 10 but have separate Annex A control sets, 93 controls for ISO 27001 and 38 for ISO 42001. See the side-by-side table above.

Do You Need Both ISO 42001 and ISO 27001?

Not always. If AI isn't part of your product, ISO 27001 alone usually covers what buyers ask for. If you build or deploy AI on sensitive data and buyers ask about AI governance, most companies end up holding both. The decision guide above lays out five common situations.

Is ISO 27001 a Prerequisite for ISO 42001?

No. Neither standard requires the other, and the idea of an ISO 27001 prerequisite for ISO 42001 comes from cost, not from the standard itself. In practice, holding ISO 27001 first is usually cheaper because the shared management-system clauses are already in place, so ISO 42001 costs you only the AI-specific layer.

Does ISO 27001 Cover AI?

Partly. AI systems inside your ISMS scope get the same access control, logging, supplier, and incident controls as any other system. ISO 27001 doesn't ask about bias, transparency, human oversight, or AI impact assessment. Those live in ISO 42001.

Can You Get ISO 42001 and ISO 27001 Certified at the Same Time?

Yes, when a certification body is accredited for both and offers a combined audit. ISO/IEC 42006:2025 sets the accreditation requirements for bodies certifying AI management systems, so ask your current auditor whether they hold that scope before you plan a single engagement.

ISO 42001 vs ISO 27001: Which Should You Get First?

For most SaaS companies, ISO 27001 first. It unlocks more buyer conversations, and the shared clauses lower the cost of ISO 42001 later. Start with ISO 42001 only if you're AI-native and buyers are asking about AI governance before anything else.

Do ISO 42001 and ISO 27001 Use the Same Structure?

Yes. Both follow the ISO harmonized structure (originally Annex SL), so clauses 4 through 10 appear in the same order with the same jobs. What differs is the AI-specific content added to some clauses and the separate Annex A catalogues.

How Many Controls Are in ISO 42001 vs ISO 27001?

ISO/IEC 27001:2022 has 93 Annex A controls in four themes. ISO/IEC 42001:2023 has 38 controls across nine objectives, A.2 through A.10. Neither requires implementing every control; you select by risk and document the decision in a Statement of Applicability.

Related Reading

Sources: ISO/IEC 27001:2022 control count and themes per Secureframe and Dionach. ISO 42001 structure and impact assessment clauses per Konfirmity and Presencis. Position on prerequisite per TÜV UK. Control overlap per Elevate Consult. Certification body requirements per ISO/IEC 42006:2025.