help (at) seqmtraining.co.uk [ help (at) seqmtraining.co.uk ]

ISO 42001 vs ISO 27001: What’s the Difference?

The short answer to ISO 27001 vs ISO 42001 is that they govern different things. ISO/IEC 27001 is the international standard for information security management, concerned with protecting the confidentiality, integrity and availability of information. ISO/IEC 42001 is the first international standard for AI management systems, concerned with whether artificial intelligence is developed and used responsibly. Neither replaces the other, and a growing number of organisations need both.

Adoption of AI has moved quickly from experiment to everyday operation, and with it has come pressure from customers, regulators and boards to show that AI is being governed rather than simply deployed. This guide compares the two standards, sets out where they overlap, and helps you work out which one your organisation actually needs. For background reading, see our introductions to ISO 27001 and ISO 42001, along with our summaries of the ISO 27001 requirements and the ISO 42001 requirements. If you are moving towards auditing either system, our ISO 27001 training courses and ISO 42001 Lead Auditor Course cover both in depth.

What Is ISO 27001?

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS), published jointly by ISO and the International Electrotechnical Commission. The current edition is ISO/IEC 27001:2022.

Purpose. To give organisations a systematic, risk-based framework for protecting information, whether that information is digital, physical or held by a third party.

Key objectives. The standard is built around the confidentiality, integrity and availability of information. Rather than prescribing a fixed set of security measures, it requires organisations to assess their own risks, decide how to treat them, and select controls accordingly. Annex A provides 93 reference controls arranged under four themes: organisational, people, physical and technological.

Typical users. Any organisation holding information that matters to someone else. In practice, adoption is heaviest in technology, financial services, healthcare, professional services and government supply chains.

Certification. ISO 27001 is certifiable by accredited certification bodies, and the certificate is widely recognised in procurement and due diligence. Certification typically runs on a three-year cycle with annual surveillance audits.

What Is ISO 42001?

ISO/IEC 42001:2023 is the international standard for Artificial Intelligence Management Systems (AIMS). Published in 2023 and prepared by ISO/IEC JTC 1/SC 42, it was the first management system standard written specifically for AI.

Purpose. To help organisations develop, provide or use AI systems responsibly, and to demonstrate that responsible approach to customers, regulators and other interested parties.

Key objectives. The standard addresses AI governance in the round: accountability for AI decisions, transparency about how systems work, data quality and provenance, human oversight, and the assessment of impacts on individuals and on society. Its Annex A contains 38 reference controls across nine areas, covering AI policy, internal organisation, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems, and third-party relationships.

Typical users. Organisations that build AI products, embed AI into their services, or deploy AI internally. The scope of the standard is explicit that it applies to organisations providing or using AI systems, which brings a great many businesses into range that do not think of themselves as AI companies at all.

Certification. ISO 42001 is certifiable, and the certification market has developed quickly since publication. As with ISO 27001, certification is voluntary and awarded by accredited certification bodies.

ISO 42001 vs ISO 27001 at a Glance

The table below summarises how ISO 27001 vs ISO 42001 compare across the features organisations most often weigh up.

Feature ISO 42001 ISO 27001
Focus Responsible governance of artificial intelligence Protection of information
Management system AI Management System (AIMS) Information Security Management System (ISMS)
Main risk area Harm from AI: bias, opacity, unintended consequences and societal impact Loss of confidentiality, integrity or availability of information
Reference controls 38 controls across nine areas (Annex A) 93 controls across four themes (Annex A)
Certification available Yes Yes
Suited for Organisations developing, supplying or using AI systems Organisations handling sensitive or business-critical information
Key standard ISO/IEC 42001:2023 ISO/IEC 27001:2022

Both standards share the harmonised management system structure used across ISO standards, so clauses 4 to 10 cover context, leadership, planning, support, operation, performance evaluation and improvement in the same sequence. That shared skeleton is what makes running both together considerably easier than running two unrelated systems.

Key Differences Between ISO 27001 and ISO 42001

Purpose

The clearest difference between ISO 27001 and ISO 42001 is the question each one answers. ISO 27001 asks whether information is adequately protected. ISO 42001 asks whether AI is being used responsibly. A system can be entirely secure and still produce discriminatory outcomes; it can also be ethically well governed and still leak data. The two concerns are related but genuinely distinct.

Risk Management Focus

ISO 27001 assesses risk to information, expressed in terms of confidentiality, integrity and availability. ISO 42001 assesses risk arising from AI systems, which includes risk to the organisation but also, and unusually for a management system standard, risk to individuals and to society. Its Annex A devotes a whole control area to impact assessment, requiring organisations to assess and document the potential consequences of their AI systems for individuals, groups and society across the system life cycle.

Scope

ISO 27001 scopes around information assets and the processes, people and technology that handle them. ISO 42001 scopes around the AI system life cycle: how systems are specified, designed, trained, verified, deployed, monitored and eventually retired. Data appears in both, but for different reasons. ISO 27001 is concerned with keeping data safe; ISO 42001 is concerned with whether data is fit for the purpose the model is being trained on, and where it came from.

Stakeholder Considerations

ISO 42001 introduces a noticeably broader view of who is affected. Its controls require organisations to provide information to users about how AI systems work, to give interested parties a route to report adverse impacts, and to communicate incidents. This reflects the reality that an AI system’s consequences often land on people who never chose to interact with it.

Regulatory Alignment

Regulation is where the ISO 27001 vs ISO 42001 comparison becomes most practical, and it is moving fast.

EU AI Act. The Act entered into force on 1 August 2024, with obligations phased in over several years. The Digital Omnibus on AI (Regulation (EU) 2026/1744), which entered into force on 27 July 2026, then shifted the timetable. High-risk obligations for standalone Annex III systems now apply from 2 December 2027, and for AI embedded in regulated products under Annex I from 2 August 2028. The Article 50 transparency obligations, covering matters such as disclosing that users are interacting with AI, were largely not deferred and applied from 2 August 2026, though the Article 50(2) watermarking duty for systems already on the market was given a short grace period to 2 December 2026. Given how recently this changed, organisations should confirm the current position rather than rely on guidance published earlier.

An important caveat: ISO 42001 certification is not the same as EU AI Act compliance, and no standard currently confers it. What an AI management system does provide is much of the governance scaffolding the Act expects, including risk management, documentation, human oversight and post-market monitoring.

UK approach. The UK has not enacted an equivalent statute. It relies instead on non-statutory principles applied by existing sector regulators such as the ICO, FCA and Ofcom, supported by the AI Security Institute, which was renamed from the AI Safety Institute in February 2025. A broader AI bill has been signalled but is not yet before Parliament. For UK organisations, a certified management system is currently one of the more credible ways to evidence responsible AI governance in the absence of a single statutory test.

GDPR overlap. Both standards intersect with data protection law without satisfying it. UK and EU GDPR obligations around lawful basis, automated decision-making and data protection impact assessments apply regardless. The AI system impact assessment required by ISO 42001 complements a DPIA but does not replace it, since the two ask different questions.

How Controls Are Applied

One structural difference is frequently missed and matters at audit. Under ISO 27001, every Annex A control must be accounted for in the Statement of Applicability, either included with justification or excluded with justification. ISO 42001 is more permissive: its Annex A is explicitly a reference set, not all of its controls are required to be used, and organisations may design their own. Both standards do require a Statement of Applicability, but ISO 27001 additionally requires you to record whether each necessary control has been implemented.

How ISO 27001 and ISO 42001 Work Together

Framed simply:

  • ISO 27001 answers: is information protected?
  • ISO 42001 answers: is AI being used responsibly?

Run together, they cover four things that stakeholders increasingly ask about at the same time: security, governance, trust and regulatory readiness.

Consider an organisation that has adopted a generative AI assistant across its customer service function. ISO 27001 addresses the questions about the data: where customer records are stored, who can access them, whether information is being sent to a third-party model provider, and what happens if that provider suffers a breach. ISO 42001 addresses a different set of questions entirely: whether the assistant produces consistent answers across different customer groups, whether customers are told they are dealing with AI, who is accountable when it gets something wrong, and how the organisation would detect degrading performance.

Neither set of questions answers the other. This is the practical reason the ISO 27001 vs ISO 42001 framing can mislead: for many organisations it is not a choice at all.

Because both standards share the harmonised structure, the shared clauses can be operated once rather than twice. Context, leadership, competence, documented information, internal audit and management review can all be run as integrated processes, and many certification bodies will conduct combined audits.

Do You Need ISO 27001 or ISO 42001?

The ISO 27001 vs ISO 42001 decision usually resolves quickly once you look at what your organisation actually does with information and with AI. The lists below are a starting point rather than a test.

Choose ISO 27001 If

  • Information security is your primary risk and governance concern
  • Customers, tender processes or regulators require security assurance
  • You handle sensitive personal, financial or commercially confidential data
  • You use little or no AI, or use it only in ways that carry limited consequence

Choose ISO 42001 If

  • You develop AI systems or models
  • You deploy AI internally in ways that affect staff, customers or decisions
  • You provide AI-enabled products or services to others
  • You need to demonstrate responsible AI governance to buyers or regulators

Consider Both If

  • You use AI extensively and process sensitive information through it
  • Your AI systems make or materially influence decisions about people
  • You operate in a regulated sector, or sell into one
  • Your customers are already asking about both security and AI governance

For most organisations that already hold ISO 27001 and are now adopting AI, the sensible sequence is to extend the existing management system rather than build a second one from scratch. The governance machinery is already in place; what is missing is the AI-specific risk thinking.

Benefits of Implementing Both Standards

Where an organisation concludes that ISO 27001 vs ISO 42001 is not an either/or, the combination delivers more than the sum of the two certificates.

Benefit What it looks like in practice
Improved governance One set of accountabilities covering information and AI, rather than security owned by IT and AI owned by nobody in particular.
Enhanced stakeholder trust Two recognised certificates answer the security and AI governance questions that increasingly appear together in the same procurement questionnaire.
Better risk management AI risk assessment and information security risk assessment inform one another. A model trained on poorly governed data is both a security and a governance problem.
Regulatory preparedness Much of what the EU AI Act expects of high-risk systems, including risk management, documentation and monitoring, maps onto an AI management system already in operation.
Competitive advantage Early certification is a differentiator while it remains uncommon. As with ISO 27001 a decade ago, that advantage narrows as adoption spreads.

The efficiency argument is worth stating plainly. Because the two standards share a common structure, the incremental cost of adding the second is considerably lower than the cost of the first.

Frequently Asked Questions

No. They cover different subject matter. ISO 42001 governs AI management; ISO 27001 governs information security. Holding one does not satisfy the other.

Yes, and it is increasingly common. Because both use the harmonised management system structure, they can be integrated and audited together, which reduces duplication and audit time.

No. Certification is voluntary. It is not legally required in any jurisdiction, and it does not by itself demonstrate compliance with the EU AI Act. It is, however, appearing more often as a contractual or procurement requirement.

ISO 27001, by some margin. Its first edition was published in 2005, with the current edition dating from 2022. ISO 42001 was published in 2023.

It touches on security, particularly around data and third-party relationships, but it is not a security standard and its controls are nothing like as detailed as those in ISO 27001 Annex A. Organisations with meaningful security risk need ISO 27001 as well.

Yes. The standard’s scope explicitly covers organisations that use AI systems as well as those that provide them, and Annex A includes a control area dedicated to the responsible use of AI systems. If your organisation has adopted third-party AI tools, ISO 42001 applies to you.