Anyone weighing ISO 27001 vs ISO 42001 is really asking one practical question: which certificate does my business actually need, and will I end up doing both? The short version is that these are not competing standards. ISO/IEC 27001 governs how you protect information. ISO/IEC 42001 governs how you develop, buy and operate artificial intelligence responsibly. They sit side by side, and a growing number of software companies now hold both.
The confusion is understandable. Both are certifiable ISO management system standards. Both share an identical clause skeleton. Both hand you an Annex A of reference controls and demand a Statement of Applicability explaining what you left out and why. From the outside they look like the same machine with different stickers, which is exactly why most ISO 27001 vs ISO 42001 comparisons end up muddled. Inside, the evidence an auditor asks for is very different.
ISO 27001 vs ISO 42001: the short answer
If enterprise buyers are sending you security questionnaires, you need ISO 27001. If your product makes or materially influences decisions using AI — screening candidates, scoring risk, generating customer-facing output — you need ISO 42001, and you will still need an information security management system underneath it. Choosing between ISO 27001 vs ISO 42001 is usually a question of sequencing rather than an either/or.
ISO 27001 vs ISO 42001 side by side
| ISO/IEC 27001:2022 | ISO/IEC 42001:2023 | |
|---|---|---|
| What it manages | Information security management system (ISMS) | AI management system (AIMS) |
| Published | October 2022; Amendment 1:2024 added climate action | December 2023 — the first AI management system standard |
| Annex A reference controls | 93 controls in 4 themes: 37 organizational, 8 people, 14 physical, 34 technological | 38 controls across 9 control objectives (A.2–A.10) |
| Statement of Applicability | Mandatory, clause 6.1.3 | Mandatory, clause 6.1.3 |
| Distinctive mandatory artefact | Risk treatment plan for information security risk | AI system impact assessment, clause 6.1.4 — effects on individuals and society |
| Certifiable | Yes, mature accredited market | Yes, accreditation still scaling up |
| Typical trigger | Customer security due diligence, tenders, insurance | AI procurement questions, board oversight, regulatory pressure |
| Audit cycle | Stage 1 + Stage 2, three-year cycle, annual surveillance | Stage 1 + Stage 2, three-year cycle, annual surveillance |
What ISO 27001 actually asks of you
ISO 27001:2022 asks you to define a scope, identify information security risks, decide how you will treat them, and then prove — with records, not intentions — that the system runs. Clauses 4 to 10 cover context, leadership, planning, support, operation, performance evaluation and improvement. Annex A gives you 93 reference controls grouped into four themes, and your Statement of Applicability has to account for every one of them, included or excluded.
It is a well-worn path, and in any ISO 27001 vs ISO 42001 comparison this is the mature half of the pair. The ISO Survey for 2024 recorded 96,709 valid ISO/IEC 27001 certificates worldwide, and the transition window from the 2013 edition closed on 31 October 2025, so any certificate still valid today is against the 2022 text. Auditors have precedent, buyers recognise the certificate, and the cost and timeline are reasonably predictable — we broke the numbers down in our ISO 27001 certification cost guide.
What ISO 42001 actually asks of you
ISO/IEC 42001:2023 reuses that same clause 4 to 10 skeleton, which is why an organisation with a working ISMS recognises most of the paperwork immediately. The differences start in clause 6. Annex A carries 38 controls organised under nine control objectives, covering AI policy, internal organisation, resources, impact assessment, the AI life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships. Our breakdown of the ISO 42001 Annex A controls walks through each objective.
Then comes clause 6.1.4, the requirement with no ISO 27001 equivalent: an AI system impact assessment. You have to assess and document how the AI system could affect individuals, groups and society — including foreseeable misuse — and feed that back into risk treatment. ISO 27001 asks what could happen to your information. ISO 42001 also asks what your system could do to other people. That single shift explains most of the extra evidence: bias and fairness testing, training data provenance, human oversight logs, explanations for automated decisions.
Annexes B, C and D are informative rather than auditable. Annex B gives implementation guidance, Annex C lists typical AI risk sources and objectives, and Annex D deals with using an AI management system alongside other management system standards — including ISO 27001 itself.
One practical caveat: accredited certification is younger here. UKAS issued its first ISO/IEC 42001 accreditation in January 2026, ANAB-accredited bodies have been coming online since 2025, and the roster is still growing. Check that your certification body’s accreditation scope covers ISO/IEC 42001 before you sign, not after. Our guide to ISO 42001 certification covers what to ask.
Where the two standards overlap
The overlap in ISO 27001 vs ISO 42001 is larger than most vendors admit. Because both follow the harmonized structure, the following work is written once and serves both systems:
- Context of the organisation and interested parties
- Leadership commitment, policy approval, roles and responsibilities
- Competence, awareness, communication and control of documented information
- Internal audit programme and management review
- Nonconformity and corrective action
- The risk assessment and risk treatment method — different registers, same mechanics
What you cannot share is the substance: two risk registers, two Statements of Applicability, two sets of operational evidence. The management shell is common; the controls are not.
The differences that change your workload
Control counts mislead anyone reading an ISO 27001 vs ISO 42001 table for the first time. ISO 27001 has 93 Annex A controls and ISO 42001 has 38, which makes ISO 42001 look like the lighter lift. In practice the AI controls are broader and less prescriptive, and the evidence behind them is harder to produce. “Keep records of the data used to develop AI systems” is one line in Annex A and months of work if nobody tracked training data lineage.
Three areas consistently cost more than teams expect:
- Data provenance. Knowing where training and tuning data came from, on what legal basis, and what it contains.
- Human oversight. Demonstrating that a person can meaningfully intervene, with logged examples of real overrides rather than a policy statement.
- Third-party AI. If you build on someone else’s model, you inherit risk you cannot inspect, and you still have to show you assessed it.
ISO 27001 vs ISO 42001: which one first?
Start with ISO 27001 if you are beginning from nothing, sell to enterprise buyers, and AI is a feature rather than the product. The ISMS gives you the access control, cryptography, logging and supplier management that ISO 42001’s Annex A assumes already exist. Building the AI management system afterwards is an extension, not a second project from zero.
Start with ISO 42001 if AI is the product, your buyers are asking AI-specific governance questions in procurement, or your board has told you to get AI oversight documented this year. You will still need security controls, but the commercial pressure is on the AI side and the certificate that unblocks deals should come first.
Do both together only if you have a dedicated compliance owner and executive air cover. It is achievable and often cheaper per certificate, but it is two audits’ worth of evidence gathered in one window.
What the EU AI Act changed in 2026
An important correction to a claim you will see repeated: ISO 42001 certification is not EU AI Act compliance. Presumption of conformity under Article 40 attaches only to harmonised standards whose references have been published in the Official Journal, and none have been cited yet. CEN-CENELEC’s JTC 21 concluded that ISO/IEC 42001’s objectives and definitions did not line up with the AI Act’s quality management requirement, and is drafting a bespoke European standard, prEN 18286, instead.
The timetable also moved. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It pushes the obligations for stand-alone high-risk AI systems to 2 December 2027, and for high-risk systems embedded in regulated products to 2 August 2028. What did not move: the Article 5 prohibited practices, in force since 2 February 2025; the general-purpose AI provider obligations that started on 2 August 2025; and the Article 50 transparency and AI content labelling duties. See our EU AI Act deadlines guide for the full sequence, and ISO 42001 vs the EU AI Act for where the standard helps and where it stops.
The deferral buys preparation time. It does not change the answer on ISO 27001 vs ISO 42001, because neither certificate was ever going to satisfy the Act on its own.
Certifying both without doing the work twice
For most growing software companies the ISO 27001 vs ISO 42001 question resolves to “both, eventually”. If that is you, plan for an integrated management system from day one. Run one document control procedure, one internal audit programme, one management review agenda covering both systems, and one corrective action log. Keep the risk registers and the two Statements of Applicability separate — auditors will look for them individually. Ask your certification body about a combined audit; when the same body is accredited for both scopes, shared clause 4 to 10 evidence is usually assessed once, which trims audit days.
If the documentation is the part slowing you down, our ISO 42001 Toolkit ships 67 clause-mapped templates at $199 — including the Statement of Applicability, the AI system impact assessment record, bias testing and human oversight forms, and an EU AI Act crosswalk — and the ISO 27001 Toolkit covers the ISMS side with 175 templates.
ISO 27001 vs ISO 42001: frequently asked questions
Is ISO 42001 replacing ISO 27001?
No. They cover different objects. ISO 27001 certifies an information security management system; ISO 42001 certifies an AI management system. Neither supersedes the other, and holding one says nothing about the other.
Do I need ISO 27001 before I can certify to ISO 42001?
It is not a formal prerequisite — you can certify to ISO 42001 with no ISO 27001 certificate. In practice several Annex A controls assume working security fundamentals, so most organisations find the AI management system audit easier once an ISMS exists.
Does ISO 42001 certification make me EU AI Act compliant?
No. It is strong evidence of governance maturity and useful in procurement, but presumption of conformity requires harmonised standards published in the Official Journal, and none had been cited as of mid-2026.
How many controls does each standard have?
ISO 27001:2022 has 93 Annex A controls in four themes. ISO 42001:2023 has 38 Annex A controls under nine control objectives. Both require a Statement of Applicability justifying inclusions and exclusions.
Can the same certification body audit both?
Yes, provided it holds accreditation for both scopes. Confirm that ISO/IEC 42001 appears on its accreditation certificate — the market is newer, and not every body accredited for ISO 27001 is accredited for ISO 42001.
The bottom line
Treat ISO 27001 vs ISO 42001 as a sequencing decision, not a contest. Information security is the foundation almost every buyer checks first; AI governance is the layer that is fast becoming the second question in the same procurement email. Pick the one your customers are asking about now, build it so the shared clauses are reusable, and add the second without rewriting the first.