Standards Comparison

ISO 42001 vs ISO 27001: what is the difference?

They are often confused, and they are not alternatives. ISO/IEC 27001 governs how you protect information. ISO/IEC 42001 governs how you manage artificial intelligence. This page sets out what each one covers, where they overlap, and how to decide which you need first.

The short answer Side-by-side comparison

Last reviewed July 2026 · Bcom — ISO/IEC 42001 specialists, Australia

The short answer

ISO/IEC 27001 protects information. ISO/IEC 42001 governs AI. ISO 27001 asks whether your data is safe from breach, loss and unauthorised access. ISO/IEC 42001 asks a different question entirely: whether the AI systems you use are accountable, overseen, fit for purpose, and free from harms your organisation has not considered.

You can hold a valid ISO 27001 certificate and still have no governance over AI at all. Security and AI governance are complementary disciplines — one does not substitute for the other.

The distinction that matters most

ISO 27001 asks: could someone access this data who should not? ISO/IEC 42001 asks: is this system making sound, accountable decisions — and can we show how? Airtight security tells you nothing about whether a model is biased, wrong, or unexplainable.

ISO/IEC 42001 and ISO/IEC 27001 compared

Both are certifiable management system standards published by ISO and IEC. They differ in what they are managing.

 ISO/IEC 27001ISO/IEC 42001
What it managesInformation Security Management System (ISMS)AI Management System (AIMS)
Core questionIs our information protected?Is our AI governed and accountable?
PublishedCurrent edition 20222023 — the first international AI management system standard
Primary risks addressedBreach, unauthorised access, data loss, availabilityBias, inaccurate or harmful output, opacity, unclear accountability, misuse
Typical triggerClient or tender security requirementsAI adoption outpacing oversight; AI-specific due diligence
StructureShared — both use the ISO harmonised high-level structure (Annex SL), clauses 4–10
CertifiableYes — by an accredited certification body, via Stage 1 and Stage 2 audits

What each standard actually asks of you

ISO/IEC 27001 — information security

Establish an ISMS: classify information, assess security risk, apply controls across access, cryptography, operations, suppliers and incident response, then audit and improve. The object being protected is information.

ISO/IEC 42001 — artificial intelligence

Establish an AIMS: identify where AI is used, assess AI-specific risk and impact on people, define accountability and human oversight, govern data and models across their lifecycle, then audit and improve. The object being governed is the AI system and its effects.

Where they genuinely overlap

Both require leadership commitment, defined scope, competence, documented information, internal audit, management review and continual improvement. That shared machinery is why implementing the second standard is materially cheaper than the first.

Which one do you need first?

In practice the answer is driven by what your clients are asking for and where your real exposure sits — not by which standard is newer.

Start with ISO 27001 if…

Your tenders and client security questionnaires are asking about information security, you hold significant volumes of client or personal data, and your AI use is currently limited or low-consequence.

Start with ISO/IEC 42001 if…

AI is already embedded in how you deliver — assisting decisions, handling client information, generating work product — and you cannot currently show who is accountable for it. Also the right starting point if you supply, or want to supply, government buyers who are asking AI-specific due-diligence questions.

Run them together if…

You are building a management system from scratch and know both will be required. An integrated system shares one set of clauses, one internal audit programme and one management review — considerably less overhead than two separate builds.

A common and expensive misreading

The most frequent mistake we see is an organisation treating its ISO 27001 certificate as evidence of AI governance. It is not, and an informed procurement officer will know the difference. If the question on the form is "how do you govern AI?", a security certificate does not answer it.

Frequently asked questions

Do I need ISO 27001 before ISO 42001?

No. ISO/IEC 42001 is a standalone standard — you can implement and certify it without holding ISO 27001. Many organisations do exactly that.

That said, if you already hold ISO 27001, you have a real head start: the management-system machinery (context, leadership, risk process, internal audit, management review, corrective action) is already running, and 42001 can reuse it.

Can one audit cover both standards?

Yes. Because both follow the same high-level structure, certification bodies routinely run combined or integrated audits, and the shared clauses are assessed once rather than twice. This is usually cheaper and far less disruptive than two separate audit cycles.

If we are already ISO 27001 certified, are our AI risks covered?

Not in themselves. ISO 27001 addresses the confidentiality, integrity and availability of information. It does not ask whether a model's outputs are accurate, whether a decision can be explained to the person it affects, whether training data introduced bias, or who is accountable when the system gets it wrong.

You can hold a clean ISO 27001 certificate and still have no answer to any of those questions. That gap is exactly what ISO/IEC 42001 exists to close.

Which standard do procurement teams ask for?

ISO 27001 remains the more commonly requested standard, because information security has been a procurement requirement for far longer. ISO/IEC 42001 is newer and is appearing in AI-specific due-diligence questions — particularly where the buyer is a government entity or the service involves AI making or informing decisions about people.

Increasingly the question is not one or the other, but whether you can evidence both data protection and AI accountability.

How much of an ISO 27001 system can be reused for ISO 42001?

Typically the whole management-system layer — scope definition, leadership commitment, competence, documented information, internal audit, management review and improvement. What has to be built fresh is the AI-specific substance: the AI use-case inventory, AI risk and impact assessment, controls over data and models, human oversight arrangements, and lifecycle accountability.

Not sure which standard your situation calls for?

Bcom is an Australian AI governance specialist with a BSI-certified ISO/IEC 42001 Lead Implementer. A short gap assessment will tell you where your AI governance actually stands — and whether 42001, 27001, or both belong on your roadmap.

Book a gap assessment See our governance framework