They are often confused, and they are not alternatives. ISO/IEC 27001 governs how you protect information. ISO/IEC 42001 governs how you manage artificial intelligence. This page sets out what each one covers, where they overlap, and how to decide which you need first.
ISO/IEC 27001 protects information. ISO/IEC 42001 governs AI. ISO 27001 asks whether your data is safe from breach, loss and unauthorised access. ISO/IEC 42001 asks a different question entirely: whether the AI systems you use are accountable, overseen, fit for purpose, and free from harms your organisation has not considered.
You can hold a valid ISO 27001 certificate and still have no governance over AI at all. Security and AI governance are complementary disciplines — one does not substitute for the other.
ISO 27001 asks: could someone access this data who should not? ISO/IEC 42001 asks: is this system making sound, accountable decisions — and can we show how? Airtight security tells you nothing about whether a model is biased, wrong, or unexplainable.
Both are certifiable management system standards published by ISO and IEC. They differ in what they are managing.
| ISO/IEC 27001 | ISO/IEC 42001 | |
|---|---|---|
| What it manages | Information Security Management System (ISMS) | AI Management System (AIMS) |
| Core question | Is our information protected? | Is our AI governed and accountable? |
| Published | Current edition 2022 | 2023 — the first international AI management system standard |
| Primary risks addressed | Breach, unauthorised access, data loss, availability | Bias, inaccurate or harmful output, opacity, unclear accountability, misuse |
| Typical trigger | Client or tender security requirements | AI adoption outpacing oversight; AI-specific due diligence |
| Structure | Shared — both use the ISO harmonised high-level structure (Annex SL), clauses 4–10 | |
| Certifiable | Yes — by an accredited certification body, via Stage 1 and Stage 2 audits | |
Establish an ISMS: classify information, assess security risk, apply controls across access, cryptography, operations, suppliers and incident response, then audit and improve. The object being protected is information.
Establish an AIMS: identify where AI is used, assess AI-specific risk and impact on people, define accountability and human oversight, govern data and models across their lifecycle, then audit and improve. The object being governed is the AI system and its effects.
Both require leadership commitment, defined scope, competence, documented information, internal audit, management review and continual improvement. That shared machinery is why implementing the second standard is materially cheaper than the first.
In practice the answer is driven by what your clients are asking for and where your real exposure sits — not by which standard is newer.
Your tenders and client security questionnaires are asking about information security, you hold significant volumes of client or personal data, and your AI use is currently limited or low-consequence.
AI is already embedded in how you deliver — assisting decisions, handling client information, generating work product — and you cannot currently show who is accountable for it. Also the right starting point if you supply, or want to supply, government buyers who are asking AI-specific due-diligence questions.
You are building a management system from scratch and know both will be required. An integrated system shares one set of clauses, one internal audit programme and one management review — considerably less overhead than two separate builds.
The most frequent mistake we see is an organisation treating its ISO 27001 certificate as evidence of AI governance. It is not, and an informed procurement officer will know the difference. If the question on the form is "how do you govern AI?", a security certificate does not answer it.
No. ISO/IEC 42001 is a standalone standard — you can implement and certify it without holding ISO 27001. Many organisations do exactly that.
That said, if you already hold ISO 27001, you have a real head start: the management-system machinery (context, leadership, risk process, internal audit, management review, corrective action) is already running, and 42001 can reuse it.
Yes. Because both follow the same high-level structure, certification bodies routinely run combined or integrated audits, and the shared clauses are assessed once rather than twice. This is usually cheaper and far less disruptive than two separate audit cycles.
Not in themselves. ISO 27001 addresses the confidentiality, integrity and availability of information. It does not ask whether a model's outputs are accurate, whether a decision can be explained to the person it affects, whether training data introduced bias, or who is accountable when the system gets it wrong.
You can hold a clean ISO 27001 certificate and still have no answer to any of those questions. That gap is exactly what ISO/IEC 42001 exists to close.
ISO 27001 remains the more commonly requested standard, because information security has been a procurement requirement for far longer. ISO/IEC 42001 is newer and is appearing in AI-specific due-diligence questions — particularly where the buyer is a government entity or the service involves AI making or informing decisions about people.
Increasingly the question is not one or the other, but whether you can evidence both data protection and AI accountability.
Typically the whole management-system layer — scope definition, leadership commitment, competence, documented information, internal audit, management review and improvement. What has to be built fresh is the AI-specific substance: the AI use-case inventory, AI risk and impact assessment, controls over data and models, human oversight arrangements, and lifecycle accountability.
Bcom is an Australian AI governance specialist with a BSI-certified ISO/IEC 42001 Lead Implementer. A short gap assessment will tell you where your AI governance actually stands — and whether 42001, 27001, or both belong on your roadmap.