ISO 42001 vs ISO 27001: What Is the Difference?

Comparison chart showing ISO 42001 vs ISO 27001 scope and overlap

Table of Contents

ISO 42001 is the international standard for AI management systems. ISO 27001 is the international standard for information security management systems. Both matter to organisations using AI. Both come up often in governance conversations. How they relate to each other causes a fair amount of confusion.

Here is the short version. ISO 27001 covers how organisations protect information. ISO 42001 covers how organisations govern AI. They overlap in places, but they solve different problems. Having one does not replace the other. Using both well means understanding what each is actually for.

What ISO 27001 covers

ISO 27001 is well established. It has been through several revisions and is widely used across UK organisations. It gives a framework for managing information security risk – confidentiality, integrity, and availability of information assets – through policies, controls, risk assessment, and management system requirements.

The 2022 revision touched on emerging technology risk, but AI governance was never its main focus. It addresses AI mainly as an information security topic: protecting systems from attack, managing access, ensuring resilience. It says little about AI decision-making, bias, transparency, supplier accountability, or oversight of AI outputs.

ISO 27001 certification tells you an organisation has controls to protect its information assets. It does not tell you how that organisation governs its AI use, whether its AI systems behave as intended, or whether the accountability around AI decisions is adequate.

What ISO 42001 adds

ISO 42001, published in 2023, is built specifically for AI management. It takes a lifecycle view – design, development, deployment, monitoring, and decommissioning – and sets requirements for governance, accountability, transparency, and impact assessment across that lifecycle.

Where ISO 27001 asks “is this information secure?”, ISO 42001 asks “is this AI system governed responsibly?”. It addresses who is accountable for AI decisions. It looks at how systems are assessed for intended and unintended impacts. It covers AI-specific risks such as bias, explainability, supplier dependency, and model drift. And it asks how the organisation demonstrates that its AI governance keeps working over time.

ISO 42001 also goes further than ISO 27001 on supply chain. It requires organisations to consider the governance implications of AI tools and systems bought from third parties, not just the ones built in-house. For most organisations, that is where most of the actual AI governance risk sits – the same point covered in what an AI risk assessment should actually cover.

How the two standards relate in practice

If you already have ISO 27001, ISO 42001 is not a replacement. It is a complement that covers the AI governance ground that ISO 27001 does not reach.

There is real overlap in the management system itself. Organisations with mature ISO 27001 implementations already have documentation, policy, risk assessment, and internal audit structures. These give a reasonable foundation for ISO 42001. The extra work sits mainly in AI-specific content: impact assessments, AI-specific risk identification, accountability structures, supplier governance, and AI-specific monitoring.

If you do not have ISO 27001, ISO 42001 can stand on its own. It does not require 27001 as a prerequisite. But the two standards share enough common ground that building toward both together is usually more efficient than treating them as separate programmes.

Do you actually need ISO 42001?

For most organisations, formal certification to ISO 42001 is not the right goal right now. The standard is recent. The certification market is still maturing. Most of the commercial pressure for certification currently comes from procurement requirements in specific sectors, not from general market expectations.

What most organisations need is AI governance that substantively matches what ISO 42001 requires, certified or not. The standard is a useful way to think about good AI governance: the accountability structures, the impact assessment approach, the supplier governance requirements, and the review cadence. Organisations that build governance to that standard are better governed, regardless of whether a certification body has signed it off.

Formal certification is more likely to be worthwhile for organisations in regulated sectors, those with significant public sector or enterprise procurement relationships, and those for whom an independently verified AI governance standard creates a real commercial or reputational advantage.

For everyone else, the more useful question is whether your AI governance already covers the substance of the standard. That question is worth asking whatever your certification plans are.

Where to start with ISO 42001 alignment

The most common mistake is treating ISO 42001 as a documentation exercise from day one. The standard requires a functioning management system, not a set of well-formatted documents. Governance built mainly to satisfy documentation requirements tends to fail when it meets operational reality – the same failure pattern covered in why generic AI policies usually fail.

A sensible starting point is an honest assessment of where your AI governance stands against the standard’s requirements. That gap analysis tells you where you are, what to prioritise, and what a realistic programme looks like for your size, sector, and existing governance setup. Our AI Governance Gap Assessment is a quick way to get a first read on this.

Black Chili’s AI Governance and Guardrails Design service builds governance frameworks aligned to ISO 42001 requirements – practical, tailored, and grounded in your actual AI usage.

If you are not sure what AI tools are in use inside your organisation, an AI Exposure Review gives you a clear, independent picture - what is being used, what data it touches, and where the real risks are.

Related Posts