ISO 27001 addresses information security management; ISO 42001 addresses AI management. They can work together, but using AI does not automatically mean you need both certificates. Start with your risks, actual customer requirements and the scope you need independently assessed. ISO 27001, ISO 42001.
| Your situation | A sensible starting point |
|---|---|
| Customers need assurance over information security | Assess ISO 27001 against that requirement. |
| AI is central to the product and buyers specifically request AI governance assurance | Assess ISO 42001 alongside the information-security work. |
| You already operate an ISMS and are adding AI governance | Extend the shared management processes; assess the AI-specific gaps. |
| AI use is limited and no certificate is requested | Assess the risks and necessary governance before buying certification. |
Atoro is an Irish AI governance and cyber compliance consultancy, and the first in Europe to be certified against ISO 42001. We support software companies from implementation and internal audit to ongoing managed compliance with TrustOps, with outsourced DPO and virtual CISO support where needed.
What is the difference?
The standards have different subjects, not mutually exclusive territories. AI creates information-security risks as well as wider governance questions.
An information security management system, or ISMS, addresses risks to the confidentiality, integrity and availability of information. Those risks can involve an AI system, its suppliers, access controls or development process. ISO 27001 certification is assurance about the defined management system’s conformity, not a guarantee that no breach will happen. ISO 27001.
An AI management system adds a framework for governing how an organisation develops, provides or uses AI. It addresses matters such as AI risks and impacts, responsibilities and the management of AI-related activities. Certification is not a guarantee that every model output is accurate or unbiased. ISO 42001.
For example, access controls may protect a recruitment tool’s candidate records. That does not settle whether the tool’s recommendations are appropriate, how people can challenge them or when human review is needed. A security assessment and an AI impact assessment answer related but different questions.
Which should we implement first?
Choose the order from the requirement you need to meet, not from an assumed dependency between the standards. ISO 27001 certification is not a prerequisite for ISO 42001.
Our default recommendation is ISO 27001 first: establish the information-security foundation, then extend the governance, audit and review processes to AI. Lead with ISO 42001, or run both together, when AI is central to your product and buyers are asking specifically for AI assurance. If neither certificate is needed yet, address the risks before committing to two certification projects.
Ask the buyer what they actually require: a certificate, a completed questionnaire, a particular contractual control or evidence about a specific AI feature. These are not interchangeable, and a sales assumption is not an assurance requirement.
What can an integrated system reuse?
Reuse the management processes that remain suitable, then add the AI-specific work. Do not assume a mapped control proves conformity with both standards.
Possible shared processes include document control, competence records, internal audit planning, management review and corrective-action tracking. Review each against the additional scope. An existing risk register may be a useful starting point, but AI-related impacts and responsibilities still need deliberate assessment.
A practical integration plan is to:
- Define the intended scope of each management system.
- Identify existing processes and evidence that remain applicable.
- Record the requirements that need new or changed work.
- Assign owners for AI-specific assessments, controls and monitoring.
- Make sure the audit programme covers both sets of requirements.
Integration can reduce duplication. It does not establish a fixed saving in fees or effort, and it does not remove either standard’s requirements. Certification bodies use applicable audit rules when planning integrated audits. IAF MD 11.
What if we use someone else’s AI model?
Using a third-party model does not settle your role or remove the need to govern your own use. Describe what your organisation actually builds, supplies and operates.
The supplier’s certificate is evidence about its stated scope. It does not certify your customer-facing application, prompts, workflows or decisions. Equally, calling an API is not enough information to decide every ISO role or EU AI Act obligation. Assess those questions separately rather than treating their terminology as identical. ISO’s explanation.
Does either certificate prove legal compliance?
No. A management-system certificate does not, by itself, establish compliance with every law applying to the business or its AI systems.
The EU AI Act has its own scope, definitions and requirements. GDPR obligations may also apply where personal data is involved. Use the management system to organise relevant compliance work, but assess the legal requirements for the actual activity. EU AI Act, GDPR.
FAQs
1. We already have ISO 27001. Do we need ISO 42001?
Not automatically. Assess your AI activities, impacts and buyer requirements; ISO 27001 is not a substitute for the wider AI-management requirements of ISO 42001.
2. Can we get ISO 42001 before ISO 27001?
Yes, ISO 27001 certification is not a prerequisite. You still need to address the security and other risks relevant to your AI management system.
3. Which should we implement first?
Our default is ISO 27001 first. Lead with ISO 42001, or run both together, when AI is central to your product and buyers specifically need AI assurance. The buyer’s actual requirement and your capacity to operate both systems should determine the order.
4. Is the second certification always cheaper?
No fixed saving can be assumed. Shared processes may reduce duplicated work, but scope, maturity, implementation gaps and audit arrangements determine the effort and cost.
5. How much existing documentation is reusable?
Review it requirement by requirement. Shared management processes are candidates for reuse, while AI-specific assessments, responsibilities and evidence may need substantial new work.
6. Can one certification body audit both?
Potentially, if it offers both services with the scope and credentials you need. Ask about an integrated audit programme, applicable accreditation and how both standards will be covered.
7. Does our supplier’s AI certificate cover our product?
No, not simply because your product uses that supplier. Check its certificate scope and separately assess your organisation’s responsibilities and activities.
8. Does ISO 42001 satisfy the EU AI Act?
Not by itself. ISO 42001 is a management-system standard, while the Act imposes separate legal requirements depending on the activities and systems involved.
To decide the order and scope for your organisation, book a scoping conversation with Atoro. Bring the customer requirement and the management-system evidence you already have.
Sources
- ISO/IEC 27001: https://www.iso.org/standard/27001
- ISO/IEC 42001: https://www.iso.org/standard/42001
- ISO, ISO 42001 explained: https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html
- IAF MD 11, Integrated management system audits: https://iaf.nu/iaf_system/uploads/documents/IAF_MD_11_Issue_3_12092023.pdf
- EU AI Act: https://eur-lex.europa.eu/eli/reg/2024/1689
- GDPR: https://eur-lex.europa.eu/eli/reg/2016/679