Compyl
GRC Your Way

ISO 42001 vs ISO 27001: What Is the Difference?

Last updated: August 6, 2026

ISO 42001 and ISO 27001 are complementary management system standards, not competitors. ISO 42001 (published December 2023) governs how organizations develop and use artificial intelligence responsibly through an AI management system (AIMS) with 38 Annex A controls. ISO 27001 governs information security through an ISMS with 93 Annex A controls. Most organizations that build or deploy AI at scale end up needing both, and the two are designed to be run and audited together.

This post compares scope, structure, controls, and audits, and explains when to pursue each. New to AI governance? Start with our AI governance guide.

Key takeaways

  • ISO 27001 protects information (confidentiality, integrity, availability); ISO 42001 governs AI-specific risks such as bias, explainability, and human oversight.
  • ISO 42001 has 38 Annex A controls in 9 objective areas; ISO 27001:2022 has 93 controls in 4 themes.
  • Both follow the same harmonized clause structure (Clauses 4 to 10), so they integrate cleanly.
  • ISO 42001 adds elements ISO 27001 lacks: defining your AI role (Clause 4.1) and AI system impact assessments (Clause 6.1.4).
  • Neither standard replaces the other; integrated certification audits can cover both at once.

What is ISO 27001?

ISO/IEC 27001 is the international standard for information security management systems. It requires a risk-based program that protects the confidentiality, integrity, and availability of information, backed by 93 Annex A controls across organizational, people, physical, and technological themes. It has been the default trust signal in B2B security reviews for two decades.

What is ISO 42001?

ISO/IEC 42001 is the first certifiable international standard for AI management systems. It requires organizations to govern the full AI lifecycle: defining an AI policy, assigning accountability, assessing the impact of AI systems on individuals and society, and controlling third-party AI. For a deeper introduction, read what ISO 42001 is and the detailed ISO 42001 requirements.

ISO 42001 vs ISO 27001: side-by-side comparison

DimensionISO 27001ISO 42001
Management systemISMS (information security)AIMS (artificial intelligence)
Core risk focusConfidentiality, integrity, availability of informationBias, explainability, safety, human oversight, societal impact
Annex A controls93 controls, 4 themes38 controls, 9 objective areas (A.2 to A.10)
Distinct requirementsInformation security risk assessment and treatmentAI role definition (4.1), AI system impact assessment (6.1.4)
First published2005 (current version 2022)December 2023
Typical buyer question answeredIs my data secure with you?Is your AI trustworthy and governed?
Certification cycle3 years with annual surveillance3 years with annual surveillance

What are the key differences?

Different risk universes. ISO 27001 asks what could compromise information. ISO 42001 asks what could go wrong when an AI system acts: biased outcomes, opaque decisions, missing human oversight, model drift, and misuse of AI by third parties. A perfectly secure model can still be an ungoverned one.

AI role definition. ISO 42001 Clause 4.1 requires you to define your role in the AI ecosystem (provider, producer, user, partner, or subject), which shapes which controls apply. ISO 27001 has no equivalent.

Impact assessment beyond risk assessment. ISO 42001 Clause 6.1.4 requires an AI system impact assessment considering effects on individuals and society, in addition to the classic organizational risk assessment both standards require.

Control depth vs breadth. ISO 27001 controls span everything from physical entry controls to cryptography. ISO 42001 controls go deep on one domain: AI policy, resources and data for AI, lifecycle management, transparency to interested parties, and third-party AI relationships.

Do you need both certifications?

If you sell software that processes customer data and includes AI features, the practical answer is increasingly yes. ISO 27001 remains the baseline expectation in procurement, while AI governance questions now arrive in the same vendor reviews. ISO 42001 also gives structure to obligations emerging under the EU AI Act, which regulates high-risk AI systems on a fixed enforcement timeline.

If you can only pursue one first: choose ISO 27001 when customer security reviews are blocking deals, and choose ISO 42001 when AI is your core product and buyers are asking pointed questions about model governance.

How do the two standards work together?

Both use the harmonized structure for ISO management systems, so Clauses 4 through 10 (context, leadership, planning, support, operation, performance evaluation, improvement) align almost one to one. In practice that means one risk methodology, one document control process, one internal audit program, and one management review can serve both. Many certification bodies offer integrated audits that assess both standards in a single visit, reducing audit days and cost; see our breakdown of ISO 42001 certification costs for what that saves.

Frequently asked questions

Does ISO 42001 replace ISO 27001?

No. ISO 42001 governs AI-specific risks and assumes information security is handled elsewhere, typically by an ISO 27001 ISMS. They address different risk domains and are designed to coexist.

Can one audit cover both standards?

Yes. Because the clause structures align, many registrars offer integrated audits covering the ISMS and AIMS together, which is cheaper and less disruptive than two separate audit cycles.

Which standard should you implement first?

Most organizations implement ISO 27001 first because customers demand it earlier. AI-native companies whose buyers are focused on model governance sometimes lead with ISO 42001, then add ISO 27001.

How many controls does each standard have?

ISO 27001:2022 has 93 Annex A controls grouped into organizational, people, physical, and technological themes. ISO 42001 has 38 Annex A controls grouped under 9 objectives (A.2 to A.10).

Is ISO 42001 required by the EU AI Act?

No, the EU AI Act does not mandate ISO 42001. But an AIMS provides the governance scaffolding (risk management, documentation, human oversight, monitoring) that the Act’s high-risk requirements expect, so certification is a strong head start.

Is ISO 42001 harder than ISO 27001?

It is usually a smaller control set but newer territory. Organizations find the impact assessment and AI lifecycle documentation unfamiliar, while the management system mechanics feel routine if an ISMS already exists.

Compyl maps ISO 42001 and ISO 27001 controls in one platform, so shared requirements are satisfied once and evidence flows to both audits automatically. Explore ISO 42001 compliance with Compyl.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies