Skip to content

Insights

Already ISO 27001 certified? You're roughly 40% of the way to ISO 42001 — here's the rest

Quality Gurus

  • AI Security
  • Cybersecurity
  • Certification

Organisations holding ISO 27001 are asking the ISO 42001 question in rapidly growing numbers — usually because a customer questionnaire or RFP just asked it for them. The good news is real: the two standards share the harmonised management-system structure, and a functioning ISMS gives you the governance machinery an AI management system needs. The common estimate that an ISO 27001-certified organisation is around 40% of the way to ISO 42001 matches what we see in practice.

The trap is the other 60%. Organisations that treat ISO 42001 as "ISO 27001 with AI words" consistently underestimate the genuinely new work. Here is the honest map.

Mapping ISO 27001 to ISO 42001: the management-system spine carries over, while the AI inventory, impact assessment, lifecycle controls and AI policy are new build.
Roughly 40% of the work is already done if you hold ISO 27001. The trap is assuming the other 60% is a rename.

What carries over almost unchanged

The management-system spine transfers nearly wholesale, because the harmonised structure makes clauses 4–10 structurally identical:

  • Governance machinery: document control, internal audit programme, management review, corrective action, competence and awareness processes — extend their scope to the AIMS rather than rebuilding them.
  • Risk management method: your risk assessment methodology, criteria and treatment workflow carry over; what changes is what gets assessed.
  • Context and stakeholder analysis: the clause 4 work extends naturally — AI adds new interested parties (regulators, affected individuals, data subjects) to an existing analysis.
  • Supplier and incident processes: third-party management and incident response extend to AI vendors and AI incidents with modification, not reinvention.

This is why the integrated route — one management system, one audit programme, combined certification audits — is almost always the right architecture.

What is genuinely new build

Four areas have no ISO 27001 equivalent, and they are where the project time goes:

  • The AI system inventory. ISO 27001's asset register will not contain it. Discovering the actual AI estate — procured SaaS with embedded models, Copilot-class assistants, internal projects, shadow experiments and, increasingly, autonomous agents acting on the organisation's behalf — is consistently the first surprise: most organisations find two to three times more AI in use than governance knew about. For Microsoft-estate organisations, the agent-governance tooling that arrived with Microsoft 365 E7 and Agent 365 makes part of this inventory technically discoverable rather than a survey exercise, which is a genuine help — though a tool inventories systems, it does not govern them.
  • AI impact assessment. The standard's most distinctive requirement: assessing consequences for individuals and society affected by the AI system — fairness, transparency, accountability, safety — not just risk to the organisation. Information security has no muscle memory for this; the closest analogue is a DPIA, and organisations with GDPR-style privacy practices adapt fastest.
  • AI lifecycle controls (the heart of Annex A). Controls across the lifecycle: data quality and provenance for training data, documentation of model purpose and limitations, human oversight mechanisms with genuine intervention ability, monitoring for drift and degradation, and decommissioning. For procured AI, this becomes a vendor-transparency problem — extracting model documentation from suppliers is its own workstream.
  • AI policy and role accountability. A meaningful AI policy (acceptable use, prohibited uses, escalation paths) and named accountability for each AI system — decisions ISO 27001 never forced.

The gap analysis that matters

Run it in this order: inventory first (you cannot scope what you have not found), then classify each AI system by stakes — what decisions it influences, who it affects, what data feeds it — then assess the high-stakes systems against Annex A controls. The classification step is what keeps the project proportionate: a marketing copy assistant and a credit-scoring model do not deserve equal control depth, and a system that treats them equally will be both expensive and ignored.

Certification mechanics

Certification bodies offer combined ISO 27001 + 42001 audits, and the economics favour them: shared clauses audited once, one surveillance cycle. If your ISO 27001 recertification is within the next twelve to eighteen months, aligning the ISO 42001 initial certification to that date is usually the efficient move. Timeline for the 42001 increment on top of a healthy ISMS: typically four to eight months depending on AI estate size — with an unhealthy ISMS, fix that first, because the same audit findings will otherwise surface in both standards.

Practical steps

Start the AI inventory this month — it costs little, commits you to nothing, and every governance conversation afterwards becomes concrete. Classify by stakes, run the gap analysis against the genuinely new requirements above, and time certification against your existing audit calendar. QG is built for exactly this intersection: management-systems consultancy and a cloud and AI security practice under one governance — see our full ISO 42001 explainer for the standalone view.

Have a question we can answer?

Book a short discovery call to talk through your current systems, sector and target standards. We'll come back with clear, practical next steps.